Перейти к содержимому


Фото
- - - - -

Cannot Run Dr Web Cureit


  • Please log in to reply
5 ответов в этой теме

#1 mindbaby

mindbaby

    Newbie

  • Posters
  • 3 Сообщений:

Отправлено 09 Октябрь 2010 - 06:51

First of all, please excuse me if I am posting this in the wrong forum, I don't really have any experience with this because I haven't had a virus for ten years or so.

A few days ago, I noticed that my browser had started popping open new tabs to iffy links all by itself.
I knew that wasn't a good sign, so I ran an AVG scan. It said it detected three instances of something called vundo.ka, but that they couldn't be fixed. These were the messages:
"";"C:\WINDOWS\explorer.exe (260):\memory_001a0000";"Trojan horse Vundo.KA";"Object is inaccessible."
"";"C:\WINDOWS\system32\svchost.exe (1176):\memory_001a0000";"Trojan horse Vundo.KA";"Object is inaccessible."
"";"C:\Program Files\Mozilla Firefox\firefox.exe (3904):\memory_001a0000";"Trojan horse Vundo.KA";"Object is inaccessible."
Thinking the problem was this Vundo.KA thing, I searched for more information. Suggestions were made to try using Malware Bytes, which I downloaded and ran, but it said it didn't find any infections. So I tried using Spybot Search & Destroy. It didn't find anything either. Since then, I have also tried using several other scanners (including Sophos Anti Rootkit), but still nothing has shown up. However, I know that there must be something infecting my PC because the unwanted urls are still popping open.

Most recently, I downloaded the free version of Dr.Web CureIt. I double clicked the downloaded exe file to run it, and the screen immediately went black for a second, then I got a blue screen stating something about a sys file being at fault.

Could someone please help me?
I would be very grateful.

I have HiJackThis and can post a log if necessary.

Thanks in advance.

Сообщение было изменено mindbaby: 09 Октябрь 2010 - 06:58


#2 SergM

SergM

    Guru

  • Moderators
  • 9 387 Сообщений:

Отправлено 09 Октябрь 2010 - 07:44

Attach here the HiJackThis log
Run the new(!) Dr. Web CureIt in a safe mode.

#3 mindbaby

mindbaby

    Newbie

  • Posters
  • 3 Сообщений:

Отправлено 09 Октябрь 2010 - 08:24

Attach here the HiJackThis log
Run the new(!) Dr. Web CureIt in a safe mode.


Ok. Thanks. I have attached the log file. I will try and run the Dr. Web app in safe mode in a minute, and then will get back to you.

Прикрепленные файлы:



#4 SergM

SergM

    Guru

  • Moderators
  • 9 387 Сообщений:

Отправлено 09 Октябрь 2010 - 08:43

the HiJackThis log is Ok.
Please, execute our rules (use the network translator).
To job of utility Dr. Web CureIt! prevents started antivirus AVG

#5 mrbelyash

mrbelyash

    Беляш

  • Members
  • 25 897 Сообщений:

Отправлено 09 Октябрь 2010 - 20:26

Run its programm and attach log
wiki https://drw.sh/endjcv | Утилиты https://drw.sh/dgweku | Лечить удаленно https://drw.sh/wmzdcl | Скрытые процессы https://drw.sh/tmulje | Логи https://drw.sh/ruy | Песочница https://drw.sh/exhbro

#6 mindbaby

mindbaby

    Newbie

  • Posters
  • 3 Сообщений:

Отправлено 16 Октябрь 2010 - 22:19

Thank you for your help, but this topic is now redundant. Upon trying to start in Safe Mode, I received a blue screen, and when I tried to reboot I was no longer able to boot from my HDD even though it was recognized in the BIOS. I wasn't even able to reinstall Windows, until I concluded that the drivers for the Matrox HDD might have been wiped or corrupted. So I installed them from the CD, and I was finally able to reinstall Windows.
Thanks again for helping.