"Stdrt" is driving me crazy

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by black5ent, Feb 22, 2012.

  1. black5ent

    black5ent Private E-2

    Here is the final log missing from my first post...sorry
     

    Attached Files:

  2. black5ent

    black5ent Private E-2

    "Stdrt.exe" can not be removed from my computer, please help

    My original post was not complete. My computer is infected with "stdrt.exe". If I removed it, it regenerates on reboot. Does anyone know how to remove this? It uses all the computer resources.
    I am running Win XP sp3.
    I have done the suggested antivirus removal tips. No success.
    Please note the attached Logs.

    Stdrt.exe
    Windows Media Center Diagnostic Application
    C:\WINDOWS\temp\mrt3.tmp\stdrt.exe
    "C:\WINDOWS\TEMP\mrt3.tmp\stdrt.exe" /SF "C:\WINDOWS\System32\adbcnsl.exe" /SO94208
    C:\Documents and Settings\LocalService\Application Data\MMFApplications\
    PEB Address: 0x7ffdf000
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you using for AV protection?

    I am not finding that file in your logs, but let's do this:

    Please put ComboFix directly on your desktop, not in this folder:
    Running from: c:\documents and settings\EJ\Desktop\Tech Software\ComboFix.exe

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    ClearJavaCache::
    KILLALL::
    Driver::
    cpuz135
    
    File::
    c:\docume~1\EJ\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys
    C:\Antivirus Protection.lnk
    
    Folder::
    C:\Antivirus Protection
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds