Page 5 of 9 FirstFirst ... 2345678 ... LastLast
Results 65 to 80 of 129

Thread: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

  1. #65
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by SammEl View Post
    What programs are installed on your XP?

    Download these following programs and run them.

    MalwareBytes
    Spybot Search and Destroy
    Avira Free Anti Virus

    These three programs SHOULD fix most or all of the mess, if Task Manager is not opening then it's possibly something blocking you from opening it (the whole point of most infections).

    Run Spybot and Malwarebytes together, clean Spybot first, then Malware, and reboot.

    Then load up Avira and do a full scan. If anything tries to open up during the scan, Avira will pick it up and ask you to Deny Access or Quarantine it - I'd do the latter.

    Don't worry about any sound drivers yet, they are not important.

    I'll be very surprised if doing the above doesn't get your PC working to how it was before.

    Do that, and update us.
    Since I already have Kaspersky Internet Security 2010 installed,would it be a good thing to install Avira as well?Or shud I uninstall Kaspesky first??

  2. #66
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by Amitava83 View Post
    Since I already have Kaspersky Internet Security 2010 installed,would it be a good thing to install Avira as well?Or shud I uninstall Kaspesky first??
    Let kaspersky complete its scan. Dont worry about installing Avira, you can do this after kaspersky has completed its scan (however remove kaspersky.)

    I need a new complete hijackthis log before i can continue (your last one didnt post correctly).

    Cheers.

  3. #67
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    Ok thanks,

    Navigate to C:\Windows\System32 is taskmgr.exe present?

    This may be why - C:\WINDOWS\Syste m32 the space? If you navigate to Control Panel, System, Environment, System/User Variables are you able to remove the space in syste m32?

    Can you please repost a new hijackthis log (making sure it doesnt display funny when posting)

    You can also try the steps manually -

    1. Click Start

    2. Click Run

    3. Type REGEDIT

    4. Click OK The Registry Editor will now open

    5. Browse to the following key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system

    6. In the right pane, look for the value: DisableTaskMgr

    7. Right click DisableTaskMgr and select Delete. (When prompted with "Are you sure you want to delete this value", select Yes.
    Done.

    Quote Originally Posted by CrazyMonkey View Post
    8. Now browse to the following key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system

    9. In the right pane, look for the value: DisableTaskMgr

    10. Right click DisableTaskMgr and select Delete. (When prompted with "Are you sure you want to delete this value", select Yes.
    Could not find DisableTaskMgr entry here.

    Quote Originally Posted by CrazyMonkey View Post
    11. Close the Registry by choosing File, Exit

    12. You should now be able to access Task Manager. If not, reboot into Safe Mode and repeat the steps outlined above.

    Cheers.
    Still task manager not coming up.Will try this in Safe Mode (Donno whether its possible to login to XP Safe Mode now,wasn't possible till yesterday)...

    Thanks

  4. #68
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    Let kaspersky complete its scan. Dont worry about installing Avira, you can do this after kaspersky has completed its scan (however remove kaspersky.)

    I need a new complete hijackthis log before i can continue (your last one didnt post correctly).

    Cheers.
    Sorry,dont know what had happened.Please find the Hijack This Log File :



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:04:01 AM, on 4/25/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Unable to get Internet Explorer version!
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\SYSTEM32\astsrv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\WINDOWS\system32\nlssrv32.exe
    J:\amitdb\bin\nmesrvc.exe
    J:\amitdb\bin\isqlplussvc.exe
    J:\amitdb\BIN\TNSLSNR.exe
    J:\amitdb\jdk\bin\java.exe
    j:\amitdb\bin\ORACLE.EXE
    C:\WINDOWS\system32\cmd.exe
    J:\amitdb\perl\5.8.3\bin\MSWin32-x86-multi-thread\perl.exe
    J:\amitdb\jdk\bin\java.exe
    C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
    J:\amitdb\bin\emagent.exe
    F:\Program Files\Irfanview\i_view32.exe
    F:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
    O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [MDS_Menu] "F:\Program Files\CyberLink\MediaShow Espresso\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "F:\Program Files\CyberLink\MediaShow Espresso\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.5"
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
    O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1259424836671
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4363DC25-F2D6-42B0-B029-73575FC6AD35}: NameServer = 172.16.0.1,202.54.1.63
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPE R~1\KASPER~1\kloehk.dll
    O23 - Service: 1239710008 (.1239710008) - Unknown owner - C:\Program Files\1239710008\Amitava1239710008L.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\SYSTEM32\astsrv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: HDD & SSD access service - Unknown owner - C:\Program Files\Common Files\BinarySense\disksvc.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: mysql - Unknown owner - F:\xampp\mysql\bin\mysqld.exe (file missing)
    O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\nlssrv32.exe
    O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
    O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
    O23 - Service: OracleDBConsoleamitdb - Oracle Corporation - J:\amitdb\bin\nmesrvc.exe
    O23 - Service: OracleOraDb10g_home2iSQL*Plus - Oracle - J:\amitdb\bin\isqlplussvc.exe
    O23 - Service: OracleOraDb10g_home2TNSListener - Unknown owner - J:\amitdb\BIN\TNSLSNR.exe
    O23 - Service: OracleServiceAMITDB - Oracle Corporation - j:\amitdb\bin\ORACLE.EXE
    O23 - Service: Power Manager (PowerManager) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
    O23 - Service: PrTgressep - Unknown owner - C:\WINDOWS\system32\srvany.exe

    --
    End of file - 7772 bytes


    Thanks

  5. #69
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Kaspersky obviously isn't working very well in this instance. Do manual scans from your Windows 7 installation. Uninstalling it wouldn't do any harm - you can put it back on when it's cleaned up.

    Malwarebytes, Spybot & avira are decent programs, but it's not often that *everything* is found with them. You need to do manual checks with rootkit finders, autoruns to disable everything which isn't required, and a few other things to find "odd"-looking stuff.

    This thread could go on for a few days yet, unless someone remotes on to the PC.

    Combofix could potentially be the last resort - sometimes it can delete files it shouldn't, for example I've seen one person not be able to use AutoCAD after using Combofix.

  6. #70
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Ok is C:\Windows\System32 is taskmgr.exe present?

    Go to Start>Run>cmd
    type followed by enter -
    sc stop ".1239710008"

    sc delete ".1239710008"

    sc stop "PowerManager"

    sc delete "PowerManager"

    Hopefully it will say SUCCESS after each.

    Next select these in hijackthi and click fix -

    Code:
    O23 - Service: 1239710008 (.1239710008) - Unknown owner - C:\Program Files\1239710008\Amitava1239710008L.exe (file missing)
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
    O23 - Service: HDD & SSD access service - Unknown owner - C:\Program Files\Common Files\BinarySense\disksvc.exe (file missing)
    O23 - Service: mysql - Unknown owner - F:\xampp\mysql\bin\mysqld.exe (file missing)
    O23 - Service: Power Manager (PowerManager) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
    Reboot. Post a fresh copy of hijackthis.

    Quote Originally Posted by smargh View Post
    This thread could go on for a few days yet, unless someone remotes on to the PC.

    Combofix could potentially be the last resort - sometimes it can delete files it shouldn't, for example I've seen one person not be able to use AutoCAD after using Combofix.
    Trying Combofix or SDfix would be a good idea. You can remote to his pc if you/him like, though i usually dont do this myself.

  7. #71
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    Ok is C:\Windows\System32 is taskmgr.exe present?
    oops forgot to mention no taskmgr.exe not present in C:\Windows\System32.Taskman.exe is present(dont know whats that)

  8. #72
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by Amitava83 View Post
    oops forgot to mention no taskmgr.exe not present in C:\Windows\System32.Taskman.exe is present(dont know whats that)
    Ok also do the name servers 172.16.0.1,202.54.1.63 mean anything to you? As they seem to keep returning in the hijackthis log. Are you making sure to check

    O17 - HKLM\System\CCS\Services\Tcpip\..\{4363DC25-F2D6-42B0-B029-73575FC6AD35}: NameServer = 172.16.0.1,202.54.1.63

    When running hijack this? or are these nameservers indeed legit?

    Is this C:\Windows\System32.Taskman.exe the correct path or do you mean C:\Windows\System32\Taskman.exe

    Try uploading this file to jotti and post the results.

    Are you able to find taskmgr.exe when running a search on the computer?

  9. #73
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    This is me if Amitava83 wants someone to go on to do a quicker cleanup: http://www.crossloop.com/smargh

    I get far too fed up trying to guide people through checking these things - it's easier to just remote on and get it over with.

  10. #74
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    Ok also do the name servers 172.16.0.1,202.54.1.63 mean anything to you? As they seem to keep returning in the hijackthis log. Are you making sure to check

    O17 - HKLM\System\CCS\Services\Tcpip\..\{4363DC25-F2D6-42B0-B029-73575FC6AD35}: NameServer = 172.16.0.1,202.54.1.63

    When running hijack this? or are these nameservers indeed legit?

    Is this C:\Windows\System32.Taskman.exe the correct path or do you mean C:\Windows\System32\Taskman.exe

    Try uploading this file to jotti and post the results.

    Are you able to find taskmgr.exe when running a search on the computer?
    First nameserver look like a legit India ISP DNS server, second is non-routable though but maybe it's only visible inside the ISP's network (or they're doing NAT). Is the OP using a router or is the PC connected directly to the Internet?

  11. Received thanks from:

    CrazyMonkey (24-04-2010)

  12. #75
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by smargh View Post
    This is me if Amitava83 wants someone to go on to do a quicker cleanup: http://www.crossloop.com/smargh

    I get far too fed up trying to guide people through checking these things - it's easier to just remote on and get it over with.

    Can both you and CrazyMonkey come on Remote with me,at your convenient time and get this over with???

    I'm a photographer by profession and all my Photoshop CS4 plugins which I painstakingly acquired over past couple of years work ONLY on XP but not on Win7 Ultimate.I do not even have backups of all other editing softwares I use regularly on XP.

    Otherwise I wouldn't have hesitated a sec to reformat XP.
    But as the situation is now,reformatting would mean I'd be out of work for quite sometime and I have a family to support.

    Help me out guys,thats all I can say.

  13. #76
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    I am available to remote tonight for the next hour or so. I presume teamviewer would be easiest?

    Update me on whether or not you want to take this route.

    Would be easiest if you PM me your teamviewer ID and password if thats is what you want to do.

    Cheers.

  14. #77
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    Ok also do the name servers 172.16.0.1,202.54.1.63 mean anything to you? As they seem to keep returning in the hijackthis log. Are you making sure to check

    O17 - HKLM\System\CCS\Services\Tcpip\..\{4363DC25-F2D6-42B0-B029-73575FC6AD35}: NameServer = 172.16.0.1,202.54.1.63

    When running hijack this? or are these nameservers indeed legit?
    172.16.0.1--my Preferreed DNS Server
    202.54.1.63--Alternate DNS Server


    Quote Originally Posted by CrazyMonkey View Post
    Is this C:\Windows\System32.Taskman.exe the correct path or do you mean C:\Windows\System32\Taskman.exe
    Its C:\WINDOWS\system32\Taskman.exe

    Quote Originally Posted by CrazyMonkey View Post
    Try uploading this file to jotti and post the results.
    Here it is:
    http://virusscan.jotti.org/en-GB/sca...040243d844f07c

    And here is the latest Log from MBAM:

    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 3930

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 6.0.2900.2180

    4/25/2010 1:54:58 AM
    mbam-log-2010-04-25 (01-54-58).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 153960
    Time elapsed: 20 minute(s), 58 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\conime.exe (Security.Hijack) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    Quote Originally Posted by CrazyMonkey View Post
    Are you able to find taskmgr.exe when running a search on the computer?
    When i do a search for taskmgr.exe Windows finds TASKMGR.EXE-118158DD.pf in C:\WINDOWS\Prefetch .In D Drive(for Win 7),it finds an actual taskmgr.exe.

  15. #78
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    I am available to remote tonight for the next hour or so. I presume teamviewer would be easiest?

    Update me on whether or not you want to take this route.

    Would be easiest if you PM me your teamviewer ID and password if thats is what you want to do.

    Cheers.
    yes that would be great.just let me download and install teamviewer.

  16. #79
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Ok do you want me to remote you or continue working on here? Your choice, i dont mind.

    EDIT - ok, just pm me the details when you are ready, or we can discuss over msn if you perfer?

  17. #80
    Registered+
    Join Date
    Jul 2009
    Location
    Calcutta,India
    Posts
    86
    Thanks
    7
    Thanked
    1 time in 1 post
    • Amitava83's system
      • Motherboard:
      • ASUS P5Q-E
      • CPU:
      • C2D E7300@stock speed
      • Memory:
      • 2X2 GB 800MHz Corsair
      • Storage:
      • 500.1 GB @7200.11 Seagate
      • Graphics card(s):
      • Palit Radeon HD 4870 1 GB DDR5 Sonic Dual Edition
      • PSU:
      • Corsair TX 650W
      • Case:
      • Corsair CM 690
      • Operating System:
      • XP SP2,Vista SP1
      • Monitor(s):
      • Dell 1909W
      • Internet:
      • 128kbps DSL unlimited

    Re: VERY URGENT.System infected with umdmgr.exe.PLEASE HELP!!!

    Quote Originally Posted by CrazyMonkey View Post
    Ok do you want me to remote you or continue working on here? Your choice, i dont mind.

    EDIT - ok, just pm me the details when you are ready, or we can discuss over msn if you perfer?

    Hello,

    Ihave pinged you Teamviewer details through private message....I'm ready for the session.

Page 5 of 9 FirstFirst ... 2345678 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. server hacked, help plz !
    By GoNz0 in forum Software
    Replies: 34
    Last Post: 10-01-2010, 08:24 PM
  2. Infected or not infected ?
    By Cov in forum Software
    Replies: 2
    Last Post: 15-01-2009, 10:02 AM
  3. HELP! Removing Trojan Vundo.H
    By ryan_w08 in forum Software
    Replies: 14
    Last Post: 06-12-2008, 10:33 AM
  4. Replies: 14
    Last Post: 02-07-2008, 10:36 PM
  5. Replies: 37
    Last Post: 10-09-2007, 03:02 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •