Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Too Many Infection! Trojan, backdoors, hidexec.bd, etc


  • Please log in to reply

#1
MarieT

MarieT

    New Member

  • Member
  • Pip
  • 3 posts
Peace to you!

Ive used Malwarebyte's Anti malware and found 3 infections.
Files Infected:
c:\system volume information\_restore{7e101c60-0d58-4c7a-9c39-63f7fd9e9697}\RP50\A0054350.exe (Trojan.Downloader)
Files Infected:
c:\WINDOWS\system32\FlushCode.exe (Trojan.Downloader)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

AVG found over 200 infected (including tracking cookie of course)
worm.autorun.bg
trojan horse generic_c.azus
downloader.wimad.k
trojan generic12.brx
virus win32.small
trojan downloader.agent.aosk
hidexec.bd
trojan psw.onlinegames.aona



Kaspersky found: not-a-virus:RiskTool.Win32.PsKill.au
at c:\windows\psshutdown.exe

most have been deleted or moved to vault. my problem is that id like to format the whole drive but whenever i start my pc, it will require me to press F1 in order to continue on to Windows. then it will mention an error in S.M.A.R.T something...
So when i load an XP cd, i press f1 and it just leads me directly to Windows. No c prompt or anything.

Thank you for those kind souls who would want to help me. I really have no clue what else to do (i dont have much money to take it for repair).

Have a good day

Marie

Edited by MarieT, 30 June 2009 - 09:25 AM.

  • 0

Advertisements


#2
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,047 posts
Hello MarieT,

Welcome to Geekstogo.

You say you have used Malwarebytes before. If you still have it on your machine, please update and run. Post the scan report back here.

If you do not have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next
  • Please download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
So when you return please post
  • MBAM log
  • the two RSIT logs - log.txt and info.txt

Note: Unless otherwise instructed always post the logs in the forum. It is likely these reports will not fit on one post. It might be necessary to break the logs up to get them on the forum. Just use as many posts as you need, that's fine. :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP