cancel
Showing results for 
Search instead for 
Did you mean: 
c-good
Level 7
Report Inappropriate Content
Message 1 of 5

I can't run a full scan...I have many problems :(

first of all, i hope i'm posting in the right section...XD
ok...so about 4 days ago, i got the information that Mcafee had dected a trojan and had deleted it.
i don't know if this has anyting to do with my problem but wtv.....
anyways I didn't really pay attention to it until i nhoticed problems with my computer.
everytime i open my computer, when you can see the user accounts,a blue page appears(i dont have time to read what it says), and my computer restarts himself!!!! it finally goes back to normal, usually after 3-4 times that it restarts, but sometimes it takes a really long time.
So i decided to run a virus scan, but everytime i want to run a full scan, after like 1min, it says : the instruction at ''ox2d393738 referenced a memory at ''0x2d393738'' the memory could not be ''read click ok to terminate the program click cancel to debug the program.
AND
A error has occured, scanning has encountered a problem witch it can not recover
problem details:-error getting scan progress

and it says it needs to close and if i wanna send report.....


I have no idea what is wrong with my computer...please help:confused::confused::confused::confused


i have windos XP 2002.

Also, McAfee says i am not fully protected and there is a big exclamation(yellow)mark on the sign.
when I click on Fix, nothing happens....


Please help
4 Replies

RE: I can't run a full scan...I have many problems :(

Download Malwarebytes ' Anti-Malware from Here or Here Double-click on mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Full Scan, then click Scan.
* The scan may take some time to finish, so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to restart (see Extra Note below).
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy & paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
c-good
Level 7
Report Inappropriate Content
Message 3 of 5

results

Malwarebytes' Anti-Malware 1.30
Database version: 1357
Windows 5.1.2600 Service Pack 3

11/2/2008 3:56:33 PM
mbam-log-2008-11-02 (15-56-33).txt

Scan type: Full Scan (A:\|C:\|D:\|)
Objects scanned: 105425
Time elapsed: 24 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 5
Folders Infected: 1
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\sexvid (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdtlt.exe -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62ddfdba-7a6b-4ad7-bece-cda6ac119052}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.107;85.255.112.200 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{62ddfdba-7a6b-4ad7-bece-cda6ac119052}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.107;85.255.112.200 -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{62ddfdba-7a6b-4ad7-bece-cda6ac119052}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.107;85.255.112.200 -> Quarantined and deleted successfully.

Folders Infected:
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\kdtlt.exe (Rootkit.DNSChanger.H) -> Delete on reboot.
C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tempo-82D.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tempo-A2B.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.




Thx alot!!!!!:D:D:D
hope everything works now
Reliable Contributor exbrit
Reliable Contributor
Report Inappropriate Content
Message 4 of 5

RE: results

Moved to Virus Discussions & Removal Assistance from VirusScan 13 for better attention.
Highlighted
melboy
Level 7
Report Inappropriate Content
Message 5 of 5

RE: results



Did you Reboot? In light of the fact you had a rootkit infection i strongly suggest you post a Hijackthis (HjT) log at any one of the forums on Ex_Brits post here

HijackThis generates a log that a trained malware removal expert can analyze to see what may be wrong with your system.

Further HjT forums can be found here.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community