Trojan Virus affecting my anti-virus

Closed
loukas78 Posts 19 Registration date Thursday October 20, 2011 Status Member Last seen November 3, 2011 - Nov 2, 2011 at 07:37 PM
 Anonymous User - Nov 12, 2011 at 10:06 AM
Hello, guys!
It seems that bad habbits die hard...
As you may remember (especially Ambucias and Suundar) 1 week ago I installed the AVG free edition on my PC (HP Pavillon dv6000 series) after a virus infection.

Everything seemed to worked nice till yesterday night when AVG blocked a trojan attack. After a while I shut down my laptop and today first thing in the morning I found out that the winamp shortcut did not work. Moreover the AVG icon was missing from the notification area. MSCONFIG command showed that AVG starts same time with my PC but its icon was missing. I also could not operate-run AVG so I uninstalled it.
I suspect some suspicious things are going on.
I also found (through CTRL +ALT+DEL) that a strange 1159008889:2263739066.exe exist on C/WINDOWS. I downloaded avast, it found it (together with a whole bunch of other stuff) but could not eliminate it.
Can you please give me your input on what should I do? Is my PC infected again?

Thank you

P.S. During all these processes my PC has automatically rebooted 3-4 times which was also rare

63 responses

Anonymous User
Nov 7, 2011 at 10:32 AM
Try this,download

http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

Extract and copy the following script and paste it in the box


Begin copying here:
Files to move:
C:\WINDOWS\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22662_none_b54f51417cd8f970\tcpip.sys | C:\windows\system32\drivers\tcpip.sys


Click on execute


I'm not sure what you mean by importing it to services folder


I want you to save it on the desktop,Just double click on it,It should ask for YES or NO

Click on YES,make sure to back up the key as said in previous step

Restart the PC and try starting the tcp/ip netbios helper and dhcp client in services

Let me know
0
Sundar,
the avenger scan went well
http://speedy.sh/HDQvd/Mo-1.txt

For the tcpip starts but the DHCP doesn't. SHOULD WE FOCUS ON THIS LAST ONE??? IS MY LAPTOP ROOTKIT FREE?
0
Anonymous User
Nov 7, 2011 at 06:02 PM
Your PC looks clean

Did you try to add the netbt registry fix ,restart and check the services?
0
Anonymous User
Nov 7, 2011 at 07:01 PM
Add netbt.reg key to registry

Open command prompt as administrator

Run these commands

netsh int ip reset resetlog.txt
netsh winsock reset catalog

Restart your PC

Try to start dhcp client and tcp/ip netbios helper now
0
1.First command not succesfull
2.The second was succesfull
3.I rebooted and FINALLY WAS ABLE TO START TCP AND THE DHCP

However, I still CAN'T BROWSE

4.the rebooting problem GONE. Rebooting time is VERY SMALL.

I think we may be close
0

Didn't find the answer you are looking for?

Ask a question
Anonymous User
Nov 8, 2011 at 02:36 AM
What error did you receive for winsock reset?


Give this a try now

https://www.softpedia.com/get/Tweak/Network-Tweak/WinSockFix.shtml

Click on repair and reboot,if you get a run time error


Enter your Control Panel and double-click on Network Connections
Then right click on your LAN Connection
Right click on Properties
Double-Click on the Internet Protocol (TCP/IP) item
Make sure that ip address and dns has been set to be assigned automatically.


Go to Start->Run->Type CMD and click Ok. Now run this

IPCONFIG /release

IPCONFIG /renew

Type Exit

Go to device manager >>> network adapters and see if your drivers are ok

Restart your PC

Let me know
0
Anonymous User
Nov 8, 2011 at 02:42 AM
https://download.bleepingcomputer.com/farbar/MiniToolBox.exe

select all the boxes and run it>> a text file should pop up.Copy the contents and post it here

Let me know
0
1. The ip reset command was not succesfull. I got the message RESETING ECHO REQUEST FAILED. ACCESS IN DENIED. RESETING INTERFACE OK

2. THE WINSOCK command was succesfull
3. Then I run winsockfix.
4.Then I went to the Local Area Connection. It was trying to identify the connection. I checked the stuff you said
5. the ip and the dns were OK
6. I run the ip config commands OK
7. Device manager OK
8.I restarted, run the MT box and got this report

http://speedy.sh/nsC53/MT-log.txt


Then I went BACK AGAIN to the internet connections. WENT TO LAN AND
WHEN I right clicked on, Properties I got "THE DHCP Client service is not running on this computer".
It also gave me the choice to manually restart it (EVEN THOUGH IN THE PREVIOUS SERVICE STEP I HAD STARTED IT).
I CLICK TO RESTART IT, IT RESTARTED AND THEN BOOM INTERNET IS BACK

Whats should our last checks be? Honestly speaking after SO MUCH WE HAVE GONE THROUGH I TRUST NO ONE (except you of course). WHY THE HELL SOME PEOPLE CREATE SO HARMFULL STUFF????

I REALLY REALLY NEED YOU TO BE SURE THAT MY PC IS FINE IN ORDER TO CLOSE THE THREAD-NIGHTMARE
0
Guess what? The nightmare keeps on!
Well, after all the above described steps I restarted PC and AGAIN I HAD NO CONNECTION.

I went back to LAN and found that the connection was trying to identify....
I right clicked, diagnose AND AGAIN I GOT THE DHCP Client is not working etc.

I restarted the DHCP and I was able to browse again.

Conclusion: EVERY TIME I REBOOT THE DHCP Client needs some short of activation. HOW SHOULD I MAKE IT TO START AUTOMATICALLY???
0
I just went to services, view, dhcp. IT IS SET TO THE AUTOMATIC START UP.
I am really confused
0
Anonymous User
Nov 8, 2011 at 08:02 AM
Lets discuss that after scans gets over
0
Anonymous User
Nov 8, 2011 at 07:57 AM
Grt job!!! we have got some output

Virus writers make a living out of these harmful stuffs.This will continue and we should start being more secure while surfing.

I want you to do this

Go to start and type

services.msc and press enter

Go to DNS client,right click >>properties

Change the startup type to automatic.

Do this to DHCP client service too.

Now go to start and type
cmd and press enter and run this command

ipconfig /flushdns


Now update malwarebytes and run a scan


Now download this

https://support.kaspersky.com/downloads/utils/tdsskiller.exe

Run a scan,let me know if it finds something

Download this

http://public.avast.com/~gmerek/aswMBR.exe

Launch it ,click on SCAN ,wait for scan to get completed.

After scan gets over ,click on SAVE LOG ,please post the log contents here


Download this

https://www.softpedia.com/get/Antivirus/Dr-WEB-CureIt.shtml


Launch it,Click Cancel on first screen(Do not run emergency scan)

Click No when asked to purchase

Click start to start scanning.

Let me know if it finds anything

Now run this online scanner

https://www.eset.com/?country=FR&path=/us/online-scanner



After running all this,Please post the zhpdiag log,so that we can see if there are any more traces

good luck
0
I did the dns and DHCP. THEY WERE ALREADY SET TO AUTOMATIC
Then typed the commands and got COULD NOT FLUSH THE DNS RESOLVER CACHE. FUNCTION FAILED DURING EXCUTION.

Currently I am running the malware scan
0
Anonymous User
Nov 8, 2011 at 09:21 AM
Did you start the dns service and try
0
Here is the set of txt. files

http://speedy.sh/Gtkdg/eset.txt
http://speedy.sh/bkNVU/MBR.txt
http://speedy.sh/jNnKH/tds-rep.txt
http://speedy.sh/gnvAM/We-mb.txt
http://speedy.sh/UvD9E/ZHPDiag.Txt


Generally speaking they went pretty good. Only the eset scanner found noticeable threats.
The Dr.Web log file is missing. However, it recognized only wmconverter.exe as a trojan and deleted it.

The internet browsing remains the same. Please we need to solve this issue. I did not use to have it before.
0
Anonymous User
Nov 9, 2011 at 10:17 AM
Step 1:

Go to run and type

combofix /uninstall

That should uninstall your combofix.

Similarly uninstall malwarbytes

Remove all the tools used till now.

Run this

https://support.microsoft.com/en-us/help/2970908/how-to-use-microsoft-easy-fix-solutions


Restart

Open command prompt as administrator and run this command

netsh winsock reset

see if it works now

Go to run and type

sfc /scannow


go to start and type

services.msc and press enter

Now Right click on DHCP client >>properties>>Dependencies

Check if all other dependency service,startup type has been set to automatic.

Let me know
0
Suundar, I tried to uninstall all these programs.
HOWEVER, AFTER THAT

MY PC IS RUNNING CRAZY, THE WINDOWS EXPLORER IS RESTARTING, STOPPING AND RESTARTING CONTUINUOUSLY.

Please I really need your help on how to stop this. Its urgent. This thing repeats itself every 5 sec
0
Anonymous User
Nov 9, 2011 at 04:31 PM
Ok cool,lets try this

boot into safemode with networking

go to run and type

msconfig and click ok

change startup type to selective

uncheck ''Load startup items''

Go to service tab-check mark ''hide microsoft services'' and then click on ''disable all''
Reboot now

See if system becomes stable in normal mode
0
It comes up even in safe mode with network!!!
0
Anonymous User
Nov 9, 2011 at 05:02 PM
do you receive any error?

Restart your PC

select '' last known good configuration and try to boot into it
0
same problem again
0
Anonymous User
Nov 9, 2011 at 05:15 PM
Boot into safemode and check for previous system restore points

Restore the PC
0
Anonymous User
Nov 9, 2011 at 05:20 PM
If you dont have any previous restore point
Launch task manager

Click on process tab

See if you can see any suspicious process

Now select explorer and end the process

Now go to file>>new task and type

explorer and click ok

Let me know
0
Did 2 things
1st. I rebooted, pressed F8 , then went to system restore. The PC had two restore points. I used the oldest one (5-6hrs ago) but no luck. AGAIN the same problem even though I suspect that the desktop folders etc. after the introduction of the restore point was the same as the last one
2nd. I rebooted in normal mode, hit CTR ALT DEL then end the explorer.exe process. Then I went to run, typed msconfig and under the general tab I checked selective start up and load system services. Then went to services chose hide all microsoft services and disable all, apply and restart.

I still have the problem but I feel that by accessing through this way msconfig we could solve it
0
Small correction: I did not go to run (since is inaccessible) but I went to FILE, NEW TASK AND TYPED MSCONFIG JUST IN CASE IT WORKED AND IT REALLY WORKED. SO I CAN NOW ACCESS MSCONFIG
0
Anonymous User
Nov 9, 2011 at 08:28 PM
Run a scan with malwarebytes,lets see
0
Currently I am running malware after lots of tricks. If it doesn't find anything what you suggest to do? Should I run the microsoft fix tool?
0
Anonymous User
Nov 10, 2011 at 01:30 PM
Can you say me the current status of the PC?

Is your PC alright except for DHCP issue?
0
No no no
I still got the problems of WINDOWS explorer starting up and stopping and restarting etc.
In order to run malwarebytes I did the following:
1. Plugged in my usb to the port
2. I stopped windows explorer through CTRL ALT DEL
3. I then clicked FILE NEW TASK AND INSTALL THE MALWARE.EXE. I am able to run it even though I suspect it wont find anything

Conclusion : THE WINDOWS EXPLORER PROBLEM PERSISTS DESPITE THE SYSTEM RESTORE POINT (which I believe wasn't so old as to go my PC in a former state)
. The reboots happen every 5 sec!!!
0
Not to mention that while doing all these I see no desktop icons since the explorer.exe has been stopped...
0
Anonymous User
Nov 10, 2011 at 01:59 PM
go ahead and run combofix once again
0
Here is the log suundar

http://speedy.sh/yRT2z/CF-log-Th.txt

Something to mention: While CF was running I have ended the explorer.exe process and it didn't reboot.

HOWEVER, AS SOON AS CF finished (AND THE LOG FILE POPPED UP) then all the sudden the windows explorer started rebooting again (by its own!!!)
0
Supposing I get your explorer.exe file I guess the list of tasks to do is :
1. Uninstall avast, lavasoft and vipre
2. Run the sfc command
3. Use the explorer (how?)

Is this right?
0
Anonymous User
Nov 11, 2011 at 01:52 AM
do not run sfc /scannow

Uninstall security softwares is secondary..let me know if replacing the clean copy works
0
Anonymous User
Nov 11, 2011 at 06:29 PM
loukas78

Check your mail id
0
your second email doesn't have an attachement...
0
Anonymous User
Nov 12, 2011 at 01:38 AM
check your mail now
0