WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionMcAfee: Error Starting on Demand Scanner et al EmptyMcAfee: Error Starting on Demand Scanner et al

more_horiz
Hello. I'm having very similar problems on my computer as rocio25 describes in his first post at http://www.geekpolice.net/virus-spyware-malware-removal-f11/error-starting-on-demand-scanner-t12398.htm. I have the same problem running Malwarebytes, the same problem updating Java and running HijackThis and I can't even get to download combofix. It seems that a lot of software designed to catalogue and fix the malware is recognised and prevented from running or even downloading/accessing the download sites. Spyware Doctor has been successfully installed and has found and (apparently) eradicated many of the maleware generated bugs, but I still have the problems described above.

If it helps, SystemLook has generated the following when ...

:filefind
scecli.dll
netlogon.dll:

... was pasted into it:

SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 11:26 on 05/09/2009 by Peter Fraser (Administrator - Elevation successful)

========== filefind ==========

Searching for "scecli.dll"
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll --a--c 180224 bytes [07:48 10/07/2008] [07:56 04/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\ServicePackFiles\i386\scecli.dll --a--- 181248 bytes [07:56 04/08/2004] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll --a--- 181248 bytes [11:41 29/08/2002] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084

Searching for "netlogon.dll"
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll --a--c 407040 bytes [07:48 10/07/2008] [07:56 04/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll --a--- 407040 bytes [07:56 04/08/2004] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [11:41 29/08/2002] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550

-=End Of File=-

Basically I'm at the point where Belhazur posted in the rocio25 thread on Sun 09 Aug 2009, 7:15 pm, where he informs us not to continue further with any procedures tailored for fixing rocio25's computer. I've downloaded and extracted avenger.exe to my desktop in anticipation, but have not run it yet.

I noticed that a.exe, and msa.exe were seen running in Task Manager. I read up about them on the internet and decided that they were malware, so I deleted them. a.exe was in the %Temp% directory and I think msa.exe was in the C:\WINDOWS directory. I also deleted b.exe, which was also running in the %Temp% directory. I also noticed something called 'monopod' in the startup listings viewed using msconfig. I think 'monopod' is related to the malware and have deleted it from the startup with CCC cleaner. I also deleted a monopod listing in XP's registry in the software listing. I still have the original .reg file I exported just before deleting that monopod entry. I've also disabled XP's System Restore and will re-enable it once, or if, I can get my system cleared of the malware.

Any assistance would be greatly appreciated, believe me - I've been working on this for three days now! Shocking Whoa

descriptionMcAfee: Error Starting on Demand Scanner et al EmptyRe: McAfee: Error Starting on Demand Scanner et al

more_horiz
Hello.
I need to use SystemLook again, use this script.

:filefind
eventlog.dll
cngaudit.dll

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
McAfee: Error Starting on Demand Scanner et al DXwU4
McAfee: Error Starting on Demand Scanner et al VvYDg

descriptionMcAfee: Error Starting on Demand Scanner et al EmptyThanks Belahzur

more_horiz
Thanks for replying, however I've given up trying to fix this - the trojan (which might be Artemis!A593E52A2E4A) was invisible to all scanners, when they were allowed to operate. I couldn't run rootkit revealer for long without it cutting out (maybe the bad guys were monitoring what I was trying to do to find the trojan and 'manually' stopping the program, because rootkit revealer never stopped at the same point). No viruses were shown (on the scanners that I could run - I could run McAfee from their web site and scan my computer from there - nothing found). Everything I tried to use to find the malware, with the exception of Spyware Doctor, was thwarted. God help me if they got into my personal banking details.

Anyway, I'm now in the long process of reinstalling from scratch using the master boot record.

I never heard of rootkits before, but they are really scary. And I think I'm being targetted now, because the Artemis!... trojan was found by McAfee at 6.15am today on an uninfected computer on my network. I wish there was some way to send a modified version of the bad guys' malware straight back to the bastards - give them a taste of their own medicine. From what I've found out about rootkits, I'd say it's probably best to forget about trying to eradicate the computer of the malware once infected, because I can't see a way of being sure Hacker Defender, etc., hasn't been used to secrete dormant malicious software somewhere else on the computer in the event the 'main' malware has been discovered and removed - a failsafe strategy.

Thanks again.

Over and out. 😉

descriptionMcAfee: Error Starting on Demand Scanner et al EmptyRe: McAfee: Error Starting on Demand Scanner et al

more_horiz
Hello.
Very true... We may be able to fix it, but I do need you to run the SystemLook script I gave you above.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
McAfee: Error Starting on Demand Scanner et al DXwU4
McAfee: Error Starting on Demand Scanner et al VvYDg

descriptionMcAfee: Error Starting on Demand Scanner et al EmptyRe: McAfee: Error Starting on Demand Scanner et al

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum