malware trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by xeriren, Sep 29, 2012.

  1. xeriren

    xeriren Private E-2

    My friends laptop is having problems. Blue screen within several hour of use. laptop have 9 svchost.exe on task manager.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's clean up a few things and then see how you are running.

    Rescan with HitmanPro.
    Choose to Delete these files if they are detected:

    • C:\ProgramData\Microsoft\Windows\DRM\E860.tmp
      C:\ProgramData\Microsoft\Windows\DRM\E8BE.tmp
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\ (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome.manifest (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\ (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\background.html (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\browser.xul (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\crossrider.js (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\crossriderapi.js (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\dialog.js (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\options.js (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\options.xul (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\search_dialog.xul (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\chrome\content\update.html (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\defaults\preferences\ (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\defaults\preferences\prefs.js (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\install.rdf (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\locale\en-US\ (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\locale\en-US\translations.dtd (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\ (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\button1.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\button2.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\button3.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\button4.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\button5.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\crossrider_statusbar.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\icon128.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\icon16.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\icon24.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\icon48.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\panelarrow-up.png (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\popup.html (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\popup_binding.xml (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\skin.css (Adware.IWantThis)
      C:\Users\Einheart\AppData\Roaming\Mozilla\Firefox\Profiles\sr70yta8.default\extensions\crossriderapp2258@crossrider.com\skin\update.css (Adware.IWantThis)
      HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055225558}\ (Adware.IWantThis)
      HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066226658}\ (Adware.IWantThis)
      HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758}\ (Adware.IWantThis)

    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    Now use windows explorer to find and delete:
    C:\Users\Einheart\AppData\Roaming\Microsoft\Windows\Templates\1e01ns5b52v572

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now re-run Hitman and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. xeriren

    xeriren Private E-2

    Thank you for your time but my friend was already at his breaking point and made the decision to do a full wipe out.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds