Reply

Join Date: Aug 2009
Posts: 8
Reputation: rexassassin is an unknown quantity at this point 
Solved Threads: 0
rexassassin rexassassin is offline Offline
Newbie Poster

Help appreciated

 
0
  #1
Sep 2nd, 2009
Hi,

Yesterday I somehow got a Trojan(s) on my computer. All of a sudden my firewall
was turned off and I kept getting error messages from google installer saying the program had to shut down and asked if I wanted to send an error report. I then turned the firewall back on, and tried to run kaspersky Anti-Virus. It would not start and say it doesn't have any active components; I also couldn't run a full scan. I tried clicking on Spybot but it would never load up. I then tried Malwarebytes Anti-Maleware and the same thing happened, it wouldn't load. So I restarted the computer in Safe Mode with Networking, uninstalled Malwarebytes Anti-Maleware and then downloaded it again. when I tired to install it, it wouldn't load. I installed and ran numerous spyware softwares ad-aware counterspy and zone alarm in an effort to get rid of the infections After it was run, it was showing that I had infections. I had them removed but it couldn't remove 1 infection so it said that that infection would be removed after I restart. So I restarted and it got stuck for 20 minutes on the load up, so I shut it off and tried starting it again. When I went back into normal Windows, I still couldn't run any anti-virus/spyware programs
I also for some reason can not burn any cds after this when i put in a cd-r in the drive nothing happens on the softwre it says insert a writeable cd
What can I do next? please help Thank you.

Sincerely,
Adeel
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,003
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 757
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Help appreciated

 
0
  #2
Sep 2nd, 2009
Hi and welcome to the Daniweb forums .

==========

Try a system restore first, going back far enough to be sure it was before this infection.
Once done, try running MBA-M again. Update it first, then do a full scan and remove what is found. Be sure to restart the pc.
Post it's log when done.
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 920
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 43
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark

Re: Help appreciated

 
0
  #3
Sep 2nd, 2009
EDIT: Sorry crunchie - didn't see you. Let me get a look at this log and then I'll get out of your way.
PP

@rexassassin
Have a try with my post below before doing what crunchie requested


Please download FindIt.zip and Extract the FindIt folder to your desktop.
-- Inside the folder, you'll see RunThis.bat - DoubleClick it and let it run. (10-20 seconds)
A log should pop up - please post that for me.


PP
Last edited by PhilliePhan; Sep 2nd, 2009 at 9:02 pm. Reason: Didn't see crunchie....
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 8
Reputation: rexassassin is an unknown quantity at this point 
Solved Threads: 0
rexassassin rexassassin is offline Offline
Newbie Poster

Re: Help appreciated

 
0
  #4
Sep 3rd, 2009
Looking for cngaudit.dll


Looking for eventlog.dll


Looking for logevent.dll


Looking for netlogon.dll


Looking for scecli.dll
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 8
Reputation: rexassassin is an unknown quantity at this point 
Solved Threads: 0
rexassassin rexassassin is offline Offline
Newbie Poster

Re: Help appreciated

 
0
  #5
Sep 3rd, 2009
thanks for the assistance much appreciated
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 920
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 43
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark

Re: Help appreciated

 
0
  #6
Sep 3rd, 2009
Originally Posted by rexassassin View Post
thanks for the assistance much appreciated
Happy to help

You need to EXTRACT the the FindIt folder from the Zip to your desktop, or it won't work properly.
Rightclick on the ZIP and choose Extract All
Then run it.

-- What happened when you tried System Restore as crunchie advised? Ideally, we would like to restore your compy to a state where MBA-M and other tools can be run.


I am going to get out of crunchie's way - I've got limited time + too many cooks will ruin the broth, as they say . . .. .

Best Luck
PP
Last edited by PhilliePhan; Sep 3rd, 2009 at 6:05 pm.
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 8
Reputation: rexassassin is an unknown quantity at this point 
Solved Threads: 0
rexassassin rexassassin is offline Offline
Newbie Poster

Re: Help appreciated

 
0
  #7
Sep 3rd, 2009
also cd-r's are not being recognized by my drive please help it was working fine then all of a sudden stopped in thinking this has to do with the trojan please assist with this problem as well
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 8
Reputation: rexassassin is an unknown quantity at this point 
Solved Threads: 0
rexassassin rexassassin is offline Offline
Newbie Poster

Re: Help appreciated

 
0
  #8
Sep 3rd, 2009
when i ran that this came up



Looking for cngaudit.dll

No matches found.


Looking for eventlog.dll

C:\WINDOWS\I386\
eventlog.dl_ Wed Aug 4 2004 8:00:00a ..... 30,131 29.42 K

C:\WINDOWS\SYSTEM32\
eventlog.dll Wed Aug 4 2004 8:00:00a A.... 55,808 54.50 K

C:\WINDOWS\SYSTEM32\DLLCACHE\
eventlog.dll Wed Aug 4 2004 8:00:00a A.... 55,808 54.50 K

C:\WINDOWS\SOFTWA~1\DOWNLOAD\DD9AB5~1\
eventlog.dll Sun Apr 13 2008 8:11:54p A.... 56,320 55.00 K

4 items found: 4 files, 0 directories.
Total of file sizes: 198,067 bytes 193.42 K


Looking for logevent.dll

No matches found.


Looking for netlogon.dll

C:\WINDOWS\I386\
netlogon.dl_ Wed Aug 4 2004 8:00:00a ..... 181,419 177.16 K

C:\WINDOWS\SYSTEM32\
netlogon.dll Wed Aug 4 2004 8:00:00a A.... 407,040 397.50 K

C:\WINDOWS\SYSTEM32\DLLCACHE\
netlogon.dll Wed Aug 4 2004 8:00:00a A.... 407,040 397.50 K

C:\WINDOWS\$HF_MIG$\KB968389\SP2QFE\
netlogon.dll Fri Feb 6 2009 2:46:10p A.... 408,064 398.50 K

C:\WINDOWS\SOFTWA~1\DOWNLOAD\DD9AB5~1\
netlogon.dll Sun Apr 13 2008 8:12:02p A.... 407,040 397.50 K

5 items found: 5 files, 0 directories.
Total of file sizes: 1,810,603 bytes 1.73 M


Looking for scecli.dll

C:\WINDOWS\I386\
scecli.dl_ Wed Aug 4 2004 8:00:00a ..... 71,807 70.12 K

C:\WINDOWS\SYSTEM32\
scecli.dll Wed Aug 4 2004 8:00:00a A.... 180,224 176.00 K

C:\WINDOWS\SYSTEM32\DLLCACHE\
scecli.dll Wed Aug 4 2004 8:00:00a A.... 180,224 176.00 K

C:\WINDOWS\SOFTWA~1\DOWNLOAD\DD9AB5~1\
scecli.dll Sun Apr 13 2008 8:12:06p A.... 181,248 177.00 K

4 items found: 4 files, 0 directories.
Total of file sizes: 613,503 bytes 599.12 K
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 920
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 43
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark

Re: Help appreciated

 
0
  #9
Sep 3rd, 2009
Originally Posted by rexassassin View Post
when i ran that this came up
Those look OK to me.

Try crunchie's advice and stand by for his reply.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 8
Reputation: rexassassin is an unknown quantity at this point 
Solved Threads: 0
rexassassin rexassassin is offline Offline
Newbie Poster

Re: Help appreciated

 
0
  #10
Sep 3rd, 2009
hey crunchie i have no way of going back to august for some reasom to restore it wont click over to the previoius month arghh please advise
Reply With Quote Quick reply to this message  
Reply

Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC