PDA

View Full Version : Unknown infection



Zalethon
2010-10-24, 08:02
DDS will not open a logfile, which bothers me a lot.

Symptoms, at this point: user accounts take a long time to load, and once they do the taskbar takes a long time to start working. (It freezes and stays that way, I'm not sure for how long) Avast is unable to connect with shields. Other than that, there are probably more symptoms that I don't know of.

I've run various antivirus programs at this point, those being Avast (including a bootup scan, but Avast has since been disabled it seems) Spybot, Malware Bytes, Super-Anti Spyware, Stinger, and some version of erunt's online scanner. They all found and removed stuff, except for erunt, which I did not complete for some reason. (The log is below, still) Erunt was the last one I ran, before trying to run DDS and coming here.

ERUNT LOG:

C:\Documents and Settings\All Users\Documents\Server\hlp.dat Win32/Bamital.EK trojan cleaned by deleting (after the next restart) - quarantined
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\27\aba135b-4291c2e2 probably a variant of Win32/Agent.FQRCZBA trojan deleted - quarantined
C:\Documents and Settings\Zalethon\Application Data\Sun\Java\Deployment\cache\6.0\23\3f3af9d7-464d4af9 multiple threats deleted - quarantined
C:\Documents and Settings\Zalethon\Application Data\Sun\Java\Deployment\cache\6.0\27\aba135b-43b157b4 probably a variant of Win32/Agent.FQRCZBA trojan deleted - quarantined
C:\Documents and Settings\Zalethon\Application Data\Sun\Java\Deployment\cache\6.0\43\556445eb-76b14efd probably a variant of Win32/Agent.DYXWUMY trojan deleted - quarantined
C:\WINDOWS\explorer.exe Win32/Bamital.EL trojan unable to clean
C:\WINDOWS\uyozoqoc.dll a variant of Win32/Kryptik.GTR trojan cleaned by deleting - quarantined
C:\WINDOWS\system32\winlogon.exe Win32/Bamital.EL trojan unable to clean
Operating memory Win32/Bamital.EL trojan

Update: I'm unable to even boot the computer now. I have done nothing but shut it down since I posted, and it restarts once it gets to about the login screen. (The login screen never loads)

It was eset, not erunt, obviously. (I'm sure that whoever is reading this gathered that, but I thought I should make that clear. I had erunt on the brain...)

ken545
2010-11-01, 10:41
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.


Sorry for the delay but the forums are very busy

Your log is showing some serious infections, this could be the cause of your computer not starting


Go to Start> Shut off your Computer> Restart
Or if the computer is off press the power button
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Last Known Good
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)


See if this helps and if not I can link you to a windows forum that can get you up and running

Zalethon
2010-11-01, 23:26
It didn't help, unfortunately.

ken545
2010-11-02, 00:34
What I am going to ask you to do is to go to this forum and post for help getting your system to start up, I think that the amount and type of viruses you had did a number on your system. They may walk you through doing a System Repair . When they get you up and running post back here and we can check your system to make sure its all clean.

http://forums.whatthetech.com/index.php?showforum=119

Like Safer its a free forum but you will need to register. I will keep this thread open for you for a week or so so post back and let me know how it went