Boards.ie uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Click here to find out more x
Post Reply  
 
 
Thread Tools Search this Thread
29-06-2012, 11:30   #1
oldsmokey
Registered User
 
Join Date: Aug 2009
Posts: 121
trojan, virus? what is it?

Hi,I'm no techie on the pc, but hope you can help... Am running windows 7 with AVG anti-virus...for past few days the AVG 'resident shield alert' keeps throwing up dire warnings about a windows system32services'exe...trojan horse dropper. generic..and goes on to say items resolved...then throws the warning up again 15 mins later...another warning , dont know if its related, from AVG, occasionally pops up to advise that the system is using too much memory, or to that effect...could it be this bloody trojan doing something nasty in the background?
Tried using AVG and malwarebytes to cure it to no effect...the computer won't let me do a system restore either!!
Would really appreciate some help...ta
__________________
oldsmokey is offline  
Advertisement
29-06-2012, 12:02   #2
chin_grin
Closed Account
 
Join Date: Mar 2007
Posts: 10,396
Did you do a scan in safe mode?

Malewarebytes usually sorts it out, although personally I'd get rid of AVG and install MSE instead.
chin_grin is offline  
29-06-2012, 15:24   #3
ASJ112
Registered User
 
Join Date: Jan 2010
Posts: 1,080
got a log from avg or mbam ?
ASJ112 is offline  
29-06-2012, 16:09   #4
Nothingbetter2d
Closed Account
 
Join Date: Jan 2007
Posts: 3,961
i prefer avast over mse.... mse seems to miss so many.

also spybot and mbam are good
Nothingbetter2d is offline  
29-06-2012, 16:38   #5
oldsmokey
Registered User
 
Join Date: Aug 2009
Posts: 121
Hi...I've seen logs posted by other troubled souls, no idea how to do it..if it helps, you might let me know how to get the log and i'll put it up.. just been trying to run MSE ( it was switched off, dunno why), and the damn thing keeps throwing up a 'can't run' error....grrrrr
oldsmokey is offline  
Advertisement
29-06-2012, 17:49   #6
ASJ112
Registered User
 
Join Date: Jan 2010
Posts: 1,080
The log can be viewed by clicking the Logs tab in MBAM. Copy and paste that here.
ASJ112 is offline  
30-06-2012, 15:52   #7
oldsmokey
Registered User
 
Join Date: Aug 2009
Posts: 121
Here we go...is it fixed now d'you think?...no nasties so far today...thanks all..
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.29.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Dan :: DANS-PC [administrator]

Protection: Enabled

29/06/2012 16:43:16
mbam-log-2012-06-29 (16-43-16).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 390422
Time elapsed: 1 hour(s), 29 minute(s), 58 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\Installer\{732eec09-4e70-0f7a-a81a-289489e5979b}\U\800000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.

(end)
oldsmokey is offline  
30-06-2012, 15:55   #8
yoyo
Moderator
 
yoyo's Avatar
 
Join Date: Aug 2005
Location: Dublin 6
Posts: 8,241
Quote:
Originally Posted by oldsmokey View Post
Here we go...is it fixed now d'you think?...no nasties so far today...thanks all..
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.29.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Dan :: DANS-PC [administrator]

Protection: Enabled

29/06/2012 16:43:16
mbam-log-2012-06-29 (16-43-16).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 390422
Time elapsed: 1 hour(s), 29 minute(s), 58 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\Installer\{732eec09-4e70-0f7a-a81a-289489e5979b}\U\800000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.

(end)
It removed a rootkit which is quite nasty. I would run another scan with mbam/Super anti spyware and see if anything else shows up

Nick
yoyo is offline  
Thanks from:
30-06-2012, 16:32   #9
ASJ112
Registered User
 
Join Date: Jan 2010
Posts: 1,080
na definitely not fixed, download and run combofix

http://www.bleepingcomputer.com/comb...o-use-combofix


post the log it gives you.
ASJ112 is offline  
(2) thanks from:
Advertisement
02-07-2012, 10:46   #10
oldsmokey
Registered User
 
Join Date: Aug 2009
Posts: 121
ajs, you're right, booted up this am, avg 'threat detected' popup... is the combo-fix program ok to run for a tech-numpty such as meself?..I don't want the pc to end up any worse...thanks..
oldsmokey is offline  
02-07-2012, 12:34   #11
practice
Registered User
 
Join Date: Nov 2009
Posts: 180
Run the scan again and when it deletes the file,
Turn off system restore, ignore the warning and then turn it back on again.
practice is offline  
02-07-2012, 12:34   #12
yoyo
Moderator
 
yoyo's Avatar
 
Join Date: Aug 2005
Location: Dublin 6
Posts: 8,241
Quote:
Originally Posted by oldsmokey View Post
ajs, you're right, booted up this am, avg 'threat detected' popup... is the combo-fix program ok to run for a tech-numpty such as meself?..I don't want the pc to end up any worse...thanks..
Run combofix and then post the log it makes up here (C:\combofix.txt), it will probably sort your issues out. Try running it in safe mode if possible (download it onto a cd/usb key then boot machine into safemode, copy the combofix.exe to the desktop and run it from there)

Nick
yoyo is offline  
02-07-2012, 13:19   #13
ASJ112
Registered User
 
Join Date: Jan 2010
Posts: 1,080
combofix is perfectly safe to use, and should be easy enough to use for tech-numptys


Don't waste your time running AVG, its not going to be able to remove a rootkit. I wouldn't use your PC for online banking or credit card usage till you remove this by the way.
ASJ112 is offline  
Thanks from:
02-07-2012, 21:48   #14
CaSCaDe711
Registered User
 
Join Date: Aug 2009
Posts: 578
@ OP: Hope you got your machine sorted.

Excuse the language, but malware writers, what a bunch of cunt5
CaSCaDe711 is offline  
03-07-2012, 12:12   #15
oldsmokey
Registered User
 
Join Date: Aug 2009
Posts: 121
Cascade youre right..I've spent the most of a day bolli+ing with this thing..turns out malwarebytes didnt sort it..MSE can't be switched on, presumably on account of it..same with MS updates, cant turn it on...am doing a MS safety scanner scan on it now to try and sort the damn thing...a 0x80070424 error keeps coming up, and the recommended fixes don't...
oldsmokey is offline  
Post Reply

Quick Reply
Message:
Remove Text Formatting
Bold
Italic
Underline

Insert Image
Wrap [QUOTE] tags around selected text
 
Decrease Size
Increase Size
Please sign up or log in to join the discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search