Hi,
I am new to this forum and very grateful for it. The problem that I've been having is related to a Trojan.Agent and/or Trojan.Fakems. I got this yesterday. I was in the middle of something and then all of a sudden my computer shut down. Now every time I start it in Normal Mode it will eventually give me the bluescreen of death with a long message that I never have time to read.
I think maybe this trojan is removable because I still can get in normal mode and can get into safe mode with no problem (which is what I am in now). I have ran Malwarebytes, Super AntiSpyware and Spybot and they have all found infections but there has still been no relief from the symptoms.
The below posts are the files that you asked for except for the extras.txt. For some reason that did not open. Is there a way to get to it?
Thanks for any help you can give.
aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-01-30 21:44:37
-----------------------------
21:44:37.024 OS Version: Windows x64 6.1.7601 Service Pack 1
21:44:37.024 Number of processors: 2 586 0x2502
21:44:37.025 ComputerName: MUSICABONITA-PC UserName: musicabonita
21:44:38.164 Initialize success
21:48:13.577 AVAST engine defs: 12013000
21:48:22.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:48:22.174 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
21:48:22.176 Device \Driver\iaStor -> MajorFunction fffffa80034b95c4
21:48:22.179 Disk 0 MBR read successfully
21:48:22.181 Disk 0 MBR scan
21:48:22.185 Disk 0 Windows VISTA default MBR code
21:48:22.189 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13000 MB offset 2048
21:48:22.204 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 26626048
21:48:22.249 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 225373 MB offset 26830848
21:48:22.255 Service scanning
21:48:23.410 Modules scanning
21:48:23.440 Disk 0 trace - called modules:
21:48:23.447
21:48:24.954 AVAST engine scan C:\Windows
21:48:28.722 AVAST engine scan C:\Windows\system32
21:48:40.178 File: C:\Windows\system32\consrv.dll **INFECTED** Win32:Sirefef-HO [Rtk]
21:50:23.800 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-FQ [Drp]
21:50:27.533 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-HO [Rtk]
21:51:58.297 AVAST engine scan C:\Windows\system32\drivers
21:52:23.397 AVAST engine scan C:\Users\musicabonita
21:53:15.886 Disk 0 MBR has been saved successfully to "C:\Users\musicabonita\Desktop\MBR.dat"
21:53:15.894 The log file has been saved successfully to "C:\Users\musicabonita\Desktop\aswMBR.txt"
Results of screen317's Security Check version 0.99.30
Windows 7 x64 (UAC is enabled)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:
Windows Security Center service is not running! This report may not be accurate!
Norton 360
McAfee Security Scan Plus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Spybot - Search & Destroy
TuneUp Utilities 2011
TuneUp Utilities Language Pack (en-US)
TuneUp Utilities 2011
Java(TM) 6 Update 22
Java(TM) 6 Update 26
Java version out of date!
Adobe Reader X (10.1.1)
Mozilla Firefox (9.0.1)
````````````````````````````````
Process Check:
objlist.exe by Laurent
Malwarebytes' Anti-Malware mbam.exe
``````````End of Log````````````
I am new to this forum and very grateful for it. The problem that I've been having is related to a Trojan.Agent and/or Trojan.Fakems. I got this yesterday. I was in the middle of something and then all of a sudden my computer shut down. Now every time I start it in Normal Mode it will eventually give me the bluescreen of death with a long message that I never have time to read.
I think maybe this trojan is removable because I still can get in normal mode and can get into safe mode with no problem (which is what I am in now). I have ran Malwarebytes, Super AntiSpyware and Spybot and they have all found infections but there has still been no relief from the symptoms.
The below posts are the files that you asked for except for the extras.txt. For some reason that did not open. Is there a way to get to it?
Thanks for any help you can give.
aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
Run date: 2012-01-30 21:44:37
-----------------------------
21:44:37.024 OS Version: Windows x64 6.1.7601 Service Pack 1
21:44:37.024 Number of processors: 2 586 0x2502
21:44:37.025 ComputerName: MUSICABONITA-PC UserName: musicabonita
21:44:38.164 Initialize success
21:48:13.577 AVAST engine defs: 12013000
21:48:22.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:48:22.174 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
21:48:22.176 Device \Driver\iaStor -> MajorFunction fffffa80034b95c4
21:48:22.179 Disk 0 MBR read successfully
21:48:22.181 Disk 0 MBR scan
21:48:22.185 Disk 0 Windows VISTA default MBR code
21:48:22.189 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13000 MB offset 2048
21:48:22.204 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 26626048
21:48:22.249 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 225373 MB offset 26830848
21:48:22.255 Service scanning
21:48:23.410 Modules scanning
21:48:23.440 Disk 0 trace - called modules:
21:48:23.447
21:48:24.954 AVAST engine scan C:\Windows
21:48:28.722 AVAST engine scan C:\Windows\system32
21:48:40.178 File: C:\Windows\system32\consrv.dll **INFECTED** Win32:Sirefef-HO [Rtk]
21:50:23.800 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-FQ [Drp]
21:50:27.533 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-HO [Rtk]
21:51:58.297 AVAST engine scan C:\Windows\system32\drivers
21:52:23.397 AVAST engine scan C:\Users\musicabonita
21:53:15.886 Disk 0 MBR has been saved successfully to "C:\Users\musicabonita\Desktop\MBR.dat"
21:53:15.894 The log file has been saved successfully to "C:\Users\musicabonita\Desktop\aswMBR.txt"
Results of screen317's Security Check version 0.99.30
Windows 7 x64 (UAC is enabled)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:
Windows Security Center service is not running! This report may not be accurate!
Norton 360
McAfee Security Scan Plus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Spybot - Search & Destroy
TuneUp Utilities 2011
TuneUp Utilities Language Pack (en-US)
TuneUp Utilities 2011
Java(TM) 6 Update 22
Java(TM) 6 Update 26
Java version out of date!
Adobe Reader X (10.1.1)
Mozilla Firefox (9.0.1)
````````````````````````````````
Process Check:
objlist.exe by Laurent
Malwarebytes' Anti-Malware mbam.exe
``````````End of Log````````````