Infected - Memory Virus - Logs Attached

Status
Not open for further replies.

Zayan

Posts: 13   +0
I had a worm in my computer which infected all my ' .exe ' files.

I made a comprehensive virus scan which removed all traces of the virus. And now all my programs work properly EXCEPT iTunes which still shows this error :

' The instruction at 0x71751040 referenced memory at 0x71751040. The memory could not be read ' .

I tried re-installing,repairing and everything but I still fail. I included the 3 logs . Help please :) ?
 
Um. No.1 Remove Limewire (that's kinda a must ;) )

Next:

-> No action taken on MBAM scan, for found issues
Download and Run Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected. <========= Not Done

Please re-run Malwarebytes
Confirm updated (third tab)
Then do the above quoted message, but this time "Remove all found issues"

By the way, you will need to then restart, and run (and attach) a new HJT log
 
Well they suspected HijackThis as an issue thus I figured I shouldn't remove. You still want me to remove it ?
 
I'm not sure what you exactly meant. But if it helps I service hundreds (about 300) TechSpot members a week. And I pride myself on Security (Virus\Malware removal)

Just do as I say ;) :D

But your choice and all
 
Um Hm

It is possible I may be taking a break
I just saw your post come in, and noticed horrible Limewire and thought I'd post
Thankfully there are other Malware specialists here, so if I'm not about, I hope they decide to help.

Otherwise I'll check back later :grinthumb
 
Please startup HijackThis Scan again
Place a tick alongside the following entries
Close all\any Internet browsers, and select Fix
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O8 - Extra context menu item: &Clean Traces - E:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - E:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - E:\Program Files\DAP\dapextie2.htm
O13 - Gopher Prefix:
Download Combofix
Lots of info on its use h e r e
Direct download h e r e

Locate the downloaded Combofix. Double click on it to run, answering any prompts along the way
Note: during Combofix scan (lasting up to 10mins) your Desktop and clock may reset (all normal)
ComboFix will also restart your computer (eventually) and then (eventually) create a log

Save this log file to be attached to a new reply

Also do another scan with HJT (scan and log file) and attach this to a new reply as well
 
It seems that Limewire and Bittorent are still running
Please note, it is impossible to remove infection on a computer with filesharing programs still running (by the way, these programs installed, means running - ie It allows full or part share to your computer)

If you feel you cannot be apart from these programs, I would highly suggest that you use a Linux Boot CD, like Ubuntu, instead.
You would be much safer, and re-infection would not be imminent, ie straight away
 
Well I removed Limewire as you told me to but kept Bittorrent as I wasn't told to uninstall. So I should uninstall and do another HJK scan ?
 
Yes

And just so I don't need to suddenly find out about any other filesharing programs (there are many available across the web)
Make sure to remove all file sharing programs

But as I mentioned above, if you are just going to re-install them (and it does sound as though you will) then there is no use continuing, (ie re-infestation highly likely)

We are up to post 12, and really haven't got very far
If you happen to notice other threads I've supported on, by Post #12, the thread is usually fully completed. This one looks like we are starting again :confused:

I should mention (warn) that I may stop supporting on this thread, if I feel I'm not getting anywhere. Basically I already feel this way now. :suspiciou
 
It looks pretty clean already. Except for some unknown "chat server"

I've decided to stop now. If others want to reply with support, go for it.

By the way, I hope we don't need to see you in a couple of days :rolleyes:
 
The only issue I have is everytime I try to start iTunes it gives me this message :

' The instruction at 0x745a1040 referenced memory at 0x745a1040. The memory could not be read. '

I had a worm in my computer which I took care of completely and the virus does not show up on the scanner. As the logs ( submitted above ) show updated full system scan using both the malware and spyware program you have asked to use. Could you help :( ?

If you require anything I'm waiting.
 
Go into Control panel Programs and features and uninstall Itumes Ipod, applle quicktime and Bonjour .

Then reboot and run CCleaner Temps then on left Panel Registry then scan for issues. Run both repeatedly until clean.

Then do the below..

Download Win2003 Resource Kit, then install, must be to the default location do not change. It is fully compatable with XP even tho it says 2003.

http://www.microsoft.com/downloads/...69-57ff-4ae7-96ee-b18c4790cffd&displaylang=en

Then do the below

Left Drag mouse and Copy for Pasting all text in the box below. Make sure the slider bar goes to bottom from the @ to the end of the second exit.

Then paste to the black screen of an open command prompt
Code:
@echo off
:: Fix Access denied
cd /d "C:\Program Files\Windows Resource Kits\Tools"

subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f

secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose
exit
exit

This will take perhaps 30 mins to an hour depending on Processor, disk speed and size of registry.

After the above finishes reboot an install Itunes.

Mike
 
mflynn. BRILLIANT MY FRIEND BRILLIANT :D.

Works perfectly so far ! Will give an update if it syncs with the iPod perfectly. Thanks :D !
 
Good!

Thread Closing-------------------------------------------------------------------

Some of these tools update so often they require downloading again later if needed. But keep and run MBAM and SAS to maintain.

Remove ComboFix
Start-Run
type
combofix /u
Hit enter or click OK.

Please download OTCleanIt http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe

Save to desktop.

This will remove all the tools we used to clean your computer.


Double-click OTCleanIt.exe. Click CleanUp. Yes to the "Begin cleanup Process?"

Approve all if prompted by Firewall. Approve Widows Defender or other guards or security programs while OTCleanIt attempting access to the Internet to allow all.

If prompted to Reboot click, Yes.
OTCleanit will delete itself when finished, If not delete it by yourself.

-------------------------------------------------------------------------------------
Run CCleaner http://www.ccleaner.com/download/builds (get SLIM at bottom no Yahoo toolbar)
Run twice or more on Cleanup temps, then on left click Registry then Scan for issues also repeat till clean.

Run ATF-Cleaner http://majorgeeks.com/ATF_Cleaner_d4949.html Temp and Registry, repeatedly until no more found.

KCleaner ftp://ftp2.kcsoftwares.com/kcsoftwa/files/kcleaner.exe
Fantastic cleaner.
-------------------------------------------------------------------------------------
The issues can and are likely found is in System Restore so do the below

Start-Programs-Accessories-System Tools-Disk- System Restore and create a new Restore point. Name it "After cleanup at TechSpot".

Then Start-Programs-Accessories-System Tools-Disk Cleanup
Click OK to accept C:
Select all Boxes
Then click More Options
Here click System Restore and OK to "Are you sure" and the OK to Run.

As this runs it clears all but the most recent Restore Point but it does one other thing that can contain infested files and a huge amount of disk space.

It clears what is known as Shadow copies which are used by specialized back up programs.

This is if you have the Volume Shadow Copy running which is the default.
-------------------------------------------------------------------------------------

Every two weeks or so, run MBAM and SAS until clean.

They take a while, so leave scanning while you are sleeping working or watching TV. If not done under the gun they can be scheduled not to interfere with computer time.

If they find something they can not clean, then get back to us.

Additionally run CCleaner. ATF-Cleaner and KCleaner.
----------------------------------------------------------------------------------------
I have been using ThreatFire for more than a year, it just went from ver 3 to ver 4.

It was designed to be used with and to co-exist with other Virus scanners.

Additionally it uses a totally different process to protect. While conventional Virus scanners work from definitions ThreatFire works on recognizing Virus/Malware activity.

It's like looking at it with 2 sets of eyes and from a different angle.

It works like some Firewalls do to learn what is good/bad.

After install it will ask you about everything that could be a security issue. For example the first time you run IE or FireFox it will prompt you. You would answer to approve and remember the setting. From then on no more prompts about IE or FireFox unless the exe changes like in an update.

As it queries you about the prompt to help you determine to approve or not you can google it with one click.

http://www.threatfire.com/Download/
-------------------------------------------------------------------------------------
Look at http://www.javacoolsoftware.com/spywareblaster.html

Run SpyBot ocassionally and use the Immunize function.
http://www.safer-networking.org/en/download/

I highly reccomend Hostman: Hostman http://majorgeeks.com/HostsMan_d4592.html

Download install run and allow it to disable DNS Client and select all Host files and then Update and install all host files.

A Disk Scan (chkdsk) and Defrag are in order.

Mike
 
Status
Not open for further replies.
Back