Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan.Agent/Gen-IExplorer[fake] & Trojan.Agent/Gen-PEC


  • This topic is locked This topic is locked
3 replies to this topic

#1 Crede15

Crede15

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:51 AM

Posted 01 August 2011 - 07:00 PM

I am housesitting, using my stepdad's somewhat ancient Hewlett-Packard laptop and I tried to open up a resturaunts PDF menu and the adobe reader icon came up and everything froze. The computer started running exteremely slowly and freezing after I rebooted and I've used malwarebytes and superantispyware but the same things keep showing up. I should have come here immediately but I had a virus a year or so ago and it wasn't a big problem so I figured malwarebytes would fix the problem but its been very persistent. The computer is actually running fairly well at the moment but their are a couple of odd reoccuring problems. I cannot (and this is absolutely consistent) open my email pages (I have two, a university account and a gmail account) and my flash player and java script doesn't seem to be working. I can watch youtube videos but I can't watch videos embedded on major sites (ESPN's the best example). Plus I know something's not right as malwarebytes and antispyware keep showing the same things no matter how many times I run them. I don't know if I should post my malwarebytes or antispyware logs yet as it just asks for dds and gmer logs but my first malwarebytes log was the most extensive, with 8 infected files and I got rid of most of those but ever since then its showed this:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

my superantispyware logs show two counts of Disabled.SecurityCenterOption and a Trojan.Agent/Gen-IExplorer[fake] and Trojan.Agent/Gen-PEC.

I have all the malwarebytes logs and will post them whenever somebody wants me to.

Attached Files

  • Attached File  ark.txt   11.41KB   0 downloads

Edited by Crede15, 01 August 2011 - 07:02 PM.


BC AdBot (Login to Remove)

 


#2 Crede15

Crede15
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:11:51 AM

Posted 01 August 2011 - 07:04 PM

although I thought I attached the attach file and the ark file it seems as if only the ark file was attached, here's the attach file

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 5/19/2006 4:46:43 AM
System Uptime: 8/1/2011 4:47:14 PM (1 hours ago)
.
Motherboard: Hewlett-Packard | | 309D
Processor: Intel® Pentium® M processor 1.73GHz | U1 | 1729/533mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 74 GiB total, 56.658 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}
Description: Photosmart C309a series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Photosmart C309a series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
==== System Restore Points ===================
.
RP289: 5/8/2011 1:14:50 PM - System Checkpoint
RP290: 5/10/2011 8:23:03 AM - System Checkpoint
RP291: 5/11/2011 8:02:51 AM - Software Distribution Service 3.0
RP292: 5/12/2011 9:29:19 AM - System Checkpoint
RP293: 5/13/2011 1:18:00 PM - System Checkpoint
RP294: 5/23/2011 9:39:45 AM - System Checkpoint
RP295: 6/7/2011 9:49:23 AM - System Checkpoint
RP296: 6/16/2011 9:28:28 AM - Software Distribution Service 3.0
RP297: 6/19/2011 10:18:00 AM - System Checkpoint
RP298: 6/20/2011 3:47:11 PM - System Checkpoint
RP299: 7/11/2011 10:45:59 AM - System Checkpoint
RP300: 7/13/2011 10:43:47 AM - Software Distribution Service 3.0
RP301: 7/19/2011 9:31:51 AM - System Checkpoint
RP302: 7/20/2011 4:21:39 PM - System Checkpoint
RP303: 7/27/2011 10:37:37 AM - System Checkpoint
RP304: 7/29/2011 11:12:32 AM - System Checkpoint
RP305: 7/30/2011 2:24:56 PM - System Checkpoint
RP306: 7/30/2011 5:47:29 PM - avast! Free Antivirus Setup
RP307: 8/1/2011 12:15:39 PM - Removed Norton Security Center
RP308: 8/1/2011 9:42:46 AM - System Checkpoint
RP309: 8/1/2011 12:15:33 PM - Software Distribution Service 3.0
RP310: 8/1/2011 1:05:04 PM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
Agere Systems AC'97 Modem
ALPS Touch Pad Driver
America Online (Choose which version to remove)
AnswerWorks Runtime
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Connectivity Services
AOL Spyware Protection
AOL Toolbar
AOL You've Got Pictures Screensaver
avast! Free Antivirus
B209a-m
BufferChm
CC_ccProxyExt
ccCommon
ccPxyCore
Corel Applications
Destinations
DeviceDiscovery
Easy Internet Sign-up
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService2
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Customer Participation Program 13.0
HP Help and Support
HP Imaging Device Functions 13.0
HP Photosmart Plus B209a-m All-In-One Driver Software 13.0 Rel .6
HP Print Projects 1.0
HP Smart Web Printing 4.5
HP Solution Center 13.0
HP Update
HP Wireless Assistant 1.01 B2
HP_User_Guides_0005
hpPrintProjects
HPProductAssistant
HpSdpAppCoreApp
HPSSupply
hpWLPGInstaller
Intel® Graphics Media Accelerator Driver for Mobile
InterVideo WinDVD
iTunes
J2SE Runtime Environment 5.0 Update 4
Learn2 Player (Uninstall Only)
LightScribe 1.4.31.1
LiveReg (Symantec Corporation)
LiveUpdate 2.5 (Symantec Corporation)
Malwarebytes' Anti-Malware version 1.51.1.1800
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft Money 2005
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
MSRedist
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 4.0 - SE
Network

Edited by Crede15, 01 August 2011 - 07:26 PM.


#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:51 PM

Posted 09 August 2011 - 09:30 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

Posted Image In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resouce! To tell me this, please click on http://www.bleepingcomputer.com/logreply/412419 and follow the instructions there. If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

Posted Image If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS and GMER log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


We also need a new log from the GMER anti-rootkit Scanner.

Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.

Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#4 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,704 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:51 PM

Posted 14 August 2011 - 09:35 AM

Hello again!

I haven't heard from you in 5 days. Therefore, I am going to assume that you no longer need our help, and close this topic.

If you do still need help, please send a Private Message to any Moderator within the next five days. Be sure to include a link to your topic in your Private Message.

Thank you for using Bleeping Computer, and have a great day!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users