Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

A change has occurred that prevents windows...


  • Please log in to reply
4 replies to this topic

#1 bradsillars

bradsillars

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:52 PM

Posted 25 July 2009 - 08:26 PM

Hi all,

I apologize in advance if this has been covered and I missed it. You all have a wealth of information on this site, and i was unable to find anything pertaining to my dilemma in a few simple searches that I conducted prior to posting.

Here's the dilly-o

My Hardware:

HP Pavilion DV9000 Entertainment Notebook Running Vista Home Premium 32bit



I picked up a Trojan. Which started downloading all sorts of fun stuff to my machine. I ran MalwareBytes, which found about 30+ instances of infection. The search completed, and I proceeded with the cleaning, rebooted and got this message.

"A change has occurred that might prevent Windows from functioning properly", or something to that extent. I'm currently running in safe mode, as every time i boot up regularly I get this message, and when I try to proceed, it logs me out of my account, and repeats the cycle. This only started happening after the cleaning that I did so I am almost positive some critical file was deleted/altered. Here is the log file from my Malware Bytes recent scan....

Any help is greatly appreciated. I submitted for some restore discs from HP, but I'd like to see if I can rectify the situation for the time being, as I will be needing to fully use my machine before these discs arrive.


*******BEGIN*******


Malwarebytes' Anti-Malware 1.39
Database version: 2495
Windows 6.0.6001 Service Pack 1

7/25/2009 12:37:07 PM
mbam-log-2009-07-25 (12-37-07).txt

Scan type: Full Scan (C:\|)
Objects scanned: 324498
Time elapsed: 47 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 19
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 17

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\System32\hjgruiqjtiebet.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\bho_cpv.workhorse (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_cpv.workhorse.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mjcore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mjcore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{26a98aa8-07fe-46e6-b6df-26704f3b895f} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sfx (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sfx (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_CPV.dll (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\MJCore.dll (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sfxdrv (Rootkit.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Worm.Koobface) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\sfx (Rootkit.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\WWShow (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Jcore (Trojan.BHO) -> Quarantined and deleted successfully.

Files Infected:
\\?\globalroot\systemroot\System32\hjgruiqjtiebet.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\ld12.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Program Files\WWShow\WWShow.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Jcore\Jcore2.dll (Trojan.BHO) -> Quarantined and deleted successfully.
c:\program files\mozilla firefox\components\WWShow.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\sFX\SfX.DlL (Adware.Agent) -> Quarantined and deleted successfully.
c:\program files\sFX\sfX.sYs (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\VRT874A.tmp (Trojan.Inject) -> Quarantined and deleted successfully.
c:\WINDOWS\pp10.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\010112010146118114.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\0101120101464849.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\0101120101464853.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\934fdfg34fgjf23 (Worm.KoobFace) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\zodin_1248545581.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\sfjh98w3jkdmfkd.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\System32\ghaf8jkdfd.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.




Thanks all!

-Brad

Edited by bradsillars, 25 July 2009 - 08:49 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:52 PM

Posted 25 July 2009 - 08:32 PM

Hello I am moving this from XP to Am I Infected.. I will also get some experts to look.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 bradsillars

bradsillars
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:52 PM

Posted 25 July 2009 - 08:50 PM

Oops, sorry. Wasn't quite sure where it should go, noob here.

Thank you.

#4 bradsillars

bradsillars
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:52 PM

Posted 26 July 2009 - 07:21 AM

bump please

#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,072 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:52 PM

Posted 26 July 2009 - 01:16 PM

Hello sorry about the delay. It seems the best course of action is to go to the MBAM site here..
http://www.malwarebytes.org/contact.php

Submit a ticket.. This seems an issue in the software and they will help you and they are quick about it.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users