I've tried all I can think of... Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by fr0sty, Nov 29, 2006.

  1. fr0sty

    fr0sty Private E-2

    I've got a number of nasties on my system, and though I've gotten rid of a few of them, there are still some that are slipping under the radar (or traces of what I thought I got rid of). I have a HJT logfile if you need it. I ran AVG antivirus and it found and supposedly removed these files:

    mmehtqvu.dll
    pre.exe
    xload.exe

    Immediatley after the scan finished the pop ups and such resumed. Please help!
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI and Welcome :)


    Hijackthis while a useful scan and log is one of the last scans we will ask you to run, best steps to fully find and start the removals process are the below ones,

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs![/B
     
  3. fr0sty

    fr0sty Private E-2

    Well, I went down the list step by step, however both the bit defender and pandascan froze up during the scan. These nasties are locking up internet explorer randomly now, and there's a program called sunthreatengine.exe that is eating up half of my CPU and 150 MB of my memory which is running in the background and can't be closed. I've attached what logs I was able to come up with.
     

    Attached Files:

  4. fr0sty

    fr0sty Private E-2

    And here's the rest.
     

    Attached Files:

  5. fr0sty

    fr0sty Private E-2

    I think I may have outsmarted the malware. I have 4 backup hard drives in my system, and I installed windows onto one of them in case something like this ever happened, so that I can boot to it rather than have to wait to clean viruses before continuing my work. I realised that these viruses won't be able to hide themselves as well if windows is not booted on that drive, so from the other installation I ran several virus scans (all of which came out clean save for pandascan) and used killbox to delete any suspicious files it found on the drive in question. It seems to have worked so far. Thanks for the help.
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    fr0sty,

    It's not that easy, you have a few problems that need addressing such as Vundo. Please let me know if you would like to continue cleaning before I start a fix.

    Thanks!
     
  7. fr0sty

    fr0sty Private E-2

    Yes, if there are still problems, then I would love to get rid of them. Note that those logs are from before I did the cleaning, and I have not had a single pop up since I did that. However, if there are lingering nasties I want them gone for sure. Props for offering to help a fellow Alabamian.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Since it's been a few days, I need a fresh Panda log and a fresh Hijack This log.
     
  9. fr0sty

    fr0sty Private E-2

    Well, unfourtunatley I've got an even bigger issue to tackle now. A friend of mine was updating the firmware in his modem, and my PC rebooted right in the middle of it. His modem was fine, but when I tried to boot to that HDD again, it said hal.dll was missing or corrupt and needed to be replaced. So, since the install on my secondary HDD came from the same CD, I tried to copy and paste that install's hal.dll over the corrupt one, thinking that would do the trick, but it didn't. Any ideas?
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds