We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help Please Trojan

2»

Comments

  • RussJK
    RussJK Posts: 2,359 Forumite
    Cheers for that, looks a lot better. How did you go with the full Malwarebytes scan that you said you were running? If you haven't already started it, try these quicker steps first

    1. Can you confirm that C:\Windows\system32\DllHost.exe has been deleted?
    2. Try HitmanPro again now that you are in normal mode
    3. Try Tdsskiller again, usually only malware prevents it running
    4. Try aswMBR again, shouldn't reboot
  • vanilla
    vanilla Posts: 3,277 Forumite
    The Malwarebytes scan was started half an hour ago.
    Glad it's looking better because i wouldn't have a clue.:o
    C:\Windows\system32\DllHost.exe has been deleted.

    I'll post the log when Malwarebytes is finished..
    Sometimes it seems that the going is just too rough.
    And things go wrong no matter what I do.
    Now and then it seems that life is just too much.
    But you've got the love I need to see me through.
    :j :j
  • GunJack
    GunJack Posts: 11,913 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    RussJK wrote: »
    That's a long full scan ;)

    mbam full scans can easily take an hour and a half, depending on what hardware the pc is and how much stuff is on the hdd...... patience russ ;)


    On a more serious note, this one is a clear candidate for running combofix probably as a belt'n'braces measure this far through the cleanup, and possibly should have been run earlier (would have advised as such if I'd had the chance....kids, eh ??)

    Also, I'd be inclined to ditch mcrapafee and use avira or avast :)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • RussJK
    RussJK Posts: 2,359 Forumite
    edited 4 June 2011 at 11:04PM
    I'd first rather see if tdsskiller and aswMBR are working now that the worm has been removed. It was probably the worm causing the startup problem. You'll notice in the other thread that Combofix was prevented from completing it's task, so definitely not a cure all.

    Can get to Mcafee and general cleanup later on... only just gotten it to boot in normal mode, patience gunjack :)

    Longest Malwarebytes scan I've seen was 1hr 57 minutes, don't doubt it can be even longer. Takes 15 times longer on my laptop to do a full scan than a quick scan ;)
  • GunJack
    GunJack Posts: 11,913 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Russ, personally I would've used cf on this earlier as it can often pick up rootkits and reboot and restart the pc to remove them as part of the scan. It's often quicker and also if it won't operate another good indicator of more deep-rooted problems. Soz, missed t'other thread, not had much chance to hang in here last few days...
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • GunJack
    GunJack Posts: 11,913 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    RussJK wrote: »
    Edit: I won't be on so much either for the next week or so, on my way to Wales ;)

    y'll have to pop in for coffee :D
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • debitcardmayhem
    debitcardmayhem Posts: 13,219 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    How do you get two whales in a mini, down the M4 and over the bridge, spelling is no better than my old jokes. Look on the bright side Russ there's no toll to get back to the civilised world :beer:
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • RussJK
    RussJK Posts: 2,359 Forumite
    How do you get two whales in a mini, down the M4 and over the bridge, spelling is no better than my old jokes. Look on the bright side Russ there's no toll to get back to the civilised world :beer:
    That's bad even for you :D
  • vanilla
    vanilla Posts: 3,277 Forumite
    edited 5 June 2011 at 7:31AM
    Sorry scan took an hour and a half....new log

    Malwarebytes' Anti-Malware 1.51.0.1200
    www.malwarebytes.org
    Database version: 6772
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 9.0.8112.16421
    04/06/2011 23:35:18
    mbam-log-2011-06-04 (23-35-18).txt
    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 306820
    Time elapsed: 1 hour(s), 23 minute(s), 34 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)

    Hitmanpro is clear.
    Avast is fine too.
    Nothing happens when i try to download Tdsskiller.

    Thanks again for all the help...
    Sometimes it seems that the going is just too rough.
    And things go wrong no matter what I do.
    Now and then it seems that life is just too much.
    But you've got the love I need to see me through.
    :j :j
  • RussJK
    RussJK Posts: 2,359 Forumite
    :)
    http://support.kaspersky.com/downloads/utils/tdsskiller.exe

    Afterwards make gunjack happy and run Combofix. Read the instructions, you'll need to disable McAfee or it can't run properly:
    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    I'm travelling soon so won't be able to help except maybe in the evening. Good luck!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.5K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.5K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.5K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.