
Hijackthis log
#61
Posted 13 November 2006 - 09:07 PM
Register to Remove
#62
Posted 14 November 2006 - 01:53 AM
I suggest that you disconnect this computer from the internet, to prevent the infection pulling in more nasties. Until we get it fixed, it unlikely that your McAfee programs are working. If you have another computer, I suggest that you use this to post and download any tools and only connect the infected one if I ask you to run an online scan. If you don't have another computer, please only connect this one for the minmum time necessary. Only reboot the computer if absolutely necessary.
I would like you to download and run a tool that has been developed to fight a very similar infection. Download it to your desktop from: http://noahdfear.gee...com/FindAWF.exe, double-click to run the program and post the log here (awf.txt). Please also post a new HijackThis log.
I will let you know more once I have had a chance to do some research on this trojan.
Honors Graduate of MalWare Removal University - A Cooperative Effort with What the Tech Classroom
Member of the Alliance of Security Analysis Professionals (ASAP)
#63
Posted 14 November 2006 - 03:03 PM
#64
Posted 14 November 2006 - 03:13 PM
Important: Make sure that you are not connected to the internet while in Safe Mode.
Boot to Safe Mode. To do this:
- Restart your computer.
- Continually tap the F8 button as your computer is booting a menu appears.
- Use up-arrow key to select Safe Mode and press Enter.
If this works, please post the report (awf.txt). Otherwise let me know. Don't worry about the HijackThis log at the moment.
Good luck!
Honors Graduate of MalWare Removal University - A Cooperative Effort with What the Tech Classroom
Member of the Alliance of Security Analysis Professionals (ASAP)
#65
Posted 14 November 2006 - 04:42 PM
#66
Posted 14 November 2006 - 06:02 PM
In the meantime, there's one thing I'd like you to try:
In normal mode...
Copy the link location: http://noahdfear.gee...com/FindAWF.exe
Open Internet Explorer and paste the link into the address bar.
When the download box opens, click on Run instead of Save
Allow the file to run when you get the warning.
A black window should open.
If this works, let the program run.
When it finishes, Notepad will open.
Copy and paste the contents of that text file here.
<EDIT>If 'McAfee comes up with a warning, close the window or click on No/Cancel. Don't click OK</EDIT>
Edited by beynac, 14 November 2006 - 06:38 PM.
Honors Graduate of MalWare Removal University - A Cooperative Effort with What the Tech Classroom
Member of the Alliance of Security Analysis Professionals (ASAP)
#67
Posted 15 November 2006 - 02:32 PM
-----------------------------------------------------------------------------
First, please try what I suggested in my previous post, if you have not already tried it. I repeat the instructions here:
Note: If 'McAfee' comes up with a warning, close the window or click on No/Cancel. Don't click OK
In normal mode...
Copy the link location: http://noahdfear.gee...com/FindAWF.exe
Open Internet Explorer and paste the link into the address bar.
When the download box opens, click on Run instead of Save
Allow the file to run when you get the warning.
A black window should open.
If this works, let the program run.
When it finishes, Notepad will open.
Copy and paste the contents of that text file here.
--------------------------------------------------------------------------------
Next. please download the following programs to your desktop (don't run them yet):Disconnect from the internet. Reboot before reconnecting to post the log, but don't forget to make sure you have it safe first.
--------------------------------------------------------------------------------
We need to make sure that none of the following processes are running. To check, you need to press the Ctrl+Alt+Del keys to open Task Manager. Click on the Processes tab and then click on Image Name (this will put the processes in order). If any of the following are running, right-click on them and select End process.
hkcmd.exe
igfxpers.exe
igfxtray.exe
mcagent.exe
mcdetect.exe
mcmnhdlr.exe
mcregwiz.exe
mcshield.exe
mctskshd.exe
mcupdate.exe
mcvsshld.exe
mmtask.exe
MotiveSB.exe
MpfService.exe
MpfTray.exe
mscifapp.exe
oasclnt.exe
qttask.exe
tfswctrl.exe
VerizonSupport.exe
If this doesn't work with any (or all) of these, please continue with the rest of the instructions.
--------------------------------------------------------------------------------
FindAWF
Double-click on FindAWF.exe to run the program and post the log here (awf.txt)
-------------------------------------------------------------------------------
ComboFix by sUBs
This is another tool that could give us the information, if we can't get FindAWF to run.
- Close all open windows.
- Double click combofix.exe & follow the prompts.
- When finished, it will produce a log for you. Post that log in your next reply
Please split the log into separate posts to ensure that they don't get cut off. It is important that I see the full log.
------------------------------------------------------------------------------
Good luck with this!
Honors Graduate of MalWare Removal University - A Cooperative Effort with What the Tech Classroom
Member of the Alliance of Security Analysis Professionals (ASAP)
#68
Posted 15 November 2006 - 04:04 PM
#69
Posted 15 November 2006 - 04:05 PM
#70
Posted 15 November 2006 - 04:24 PM
Register to Remove
#71
Posted 15 November 2006 - 04:25 PM
#72
Posted 15 November 2006 - 04:38 PM
Honors Graduate of MalWare Removal University - A Cooperative Effort with What the Tech Classroom
Member of the Alliance of Security Analysis Professionals (ASAP)
#73
Posted 15 November 2006 - 05:26 PM
#74
Posted 15 November 2006 - 05:27 PM
#75
Posted 15 November 2006 - 05:38 PM

Honors Graduate of MalWare Removal University - A Cooperative Effort with What the Tech Classroom
Member of the Alliance of Security Analysis Professionals (ASAP)
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users