kyokushin Posted May 20, 2012 ID:553106 Share Posted May 20, 2012 Hello everybody,i have a quite big problemi borrowed a usb drive from a friend and it was infected by something very powerful i will try to discribe all symptoms i could not run softwares like ccleaner, i can only run MBAMi could not run online scans in internet all pages related to online scan refuse to open in all my browsers (IE, Firefox, Chrome)i could not install any antivirus software i tried to install avast, zonealarm but once i click it stops a few seconds laterMBAM detects a lots of trojan (PUM.Disabled.SecurityCenter or virus.sality ...), i delete them i restart but they come backi found them hereHKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter)HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter)HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Heuristics.Shuriken)C:\RECYCLER\S-1-5-21-1292428093-1972579041-1417001333-1003\Dc20.exe (Malware.Packer.Gen)D:\cmym.exe (Malware.Packer.Gen)i have no clue how to solve this problemcan some one give me a help please Link to post Share on other sites More sharing options...
MrCharlie Posted May 21, 2012 ID:553250 Share Posted May 21, 2012 Welcome to the forum, please start at the link below:http://forums.malwar...?showtopic=9573Post back the 2 logs.....DDS.txt and Attach.txt<====><====><====><====><====><====><====><====>Next.......Please remove any usb or external drives from the computer before you run this scan!Please download and run RogueKiller.For Windows XP, double-click to start.For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.Click Scan to scan the system (don't run any other options, they're not all bad!)Post back the report.MrC Link to post Share on other sites More sharing options...
kyokushin Posted May 21, 2012 Author ID:553352 Share Posted May 21, 2012 Hi,Thank you for your reply, here are the 3 files attached.I have another symptom related :I could not start my computer in safe mode after a few moments it reboots again.I am really desperate Thank you for your help.attach.txtdds.txtRKreport1.txt Link to post Share on other sites More sharing options...
MrCharlie Posted May 21, 2012 ID:553356 Share Posted May 21, 2012 Run RogueKiller again and delete all of these:¤¤¤ Processus malicieux: 1 ¤¤¤[sUSP PATH] tcrs.exe -- C:\DOCUME~1\T\LOCALS~1\Temp\tcrs.exe -> KILLED [TermProc]¤¤¤ Entrees de registre: 5 ¤¤¤[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> FOUND[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> FOUND[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> FOUND[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND----------------------------------------Then.......Please download and run ComboFix.The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.Please visit this webpage for download links, and instructions for running ComboFixhttp://www.bleepingc...to-use-combofixEnsure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Information on disabling your malware programs can be found Here.Make sure you run ComboFix from your desktop. Please include the C:\ComboFix.txt in your next reply for further review.---------->NOTE<----------If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.MrC Link to post Share on other sites More sharing options...
kyokushin Posted May 22, 2012 Author ID:553796 Share Posted May 22, 2012 Sorry, but i don't know how to delete themshould i go to the folder and delete or should i do it with Rogue? Link to post Share on other sites More sharing options...
kyokushin Posted May 23, 2012 Author ID:553893 Share Posted May 23, 2012 here combo fix reportthanks for your helplog combo.txt Link to post Share on other sites More sharing options...
MrCharlie Posted May 23, 2012 ID:553927 Share Posted May 23, 2012 I'll get back to RogueKiller and ComboFix, for now........Please download and run this tool.Let me know if it find anything, if it does....reboot the computer and run it again.Next.......run RogueKiller again and post the log.MrC Link to post Share on other sites More sharing options...
MrCharlie Posted May 25, 2012 ID:554615 Share Posted May 25, 2012 How are we doing??Do you still need help or can I close this post??MrC Link to post Share on other sites More sharing options...
LDTate Posted May 26, 2012 ID:554869 Share Posted May 26, 2012 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
LDTate Posted May 27, 2012 ID:555243 Share Posted May 27, 2012 Topic reopened Link to post Share on other sites More sharing options...
kyokushin Posted May 27, 2012 Author ID:555246 Share Posted May 27, 2012 Hi,Sorry for my late reply, the avg scan took 2 days for one scan with the OS and one scan while booting then i ran rogue and here is the log fileI am very worried, it seem that it is still here the malware or the virusthanks for your helpRKreport2.txt Link to post Share on other sites More sharing options...
MrCharlie Posted May 27, 2012 ID:555247 Share Posted May 27, 2012 Did the AVG find anything?? MrC Link to post Share on other sites More sharing options...
kyokushin Posted May 27, 2012 Author ID:555248 Share Posted May 27, 2012 Did the AVG find anything?? MrCYes he found almost 400 hundred things and it wrote cleared or cancelled and some of them (almost 10) say " can not open" or "can't read" Link to post Share on other sites More sharing options...
MrCharlie Posted May 27, 2012 ID:555251 Share Posted May 27, 2012 OK good, the RK scan looks OK.Please Update and run a Quick Scan with MBAM, post the report.Make sure that everything is checked, and click Remove Selected.Please let me know how it is, MrC Link to post Share on other sites More sharing options...
kyokushin Posted May 27, 2012 Author ID:555261 Share Posted May 27, 2012 OK good, the RK scan looks OK.Please Update and run a Quick Scan with MBAM, post the report.Make sure that everything is checked, and click Remove Selected.Please let me know how it is, MrCThanks for the replyDespite the fact that the Rogue log looks good i still having problems for running Ccleaner for exempleit stop floating point support not loadedi am running the malware scan right now i'll post the report while it finishes Link to post Share on other sites More sharing options...
kyokushin Posted May 28, 2012 Author ID:555393 Share Posted May 28, 2012 Here are the result of malware scan and rogue killer afteri did fast scan then complete one cause i was not satisfiedi hope this helpsthank youmbam-log-2012-05-27 (23-17-56).txtmbam-log-2012-05-27 (23-26-43)Last.txtRKreport1.txt Link to post Share on other sites More sharing options...
MrCharlie Posted May 28, 2012 ID:555417 Share Posted May 28, 2012 These you can control by going to your Control Panel > Security Center > click > "Change The Way Sercurity Center Warns Me" on the bottom left column. Make any changes there.Elément(s) de données du Registre détecté(s): 3HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Mauvais: (1) Bon: (0) -> Mis en quarantaine et réparé avec succèsHKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Mauvais: (1) Bon: (0) -> Mis en quarantaine et réparé avec succèsHKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Mauvais: (1) Bon: (0) -> Mis en quarantaine et réparé avec succèsI'm not sure what this means:(Aucun élément nuisible détecté)This one you (UAC) can set as outlined below, on or off:¤¤¤ Entrees de registre: 1 ¤¤¤[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUNDhttp://www.howtogeek...-windows-vista/--------------------------------Please run ComboFix again and post the log, MrC Link to post Share on other sites More sharing options...
kyokushin Posted May 28, 2012 Author ID:555523 Share Posted May 28, 2012 These you can control by going to your Control Panel > Security Center > click > "Change The Way Sercurity Center Warns Me" on the bottom left column. Make any changes there.I'm not sure what this means:This one you (UAC) can set as outlined below, on or off:http://www.howtogeek...-windows-vista/--------------------------------Please run ComboFix again and post the log, MrChi thank you for your replythe words you don't understand saysnothing harmful was detected = it's cleanI am on XP i'm not on vista or 7 soi did not found how to do it correctly Link to post Share on other sites More sharing options...
MrCharlie Posted May 28, 2012 ID:555529 Share Posted May 28, 2012 OK, forget about this one, my mistake:¤¤¤ Entrees de registre: 1 ¤¤¤[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUNDDid you run ComboFix?? MrC Link to post Share on other sites More sharing options...
MrCharlie Posted May 31, 2012 ID:556317 Share Posted May 31, 2012 How are we doing??Do you still need help or can I close this post??MrC Link to post Share on other sites More sharing options...
LDTate Posted June 2, 2012 ID:556938 Share Posted June 2, 2012 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts