Please download Malwarebytes'
Anti-Malware from
Here or
Here
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
I was already in Safe Mode (I can't use my computer in Normal mode) but as per your instructions, I rebooted. Ran MalwareBytes. Still won't run. McAfee is already disabled. I didn't disable it, it just won't let me enable any of my protections.
I had downloaded said Malwarebytes' program before posting here...it doesn't work for some reason. I uninstalled it and reinstalled it again after you asked me to, and still it doesn't work. I install it, but it fails to launch the program. Even when I go via Windows explorer to open it, it fails to launch.
what ever you downloaded is blocking acces to your antivirus program. i just downloaded the same herocodec and have ran into the same problem.
solution to accessing malwarebytes antimalware is enter C:/ drive then program files then search for file with name malwarebytes antimalware.exe it will have the mbam logo and rename it to newtool.exe double click the new file titled newtool.exe and run a quick scan hopefully malware bytes finds and removes the trojan im currently running same process ill post back if it succesfully removes herocodec. so far it is scanning
Ok after changing the name of the Malwarebytes, I ran the scan as per your instructions bamajim. I removed all the selected things but I still have the same problems as I did before...
here is the log :
Malwarebytes' Anti-Malware 1.36 Database version: 1945 Windows 6.0.6001 Service Pack 1
28/04/2009 12:37:25 AM mbam-log-2009-04-28 (00-37-25).txt
In fact, it's gotten worse to the point where I am no longer using the infected PC...it seems to be getting worse, crashing within shorter and shorter periods of time.
bamajim
10.4K Posts
0
April 26th, 2009 18:00
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
jo_schmo123
7 Posts
0
April 26th, 2009 19:00
I was already in Safe Mode (I can't use my computer in Normal mode) but as per your instructions, I rebooted. Ran MalwareBytes. Still won't run. McAfee is already disabled. I didn't disable it, it just won't let me enable any of my protections.
So yeah, still no go...
jo_schmo123
7 Posts
0
April 26th, 2009 19:00
I had downloaded said Malwarebytes' program before posting here...it doesn't work for some reason. I uninstalled it and reinstalled it again after you asked me to, and still it doesn't work. I install it, but it fails to launch the program. Even when I go via Windows explorer to open it, it fails to launch.
bamajim
10.4K Posts
0
April 26th, 2009 19:00
Do this
1. Reboot into Safe Mode and Run MalwareBytes in Safe Mode.
If it still won't run, Then disable McAfee and make sure it's not interfering.
If still no go then reply, and we will do it another way
sjcmac
3 Posts
0
April 27th, 2009 16:00
what ever you downloaded is blocking acces to your antivirus program. i just downloaded the same herocodec and have ran into the same problem.
solution to accessing malwarebytes antimalware is enter C:/ drive then program files then search for file with name malwarebytes antimalware.exe it will have the mbam logo and rename it to newtool.exe double click the new file titled newtool.exe and run a quick scan hopefully malware bytes finds and removes the trojan im currently running same process ill post back if it succesfully removes herocodec. so far it is scanning
jo_schmo123
7 Posts
0
April 27th, 2009 16:00
Ok after changing the name of the Malwarebytes, I ran the scan as per your instructions bamajim. I removed all the selected things but I still have the same problems as I did before...
here is the log :
Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 6.0.6001 Service Pack 1
28/04/2009 12:37:25 AM
mbam-log-2009-04-28 (00-37-25).txt
Scan type: Quick Scan
Objects scanned: 65952
Time elapsed: 2 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 12
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4443a5f1-008e-4aca-bca1-6c32c9995ce5}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4443a5f1-008e-4aca-bca1-6c32c9995ce5}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{81a98201-32c1-4cad-87d7-a966c5fd32eb}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{81a98201-32c1-4cad-87d7-a966c5fd32eb}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89fd2979-8570-4c24-8b14-e57cd03601be}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{4443a5f1-008e-4aca-bca1-6c32c9995ce5}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{4443a5f1-008e-4aca-bca1-6c32c9995ce5}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{81a98201-32c1-4cad-87d7-a966c5fd32eb}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{81a98201-32c1-4cad-87d7-a966c5fd32eb}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{89fd2979-8570-4c24-8b14-e57cd03601be}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.200,85.255.112.182 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\RECYCLER\S-7-0-53-100016057-100007656-100017134-1919.com (Trojan.Agent) -> Quarantined and deleted successfully.
sjcmac
3 Posts
0
April 27th, 2009 16:00
Youre very welcome. just finished my scan with mbam and everything has returned back to normal.
Hopefully you have similar results. If not i have one final sugestion
jo_schmo123
7 Posts
0
April 27th, 2009 17:00
I did a second malwarebytes scan after updating...and still nothing's changed...
2nd Log:
Malwarebytes' Anti-Malware 1.36
Database version: 2051
Windows 6.0.6001 Service Pack 1
28/04/2009 12:54:45 AM
mbam-log-2009-04-28 (00-54-45).txt
Scan type: Quick Scan
Objects scanned: 71938
Time elapsed: 2 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\HeroCodecSoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
bamajim
10.4K Posts
0
April 28th, 2009 09:00
jo_schmo123
Youu said 'nothings changed'. Nothing has changed since you did the second scan, or your PC is still doing the same thing?
sjcmac
3 Posts
0
April 28th, 2009 23:00
nvmd
jo_schmo123
7 Posts
0
April 30th, 2009 10:00
My PC is still doing the same thing.
In fact, it's gotten worse to the point where I am no longer using the infected PC...it seems to be getting worse, crashing within shorter and shorter periods of time.
bamajim
10.4K Posts
0
May 3rd, 2009 11:00
Your problem is not entirely malware related, but system related as well.
See if you can do this
Using Windows explorer, see if you find c:\windows\ntbtlog.txt - If it exists, delete the file.
If you are unable to do this, you may have to do a repair install