malware problems, scanners all freeze

Discussion in 'Malware Help (A Specialist Will Reply)' started by rbdweezy, Jul 25, 2006.

  1. rbdweezy

    rbdweezy Private E-2

    I recently starting getting alerts from avast that a win32 trojan is trying to download to my computer. I tried to follow the read and run me section, but everytime I try to run adaware, avast, bit defender, etc..., the cpu useage shoots to 100 % and then the computer freezes up. Please somebody help.

    Thanks,
    Shane
     
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Are you having difficulty with the freezing in normal boot mode, safe mode or both?
     
  3. rbdweezy

    rbdweezy Private E-2

    Scanners freeze in normal and safe mode.
     
  4. AbbySue

    AbbySue MajorGeeks Administrator

  5. rbdweezy

    rbdweezy Private E-2

    here is the hijack this log. Thanks for all your help
     

    Attached Files:

  6. AbbySue

    AbbySue MajorGeeks Administrator

    You missed some important steps in the instructions. Downloading, Installing, and Running HijackThis

    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\hijack this\HijackThis.exe
    Please complete the steps you missed, run HJT and attach a new log.
     
  7. rbdweezy

    rbdweezy Private E-2

    I ran hijack this again, with only hijack this running. I still have iexplorer in the log, but it was not open when I ran the scan. Thanks again for the help.
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Follow the directions for the WareOut Removal pocedure.

    Attach report.txt from fixwareout and a fresh HijackThis.log.
     
  9. rbdweezy

    rbdweezy Private E-2

    I followed the above directions, here are the logs. Thanks.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Boot to Safe Mode

    Delete the following files in C:\WINDOWS\system32
    CSSGN.EXE
    DMPWP.EXE
    \DMVCO.EXE
    {80BF1BF9-5D0A-4268-BEBD-81F0C35E27D2}.exe
    {3E46729E-6027-4FBB-A545-C74295871C0B}.exe
    {C18D4F30-95D1-497A-B436-CD0E6905CA31}.exe
    {CBBAD3A7-C1BA-4EEC-B38F-2A14AA4A466E}.exe
    {034C5B9C-5E39-48CD-A08D-93D8E374C398}.exe
    {E8C07CF5-DB84-432C-A8E8-7DB2D5D965D9}.exe
    {1992E860-F23D-4851-9C87-CE86F3664EEB}.exe
    {C5239792-73B5-445A-B0BD-206AEE6224AD}.exe
    {B35BDD8C-2F79-40D6-92DA-9011E42A65EF}.exe
    {7D4755B4-C396-44D4-B8B4-7217950CFF85}.exe
    {88A40661-D108-44BA-968D-58C62E37CBA7}.exe
    {2AF507E4-0CC6-4CE8-A0DB-D9C6C891B7D9}.exe
    {21897CDC-A203-45BE-8AE2-425F493C54AB}.exe
    {0C613D6F-1539-482F-A8BF-E0D094E593B5}.exe
    {6900CD47-872C-4EC6-B8E2-A2CB2BE2B73F}.exe
    {5E289E77-A24A-4893-A179-A2096F9028C4}.exe
    {134F5C26-4E34-4A0E-AB74-03DE5BA0CCFE}.exe
    {3C5335B3-FCE7-4DF4-A089-6710CD5CBE2B}.exe
    {C1C96917-3493-4A0F-B6AC-3CF43BB85149}.exe
    {9D73120F-14A9-46F2-A3F6-A8DFE90871DA}.exe
    {90D4A4EC-AA1F-4AEE-85E4-87F62CFE309A}.exe
    {433313D9-35AE-4E3F-9A87-01CE2BCCA26A}.exe
    {AE4F1683-00B9-4796-B5D2-85F219258D60}.exe
    {E0FE33D9-8BC1-4491-AA33-0714F23FC93E}.exe
    {E4DAF540-EFCD-4DAB-AD45-12B677B40A6E}.exe
    {D20D0297-D658-4E35-B0C8-84F86CE536B2}.exe
    {F8143B95-D1D6-40A4-AB49-C60C4849DFF5}.exe
    {67F6607F-13CD-4F1B-ACFE-7C3F16EC8C93}.exe
    {75F094C5-C77E-4AD2-96E5-A82A8C75BC1A}.exe
    {F5DCA8EC-7256-4D52-804E-4CFA1A9E17A5}.exe
    {E1B719C2-C38A-45E9-BEF6-4FA20AE738C8}.exe
    {5C8B0BDC-4CD3-494D-BBD5-025932ADFDD2}.exe
    {52D03072-70A5-46C7-AA58-F07FEB37746E}.exe
    {5F412A4E-0B90-4C55-87E2-26F9484377F2}.exe
    {70C36F6A-C7CD-4E54-8FD6-69FC38F9EB40}.exe
    {691733B3-D80F-47D1-A672-39687E77001A}.exe
    {3AB6C58D-906C-46DC-ACE5-117AFC7EB138}.exe
    {C8A34FEE-BC0F-41F8-9880-1C17ED898C2B}.exe
    {45255F53-3E13-4357-BFCA-A79E1B789747}.exe
    {70ED83AE-EEF2-4A8B-9E74-E887A1261FC8}.exe
    {1F170505-D2D6-410A-B24C-FD4FB9E983E9}.exe
    {11E236A7-5192-464F-9C81-1BAF60DE3B8F}.exe
    {B13F1C57-29E6-4610-85F5-5439FB284097}.exe
    {3CAAFCAF-C772-44EF-9DF3-A073E4AEC6F3}.exe
    {786BE848-D350-4C8B-B8CC-7848A40B04D8}.exe
    {9AC56327-9875-4E5A-BA0E-03040E687896}.exe
    {FC027783-DA8E-46CD-9F14-CF2CC1468704}.exe
    {E84B547C-BA74-4739-BFE8-E066F67DD8A5}.exe
    {28577537-6840-4BD8-903F-B34A61815F17}.exe
    {13557A1A-4ED1-411D-8D12-15A1384A6C10}.exe
    {C4B801C2-3A86-4C84-BF67-47DF7C5AB9F1}.exe
    {80E2E2F9-9663-4454-A7E4-7956EDB0B16F}.exe
    {1FE458D6-72E1-40A4-8616-3AEEF0F4CFA9}.exe
    {59A1EBB3-A34B-4C84-90FB-851670041C0E}.exe
    {72618A92-756E-4FAA-AF1A-FAC7D37B1628}.exe
    {37FB6758-59D8-4C4A-84C6-E2337BBCF74D}.exe
    {68D652B0-6D03-42B0-A5D1-F93882C20987}.exe
    {2CF2251A-DEE5-4630-85F7-A1C2D88A370D}.exe
    {176A2CCF-1DC2-41B4-9EE8-03519A21CFAA}.exe
    {4B4F0515-7C11-43FE-85EA-1E3877F7A6B4}.exe
    {E86F84B9-4DC6-4AEC-AF9A-C5ED7670FAAE}.exe
    {A6FBB76D-7993-49EE-A976-8DDED3AA22E5}.exe
    {1E0F98DB-82ED-4565-954A-97DC8B1277F4}.exe
    {758C12B8-2DE1-4F6B-9ECE-68D43BA49227}.exe
    {73B9F583-CFCB-46DB-A22E-8F51D475D925}.exe
    {EAA1BABF-B82A-4977-A34F-0A5B56C8F0AA}.exe
    {07841443-70D4-43FB-8B26-EEB5E926DCE6}.exe
    {FC7FCBE1-4A49-4D59-9FD7-494FB57283B8}.exe
    {5EDA8E7E-26DF-476D-A667-2E64FC1DE221}.exe
    {9D9AA5F7-F89D-43D4-B84B-84E3A2370659}.exe
    {3402972E-C438-4061-A80B-01DA7EEF5BE1}.exe
    {B70096A5-D871-4DA1-8B89-7C2E0A260AA9}.exe
    {8053D7F3-B4D0-4F87-85F4-48C8C62410F0}.exe
    {DF34D538-017D-4CC4-9EC9-4BE08909A002}.exe
    {D7503736-2777-4171-8594-A28CCEBA6CE6}.exe
    {5E6E41A7-0021-492B-9FC8-4928CFBD0AD5}.exe
    {D3DF0260-B6C4-4686-B1F2-A613A5F6DAC9}.exe
    {77AB2882-7AEA-465B-B7FE-4A106D85950C}.exe
    {755B814C-E723-4231-842E-9EFAB239961A}.exe
    {0C28D3CE-A7F5-4544-87DB-D0DFE62D5AF5}.exe
    {838C599F-66F6-4EC2-8DF7-A8700239A073}.exe
    {E4089E26-BCA4-4A0F-A0D1-0BC3C391E665}.exe
    {A6FF81E0-AEB9-4DFC-B033-AC0C2B6EE3A4}.exe
    {8367B6EC-C15B-4D2E-99C6-AFF701DB4948}.exe
    {159C67B9-66C5-4FED-838F-952E7C521097}.exe
    {8B4CEDD0-0830-42BA-BD3C-A9D30F21B75C}.exe
    {555605E3-D0B9-4EA9-B572-8E6E4A56F1DE}.exe
    {85C15296-50FD-4AC8-BD08-E93E94C31488}.exe
    {64C20F27-771C-4800-BC7C-CDA390413978}.exe
    {A203F621-45FC-4547-B5D3-D0B1665691B7}.exe
    {411932C4-A84C-4B30-9E2C-CACE5EC2D444}.exe
    {EECB20CB-2D8B-44BE-A116-8810E2ED0402}.exe
    {A5865D0C-196A-44CB-923F-1860384F7FA5}.exe
    {349D61F0-B3F6-453D-8CB8-E50A04533B03}.exe
    {A3A9B2FC-5FF1-4ECB-A785-1ABD5DB137E8}.exe
    {CFE2A3A7-F612-4E37-8873-9669A14D5D64}.exe
    {6E7E0972-E544-4653-8992-2ABB1EB766B5}.exe
    {94633D2C-3FEE-45B1-A9E9-2A961A73A297}.exe
    {9CE60E23-150F-492D-A30C-09D7B3DEE0E1}.exe
    {2F560382-D438-4734-908B-BA8E30E274FB}.exe
    {8B1BB6A0-D447-4F02-B2E5-7997C061AA4C}.exe
    {E86EF62F-207F-411B-8DA5-588D1799B4C2}.exe
    {12DC71C1-B092-4036-979A-38FA50D01085}.exe
    {8C251090-010D-470E-AC28-4547243BF7D0}.exe
    {BFB20A48-0D6B-41B3-9632-D1DEB91FF2FC}.exe
    {2302A24A-7B27-4ADD-A15E-EEE1DC0AB24D}.exe
    {B9966505-E25C-4D12-AEDE-64CD5062333D}.exe
    {E9DE2F9B-B03B-44D8-A9D6-B6A12FA20D9F}.exe
    {ECBC5555-3646-4ACD-B3CF-5D0B48BCB7EC}.exe
    {E94CE8AF-B037-472D-B0B6-C73FED6B7620}.exe
    {6A069E50-7082-4E9C-ADBD-8B06C928A86A}.exe
    {EB3D644C-EAC4-49B9-BD3A-A376AEB1DF74}.exe
    {0C9BCD73-C942-4193-89F1-ACDC361E0777}.exe
    {67AE70C2-8F7F-4ECD-BCB0-B4BE53F2065F}.exe
    {61E000EA-9A3D-4F8A-8F47-2F821DE8F0D9}.exe
    {E3B160CA-E241-4730-B94E-8E0619578C5E}.exe
    {AF707077-F833-4315-B624-396F3D37DD36}.exe
    {12E2EE1F-A201-4EFE-8213-D580F31DF458}.exe
    {E8165EB3-CBEF-4EEF-B974-48607C7A1BB9}.exe
    {C7D72CD1-4AD2-4A57-BD67-5458DEFBA44A}.exe
    {F87EC998-F8F0-4D17-8B87-DDA3C4AC2581}.exe
    {12DFDEEF-0697-4FD2-89F2-0D2CC08DE800}.exe
    {70A85ABD-B022-4DEC-B5B6-CB40867975D1}.exe
    {9C15BFC1-4448-449C-A539-80DBC6521F9A}.exe
    {2739EF85-E96A-4CA7-9393-01E40512DF0E}.exe
    {68D2E2CA-0120-4DD9-BD72-B165A3BDFC31}.exe
    {947D01DD-63E1-4A1C-8E50-D8CA101FEB9A}.exe
    {B67BA7A8-6097-454B-9887-511D10AE7815}.exe
    {9543A319-4F42-484C-BFE4-F10EE9175ACD}.exe
    {D77794B2-820D-4FC9-95D9-DE364791EDA2}.exe
    {DB5830AC-8861-4676-BEC8-0F4AF3084B23}.exe
    {A974FEA6-F131-4BF2-A666-51AF7A3F4EE1}.exe
    {D38BA11C-EEDF-4CC8-8B4D-4A4613E51B0A}.exe
    {559869E9-C7D2-4A79-9AD0-DBAA7E74FA49}.exe
    {E674E534-A3AA-4326-B103-62E6D33A9831}.exe
    {3670EAF9-683D-4DEC-A6AD-E4A01AA33625}.exe
    {ECEF2399-C46F-413D-8736-5A629540437B}.exe
    {591FD6B1-36D0-4B87-BEB5-28F44DB7D68A}.exe
    {F886F62C-A95B-4530-9729-9FD0D9653C2C}.exe
    {E2E8D6A3-7BF3-4209-853E-876343FEC0B9}.exe
    {377524C7-804F-4456-84CE-57126BCDA8C8}.exe
    {18D7BE9F-642A-4D55-81A8-4F559DA88871}.exe
    {7FF72F96-22D7-4B9A-9653-F65948044B8A}.exe
    {98173190-4026-46DF-B4AB-D823D1A75F08}.exe
    {6BE27E30-F40F-4629-A0A6-0C4FD54E1FD7}.exe
    {83E0F894-34C4-41CF-B7B3-4DB41F656474}.exe
    {B2C82532-035D-498F-B1EA-791D433F68FA}.exe
    {323F3B5C-B408-4AE5-AA5A-604BB40FFEB4}.exe
    {614AD29F-0AF6-4135-A7EE-35895F87FEE6}.exe
    {9018E7BB-7A2A-41BA-B04E-A1C2ECF20F94}.exe
    {60D0F24B-683C-4132-8F3B-D3A33C9CCEB8}.exe
    {E187FD0F-ECFE-41EE-A22E-6CFFCE560834}.exe
    {8FFC297C-1AF6-4C85-B8A2-CA67E561A954}.exe
    {4AF64339-3BD0-49C6-8A60-2DA309AB07DF}.exe
    {C59AFC4B-355D-41A7-8D48-8CD81EBD3E8F}.exe
    {925A1F7C-0CBE-4937-A8ED-6C27A95A4AF8}.exe
    {1FC69EC8-B9B7-4DF3-B039-D7F08FEA61C1}.exe
    {FAFE10BA-7E7C-4B41-9176-DAEC32FA7824}.exe
    {64E44CB4-F0F4-4E8C-B571-BB1F47EE824F}.exe
    {9E492B8C-8771-4F44-B652-DE993F57CEDA}.exe
    {957644A4-0BEA-4925-9B4D-71A26120C3E3}.exe
    {2B99CC7B-7031-4C39-B666-D3F29D69B7D6}.exe
    {4E363D25-1B2B-4CBB-83D2-A7C39EF91650}.exe
    {D24C1B18-4757-446E-954A-933A0247FF7A}.exe
    {DF15C44C-2675-40EE-9EAF-6B465E376A30}.exe
    {B2F42635-BCA4-43F8-B6E8-6C356BF61870}.exe
    {63A105CC-29F4-46B3-AB63-97D8896616E2}.exe
    {74F1FDC5-D50C-442B-BECA-7F47608DF6A5}.exe
    {A790CAE6-30EB-46DD-AD6C-CEB7E5551392}.exe
    {E4605615-D669-481D-96F9-1D335AC2AE0F}.exe
    {49C46E81-C23C-4652-ADB1-9EC2ED2A3A81}.exe
    {0399DA50-39C6-437C-A3ED-F96FE7CC4159}.exe
    {43E14B39-6849-4D3D-9A3B-DE369571B6C0}.exe
    {42598DCF-F507-477B-9282-FED46DCD330D}.exe
    {0F19C021-2C6E-403B-8265-273D10036D98}.exe
    {F3021A9F-7A8C-483D-8058-86CBD88D32AD}.exe
    {F9C78875-53DF-4765-B0EE-FBA4B495A466}.exe
    {F79D7A96-753D-4308-90BD-9FB6135CA05E}.exe
    {665C6F65-DD37-4FEE-81D2-83C2B0791981}.exe

    Reboo to ormal Mode.

    Follow the directions for the following:
    Running Ewido Anti-Malware
    Running WinPfind by OldTimer

    Post the Ewido log, WinPFind.txt and a fresh HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds