Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Computer is Infected with Malware, I need Help!!!  (Read 6258 times)

0 Members and 1 Guest are viewing this topic.

thalosoe

    Topic Starter


    Starter

    Computer is Infected with Malware, I need Help!!!
    « on: August 12, 2010, 07:52:12 AM »
    Hello, My computer is infected with some bad Malware, and I can't get it out.  Whenever I turn it on, I get this error message, "Application can not be executed, computer is infected with xxxx. file."  It won't let me open any applications, or browsers, it just redirects me to this bs website, where they want me to buy a anitvirus.

    I put it in safe mode, ran Malwarebytes, Anit -Maleware, ran a scan, deleted the virus and it still is happening. 

    I can't post the log because my infected laptop wont allow me to use the internet, or wont recognize my usb storage device I plugged in to try to put the log file on it.

    Please help

    thalosoe

      Topic Starter


      Starter

      Re: Computer is Infected with Malware, I need Help!!!
      « Reply #1 on: August 12, 2010, 07:58:36 AM »
      I figured out how to get internet access in safe mode.  Below is a copy of my log:

      Malwarebytes' Anti-Malware 1.41
      Database version: 3141
      Windows 6.0.6001 Service Pack 1 (Safe Mode)

      8/11/2010 11:11:43 PM
      mbam-log-2010-08-11 (23-11-43).txt

      Scan type: Full Scan (C:\|)
      Objects scanned: 295991
      Time elapsed: 1 hour(s), 18 minute(s), 15 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 4
      Registry Values Infected: 1
      Registry Data Items Infected: 1
      Folders Infected: 1
      Files Infected: 14

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
      HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
      HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
      HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

      Folders Infected:
      C:\Windows\System32\lowsec (Stolen.data) -> Quarantined and deleted successfully.

      Files Infected:
      C:\Program Files\Sportsbook.com\bj.dll (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\casino.exe (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\directsound.dll (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\extgame.dll (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\Install.exe (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\lbyinst.exe (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\miniprocess.exe (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\plibc32.dll (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\winsound.dll (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Program Files\Sportsbook.com\temp\lbyinst.exe (Adware.Casino) -> Quarantined and deleted successfully.
      C:\Windows\System32\lowsec\local.ds (Stolen.data) -> Quarantined and deleted successfully.
      C:\Windows\System32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully.
      C:\Windows\System32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully.
      C:\Users\Mike\AppData\Local\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

      harry 48



        Egghead

      • lay back , relax and chill out
      • Thanked: 129
        • Yes
        • Yes
        • Yes
        • Dribbling Pensioner
      • Certifications: List
      • Experience: Familiar
      • OS: Windows 7
      Re: Computer is Infected with Malware, I need Help!!!
      « Reply #2 on: August 12, 2010, 08:17:48 AM »
      go to below try to complete and post the other 2 logs

      http://www.computerhope.com/forum/index.php/topic,46313.0.html

      thalosoe

        Topic Starter


        Starter

        Re: Computer is Infected with Malware, I need Help!!!
        « Reply #3 on: August 12, 2010, 10:04:25 AM »
        This log file is located at C:\rkill.log.
        Please post this only if requested to by the person helping you.
        Otherwise you can close this log when you wish.
        Ran as Mike on 08/12/2010 at 12:13:26.


        Processes terminated by Rkill or while it was running:


        C:\Users\Mike\Downloads\rkill(2).com


        Rkill completed on 08/12/2010  at 12:13:29.








        AVG 9.0 Anti-Virus command line scanner
        Copyright (c) 1992 - 2010 AVG Technologies
        Program version 9.0.832, engine 9.0.846
        Virus Database: Version 271.1.1/3064  2010-08-11

        C:\Boot\BCD Locked file. Not tested.
        C:\Boot\BCD.LOG Locked file. Not tested.
        C:\Documents and Settings\ Locked file. Not tested.
        C:\pagefile.sys Locked file. Not tested.
        C:\ProgramData\Application Data\ Locked file. Not tested.
        C:\ProgramData\avg9\Log\6aa786d2-24c0-4965-b953-34343b3c6710 Locked file. Not tested.
        C:\ProgramData\Desktop\ Locked file. Not tested.
        C:\ProgramData\Documents\ Locked file. Not tested.
        C:\ProgramData\Favorites\ Locked file. Not tested.
        C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7420a625a7ee324a4567313fadd49cfa_1b500a7e-82d7-4fba-ab32-c008b6215bf7 Locked file. Not tested.
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveUpdate Notice\LiveUpdate Notice.lnk Locked file. Not tested.
        C:\ProgramData\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\VzCdbDat.ldf Locked file. Not tested.
        C:\ProgramData\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\VzCdbDat.mdf Locked file. Not tested.
        C:\ProgramData\Start Menu\ Locked file. Not tested.
        C:\ProgramData\Templates\ Locked file. Not tested.
        C:\System Volume Information\ Locked file. Not tested.
        C:\Users\Default\AppData\Local\Application Data\ Locked file. Not tested.
        C:\Users\Default\AppData\Local\History\ Locked file. Not tested.
        C:\Users\Default\AppData\Local\Temporary Internet Files\ Locked file. Not tested.
        C:\Users\Default\Application Data\ Locked file. Not tested.
        C:\Users\Default\Cookies\ Locked file. Not tested.
        C:\Users\Default\Documents\My Music\ Locked file. Not tested.
        C:\Users\Default\Documents\My Pictures\ Locked file. Not tested.
        C:\Users\Default\Documents\My Videos\ Locked file. Not tested.
        C:\Users\Default\Local Settings\ Locked file. Not tested.
        C:\Users\Default\My Documents\ Locked file. Not tested.
        C:\Users\Default\NetHood\ Locked file. Not tested.
        C:\Users\Default\PrintHood\ Locked file. Not tested.
        C:\Users\Default\Recent\ Locked file. Not tested.
        C:\Users\Default\SendTo\ Locked file. Not tested.
        C:\Users\Default\Start Menu\ Locked file. Not tested.
        C:\Users\Default\Templates\ Locked file. Not tested.
        C:\Users\Default User\ Locked file. Not tested.
        C:\Users\Mike\AppData\Local\History\ Locked file. Not tested.
        C:\Users\Mike\AppData\Local\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
        C:\Users\Mike\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Locked file. Not tested.
        C:\Users\Mike\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Locked file. Not tested.
        C:\Users\Mike\Documents\My Music\ Locked file. Not tested.
        C:\Users\Mike\Documents\My Pictures\ Locked file. Not tested.
        C:\Users\Mike\Documents\My Videos\ Locked file. Not tested.
        C:\Users\Mike\NetHood\ Locked file. Not tested.
        C:\Users\Mike\ntuser.dat Locked file. Not tested.
        C:\Users\Mike\ntuser.dat.LOG1 Locked file. Not tested.
        C:\Users\Mike\ntuser.dat.LOG2 Locked file. Not tested.
        C:\Users\Mike\PrintHood\ Locked file. Not tested.
        C:\Users\Mike\Templates\ Locked file. Not tested.
        C:\Users\Public\Documents\My Music\ Locked file. Not tested.
        C:\Users\Public\Documents\My Pictures\ Locked file. Not tested.
        C:\Users\Public\Documents\My Videos\ Locked file. Not tested.
        C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Locked file. Not tested.
        C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Locked file. Not tested.
        C:\Windows\ServiceProfiles\LocalService\ntuser.dat Locked file. Not tested.
        C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Locked file. Not tested.
        C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp1951.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp1A96.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp30B6.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp3E54.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp412.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\csp7A6.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\cspA070.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\cspFD34.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\cspDF2E.tmp Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\ntuser.dat Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Locked file. Not tested.
        C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Locked file. Not tested.
        C:\Windows\System32\catroot2\edb.log Locked file. Not tested.
        C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Locked file. Not tested.
        C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Locked file. Not tested.
        C:\Windows\System32\config\components Locked file. Not tested.
        C:\Windows\System32\config\COMPONENTS.LOG1 Locked file. Not tested.
        C:\Windows\System32\config\COMPONENTS.LOG2 Locked file. Not tested.
        C:\Windows\System32\config\default Locked file. Not tested.
        C:\Windows\System32\config\DEFAULT.LOG1 Locked file. Not tested.
        C:\Windows\System32\config\DEFAULT.LOG2 Locked file. Not tested.
        C:\Windows\System32\config\RegBack\COMPONENTS Locked file. Not tested.
        C:\Windows\System32\config\RegBack\DEFAULT Locked file. Not tested.
        C:\Windows\System32\config\RegBack\SAM Locked file. Not tested.
        C:\Windows\System32\config\RegBack\SECURITY Locked file. Not tested.
        C:\Windows\System32\config\RegBack\SOFTWARE Locked file. Not tested.
        C:\Windows\System32\config\RegBack\SYSTEM Locked file. Not tested.
        C:\Windows\System32\config\sam Locked file. Not tested.
        C:\Windows\System32\config\SAM.LOG1 Locked file. Not tested.
        C:\Windows\System32\config\SAM.LOG2 Locked file. Not tested.
        C:\Windows\System32\config\security Locked file. Not tested.
        C:\Windows\System32\config\SECURITY.LOG1 Locked file. Not tested.
        C:\Windows\System32\config\SECURITY.LOG2 Locked file. Not tested.
        C:\Windows\System32\config\software Locked file. Not tested.
        C:\Windows\System32\config\SOFTWARE.LOG1 Locked file. Not tested.
        C:\Windows\System32\config\SOFTWARE.LOG2 Locked file. Not tested.
        C:\Windows\System32\config\system Locked file. Not tested.
        C:\Windows\System32\config\SYSTEM.LOG1 Locked file. Not tested.
        C:\Windows\System32\config\SYSTEM.LOG2 Locked file. Not tested.
        C:\Windows\System32\LogFiles\WMI\RtBackup\ Locked file. Not tested.

        ------------------------------------------------------------
        Objects scanned     : 684359
        Found infections    :    0
        Found PUPs          :    0
        Healed infections   :    0
        Healed PUPs         :    0
        Warnings            :    0
        ------------------------------------------------------------

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Computer is Infected with Malware, I need Help!!!
        « Reply #4 on: August 14, 2010, 05:18:09 PM »
        Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

        1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
        2. The fixes are specific to your problem and should only be used for this issue on this machine.
        3. If you don't know or understand something, please don't hesitate to ask.
        4. Please DO NOT run any other tools or scans while I am helping you.
        5. It is important that you reply to this thread. Do not start a new topic.
        6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
        7. Absence of symptoms does not mean that everything is clear.

        SUPERAntiSpyware

        If you already have SUPERAntiSpyware be sure to check for updates before scanning!


        Download SuperAntispyware Free Edition (SAS)
        * Double-click the icon on your desktop to run the installer.
        * When asked to Update the program definitions, click Yes
        * If you encounter any problems while downloading the updates, manually download and unzip them from here
        * Next click the Preferences button.

        •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
        * Click the Scanning Control tab.
        * Under Scanner Options make sure only the following are checked:

        •Close browsers before scanning
        •Scan for tracking cookies
        •Terminate memory threats before quarantining
        Please leave the others unchecked

        •Click the Close button to leave the control center screen.

        * On the main screen click Scan your computer
        * On the left check the box for the drive you are scanning.
        * On the right choose Perform Complete Scan
        * Click Next to start the scan. Please be patient while it scans your computer.
        * After the scan is complete a summary box will appear. Click OK
        * Make sure everything in the white box has a check next to it, then click Next
        * It will quarantine what it found and if it asks if you want to reboot, click Yes

        •To retrieve the removal information please do the following:
        •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
        •Click Preferences. Click the Statistics/Logs tab.

        •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

        •It will open in your default text editor (preferably Notepad).
        •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

        * Save the log somewhere you can easily find it. (normally the desktop)
        * Click close and close again to exit the program.
        *Copy and Paste the log in your post.
        ******************************************

        Please download: HiJackThis to your Desktop.
        • Double Click the HijackThis icon, located on your Desktop.
        • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
        • Accept the license agreement.
        • Click the Open the Misc Tools section button.
        • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
        • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
        • Please post the log in your next reply.
        Windows 8 and Windows 10 dual boot with two SSD's