Some help (again)

Status
Not open for further replies.

KnightofBane

Posts: 56   +0
Second time I've been here :/

Well, hey, again.

So... talking to my friend on AIM when he tells me about some site he is going to report to the FBI. Curiously, I told him to send me the link. I click on it then AVG starts coming up with Threat Detected messages. I panic (been clean for a long time) and start cursing at my friend for his lousy anti-virus software for not detecting it. So now we both have it. Although, I'm more pissed at mine because my computer is horrendous (Windows installer broken and so forth).

The main trojan that keeps popping up is Generic Trojan4 or something along those lines. It pops up once every time I reboot my PC after I start my browser and go to a website. I click heal but heh that doesn't seem to do squat.

So here's my symptoms since I've gotten the trojans:

-Tried to System Restore. Either a) my computer is taking forever to save my settings, or b) it's broken. Happening while restarting too.

-Everytime I download a file, my computer gives me a BSOD. I tried to download the new ewido (now AVG) from the stickies above but when I hit 'Run' to install it, I get a BSOD.

-Still trying to get my BSOD problem (or computer!) fixed with the Windows XP disk (the recovery tool thing) but my keyboard seems to... well, not work. I try to hit R to run it (chk dsk usually fixes my BSODs) but nothing happens. F3 to quit and ENTER to continue also don't work.

-Everytime I start IE7, everything is gone but the toolbar at the top that shows you what site you're on with the X, minimize etc. Have to cancel that then restart IE to get it working. I think it may be the work of Exploit.Beehappy.biz (only thing that shows up on Bazooka).

-Scanned with ewido and I got a BSOD also. At the very end of the scan BAM! BSOD.

-Also, I think my computer is getting tiny lag spikes (usually last 1-3 seconds) where I can't do anything. They happen it seems every 30 seconds to a minute. This one is pissing me off the most. Can't even play Final Fantasy 7 without my computer doing that. So if you could help me solve this problem ASAP I'd greatly appreciate it. This being solved will make working to remove this MUCH easier.

So I need some help fixing these. I may have hijack this from previously being on here. I also have Bazooka Scanner and Ad-Aware Personal (which also causes BSODs)

As you can see... pretty bad. The last thing I want to do is reformat. I have too much data to lose, even if I could move everything to my other hardrive then move it back after reinstalling Windows.

Thanks in advance.
 
Well good news is I got System Restore to work by going into Safe Mode and doing it.

EDIT: Forgot to rename, updating.
 
You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

Update.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

O4 - HKCU\..\Policies\Explorer\Run: [{1889B9A0-0A64-1033-1106-030208050001}] "C:\Program Files\Common Files\{1889B9A0-0A64-1033-1106-030208050001}\Update.exe" mc-110-12-0000272

O4 - HKUS\S-1-5-21-606747145-1409082233-725345543-1004\..\Policies\Explorer\Run: [{1889B9A0-0A64-1033-1106-030208050001}] "C:\Program Files\Common Files\{1889B9A0-0A64-1033-1106-030208050001}\Update.exe" mc-110-12-0000272 (User '?')

O16 - DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} (Panasonic Network Camera) - http://193.138.215.254/cgi-bin/SysCamInst.cab

O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://193.138.213.169/cgi-bin/bl_camera.cab

O16 - DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} (pmjpegcam Class) - http://221.251.109.90:81/JpegInst.cab

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\Program Files\Common Files\{1889B9A0-0A64-1033-1106-030208050001}\Update.exe

Reboot into normal mode and rehide your protected OS files.

Post a fresh HJT log and let me know if you`re still having problems.

Regards Howard :)

This thread is for the use of KnightofBane only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Your HJT log is clean.

What problems are you having with the Windows installer?

Maybe you could try clicking start/run and typing sfc /scannow into the run box and pressing the enter key. Windows will check for any missing or damaged OS files and replace them as necessary. You`ll need to have your Windows cd handy.

If that doesn`t help, then running a Windows repair as per the instructions in this thread HERE may well help.

Regards Howard :)

This thread is for the use of KnightofBane only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
The error I keep getting with Windows installer is:

"The Windows Installer service could not be accessed. This can occur if you are running Windows in safe mode, or the Windows Installer is not installed correctly. Contact your support for personal assistence."

This happens while installing Sony Vegas 7.

Thanks for the trojan help. Hate not having a clean machine :)
 
Yeah but I haven't been able to update for a while.

Attatched is a screenshot of what happens. Even though I select all of the updates, it fails to download them.
 
Try downloading the Windows installer from HERE. I don`t know if it`ll help.

If it doesn`t, I suggest you open a new thread in our Windows OS forum.

Regards Howard :)
 
Status
Not open for further replies.
Back