A Trojan Making Me Crazy

Joined
Dec 13, 2009
Messages
30
Reaction score
0
i am having this problem from last few days. i am using Microsoft Security Essentials as anti virus on my Window 7 32 bit. See the screen shot attached. even after doing the full scan and also deleting that file manually this warning pop ups again and again. what i do?
 

Attachments

Joined
Nov 4, 2009
Messages
217
Reaction score
50
I fix a few of these every week for my clients. This is a rootkit and won't allow you to do very much on your computer. If you are able to run malwarebytes then do it but I doubt you will be able to. Get a trial version of unhackme and put it on a flash drive and install from there. Be careful with unhackme because you might delete the wrong files. This will run at boot before Windows is loaded and that's the only way to get these threats under control. I have had success using the Kaspersky or BitDefender boot disks and running a scan from their Linux virtual drives. You'll need to have your Ethernet cable plugged in so they can update their databases.

Eventually you will be able to run malwarebytes from within Windows so set it for a complete scan.

I just finished fixing a machine this morning and this nasty virus went too far and compromised system files so badly I had to re-install the OS.
 
Last edited:

davehc

Microsoft MVP
Joined
Jul 20, 2009
Messages
1,957
Reaction score
502
Did you delete the two items shown in th elinks at the bottom of the window
 
Joined
Dec 19, 2009
Messages
5
Reaction score
1
Use malwarebytes or a squared is another really good scanner. If those don't work do a reinstall and this time do 64 bit ;)
 
Joined
Dec 13, 2009
Messages
30
Reaction score
0
I fix a few of these every week for my clients. This is a rootkit and won't allow you to do very much on your computer. If you are able to run malwarebytes then do it but I doubt you will be able to. Get a trial version of unhackme and put it on a flash drive and install from there. Be careful with unhackme because you might delete the wrong files. This will run at boot before Windows is loaded and that's the only way to get these threats under control. I have had success using the Kaspersky or BitDefender boot disks and running a scan from their Linux virtual drives. You'll need to have your Ethernet cable plugged in so they can update their databases.

Eventually you will be able to run malwarebytes from within Windows so set it for a complete scan.

I just finished fixing a machine this morning and this nasty virus went too far and compromised system files so badly I had to re-install the OS.
dear roban, i have downloaded malwarebyte and did the complete scan and found around 109 infections of different type. i am attaching the its log please have a look. how to get rid of these infections and how i destroy it? please do me help
 

Attachments

Joined
Nov 4, 2009
Messages
217
Reaction score
50
After you did your scan there is a button labeled 'view results' when you click that button all infections will be listed with check marks and a new button 'fix errors' will be shown. Click that button. You will have to re-boot.
 
Joined
Nov 30, 2009
Messages
1,752
Reaction score
396
Whoa, 109? lol

Well yes, follow as Roban says. Then also, scan with Spybot and also XoftSpySE. They will probably find more malware too.
 

Nibiru2012

Quick Scotty, beam me up!
Joined
Oct 27, 2009
Messages
4,955
Reaction score
1,302
From looking at the log you attached, you have a LOT of keygens and activators on there. Those may be causing problems.

You really need another antivirus program besides MS Security Essentials. Download the free version of AVG AntiVirus or Avira Antivirus.

You can download Avira Free HERE

You can download AVG Free HERE

Are you running a firewall also? You should, even though the Windows 7 firewall does a fairly decent job, third-party firewalls are even better.

You can download Outpost Firewall Free HERE
 

Nibiru2012

Quick Scotty, beam me up!
Joined
Oct 27, 2009
Messages
4,955
Reaction score
1,302
Try this fix, it fairly simple to use and has worked a few time when I couldn't get other AV software to wipe the trojans, etc., clean from the drive.

Here's the install info:

SDFix is a program written by AndyManchesta that removes big amount trojans, worms, rootkits and other malwares Click here for view a list of files that can be removed.

How to use SDFix.

1. Download SDFix.
Download SDFix and save it to your Desktop.

2. Install SDFix.
Double-click on the SDFix. If a “Security Warning window opens”, click on the Run button.
Follow the prompts.
3. Reboot your computer in to Safe mode.

  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear.
  • Select the first option, to run Windows in Safe Mode.
4. Run SDFix.

  • Click Start -> Run.
  • Type the following text in type box: %systemdrive%\SDFix\RunThis.bat
  • Press Enter or OK button.
  • When the tool is finished, it will produce a report for you.
Questions and answers.

If this error message “The command prompt has been disabled by your administrator. Press any key to continue . . ” is displayed when running SDFix.
Please goto Start Menu > Run > then copy and paste the following line: %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press OK then run SDFix again
If the Command Prompt window flashes on then off again on XP or Windows2000.
Please goto Start Menu > Run > then copy and paste the following line: %systemdrive%\SDFix\apps\FixPath.exe /Q Reboot and then run SDFix again
If SDFix still doesnt run check the %comspec% variable.
Goto Start Menu > Right click My Computer > click properties > click Advanced Click Environment Variables and check that the ComSpec variable points to cmd.exe %SystemRoot%\system32\cmd.exe
Try this, it works! Believe me. :)

Let us know if it works for you!
 
Last edited:

Veedaz

~
Joined
Sep 1, 2009
Messages
1,988
Reaction score
374
Nibiru2012 wrote
Windows 7 firewall does a fairly decent job
Yes it is a good firewall but needs setting up for outbound connections (as with Trojans inviting there little friends to your Computer) but there is a very good freeware tool Windows 7 Firewall Control, with this application you can control inbound and out bound connections, read more at the site ...

Link > http://www.sphinx-soft.com/Vista/order.html
 
Joined
Sep 12, 2009
Messages
133
Reaction score
29
Hi there

Please download ComboFix from one of these locations:

Link 1
Link 2

Rename it to spoon.exe before saving it to your desktop.

Double click on the renamed ComboFix.exe & follow the prompts.


  • When finished it will produce a log at C:\ComboFix.txt for you
  • Please include the log in your next reply.
 
Joined
Sep 12, 2009
Messages
133
Reaction score
29
You may also want to change your downloading habits...

D:\Soft\MyWebFaceSetup2.3.50.53.GRman000.exe (Adware.MyWebSearch) -> No action taken.
D:\Soft\ZwinkySetup2.3.50.53.ZJman000.exe (Adware.MyWebSearch) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\ACDSee 9.0 Photo Manager Keygen Rus\Keygen\Keygen 9.0.108 Std.exe (Trojan.Downloader) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe Acrobat 8.0 Keygen\Adobe Acrobat 8 Pro Keygen.exe (Backdoor.Bot) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe Contribute CS3 Keygen\Adobe Contribute CS3 Keygen.exe (Trojan.Agent) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe CS3 Web Premium Keygen\Adobe CS3 Web Premium Keygen.exe (Trojan.Agent) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe CS3 Web Premium Keygen\Adobe Web Premium CS3 Keygen + Activation.exe (Trojan.Agent) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe Dreamweaver CS3 Keygen\Adobe Dreamweaver CS3 Keygen.exe (Trojan.Agent) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe Dreamweaver CS3 Keygen\DreamWeaver CS3 Keygen + Activation.exe (Trojan.Horst) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe Photoshop Extended CS3 Keygen\PhotoShop CS3 Extended Keygen + Activation.exe (Trojan.Horst) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\Adobe CS3 Design Premium Keygen\Adobe CS3 Design Premium Keygen.exe (Trojan.Agent) -> No action taken.
D:\Soft\Keygen 2008\Keygens 2008\Keygen 2008\TuneUp_Utilities_2008\keymaker.exe (Trojan.Agent) -> No action taken.
D:\Soft\Real_Player_11.0.9.372_Premium\Activator.exe (Trojan.Agent) -> No action taken.
D:\Soft\Real_Player_11_Plus_Gold.vndownload.org\Real Player 11 Plus Gold\rp11_Activator.exe (Trojan.Agent) -> No action taken.
D:\Soft\Internet Download Manager v5.15.2.0 By Kamran_The_King\keygen\Keygen.exe (Malware.Tool) -> No action taken.
D:\Soft\Video Get\VideoGet v.3.0.2.47\videoget.3.0.2.47-patch.exe (Malware.Packer) -> No action taken.
D:\Soft\FBI Tools 11in1\FBI Tools 11in1\11 FBI Tools\disk investigator 1.4.exe (Trojan.Downloader) -> No action taken.
D:\Soft\Idm.5.18 Build 5.incl.patch\Patch 5.xx (2008-12-06).exe (Trojan.Agent) -> No action taken.
D:\Soft\IDSOFT.DESKICOTOY.3.3\IDSOFT.DESKICOTOY.3.3\KGN\nfoviewer.exe (Trojan.Agent) -> No action taken.
Using such software is asking for trouble. Visiting cracksites/warezsites - and other questionable/illegal sites is always a risk. Even a single click on the site can drop multiple forms of very serious malware, many of which disable your onboard protection, and System Restore.

If you install the cracked software, you are running executable files from these dubious, unknown sources. You are in effect giving these sources access to information on your hard disk, and potential control over the operation of your computer. Cracked software can also contain password stealers which steal personal and system information from your machine and has the ability send it to its accomplice web server for use by criminals. This could result in banking details being compromised meaning that you pay much more for your software than you originally would.
 
Joined
Dec 19, 2009
Messages
5
Reaction score
1
Avg free is not that good and slows down the computer. I recommend ms security essentials or avast. Or you can buy kaspersky ;) spybot slows down your computer too. Make sure tea timer doesn't run in the background if you do install spybot. I would take iobit advanced system care over spybot any day of the week though. Spybot can cause conflicts in a lot of systems and the scanner is outdated and useless if you have asc.
 

Nibiru2012

Quick Scotty, beam me up!
Joined
Oct 27, 2009
Messages
4,955
Reaction score
1,302
I'm running AVG Internet Security 2009 and my is not slow at all. It runs great!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top