Going nowhere fast! Can't do Read/Run Me First

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by programmer04, Dec 10, 2011.

  1. programmer04

    programmer04 Private First Class

    I am running Windows Vista on my desktop. Early this morning I encountered a problem with Google redirecting me to other sites. I was also getting pop-ups advertising blinkz. I came here to find out how to remove the Google redirection issue when I suddenly had the Vista Security 2012 crap popping up telling me that my computer was infected (please, tell me something I didn't already know) and then tried to run a fake scan, which I stopped. The pop-ups kept coming, so I disconnected the router and reset it (as one post suggested). After reconnecting the router, I tried opening Internet Explorer and window came up asking which program I would like to use to open it. That's when I discovered that no 'exe' would open up. The only option I'm given to open anything is Internet Explorer (ironic) even if I click on something else, and if I select IE then it will try to download the file I'm trying to open.

    I can't perform anyhting in "Read and Run Me First" because of this. I've tried a some fixes for the 'exe' issue, even Microsoft's site, but have had no luck. I've also received the BSOD twice.

    Please help!
     
  2. programmer04

    programmer04 Private First Class

    P.S. - This is a home built computer. It is a 32 bit. The computer is not new, but it is fairly new to me and Windows has not been updated from what I was told.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, try THIS.
     
  4. programmer04

    programmer04 Private First Class

    Ok. That seemed to work. THANKS! Now I'll go back to the "Read and Run Me First" steps, unless there's something else I should know or do.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, just start on the Read and Run first instructions and get me the requested logs. ;)
     
  6. programmer04

    programmer04 Private First Class

    ComboFix seems to be stuck. It hasn't done anything for over an hour and a half. The current message that has been displayed this whole time is:

    Scanning for infected files...
    This typically doesn't take more than 10 minutes
    However, scan times for badly infected machines may easily double

    Should I continue to wait? I've ran ComboFix on other computers in the past and it never took this long. It said in the beginnin that ESET was running, but I know for a fact that it is not. I shut it all down. I can't afford to uninstall it since I don't have the installation files or disk.

    Also, SUPERAntiSpyware could never finish because the computer continued to get the BSOD. The blue screen was occurring before I ever installed or ran SAS. I followed all the steps regarding the BSOD for SAS and still no luck. Therefore, I have no log for SAS.

    MBAM worked fine. Should I try to rerun SAS since MBAM eliminated some of the problems? I haven't had a blue screen since I ran MBAM.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running MBAM. Also, please run MGTools.exe and attach the resultant C:\MGLogs.zip.
     
  8. programmer04

    programmer04 Private First Class

    Ok, here goes. I went ahead and re-ran SAS, and it did finish and found some issues. I did not run RootRepeal since you told me to just run MGTools after the ComboFix issue. I think its obvious from my viewpoint that there are still problems. I keep getting certain messages like "Interactive services dialog detection - A program can't display a message on your desktop" and it says it has something to do with paint. I also keep getting a message that asks me if I want to turn Google toolbar back on. I'm also getting redirected on the internet every so often, such as when I tried to come here about 30 minutes ago.

    One error popped up while running MGTools:

    nslookup.exe - Ordinal not found
    The ordinal 1108 could not be located in the dynamic link library
    WSOCK32.dll

    I'm also having a problem with my Internet Explorer icon in my start menu saying "this file does not have a program associated with it", but my icon in the bar at the bottom works.

    I apparently forgot to turn off ESET's startup scan. When I restarted my computer after one of the scans it said it detected "Sirefef", which it was picking up before I started any scans.
     

    Attached Files:

  9. programmer04

    programmer04 Private First Class

    Also, any time I try to use the Recycle Bin I get a message saying it's corrupted.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon [​IMG]
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  11. programmer04

    programmer04 Private First Class

    Ran evrything. No problems with Avenger or CCleaner. MGTools came up with the same error as before:

    nslookup.exe - Ordinal not found
    The ordinal 1108 could not be located in the dynamic link library
    WSOCK32.dll

    I noticed that while MGTools was running there were folders that seemed to be replicated within themselves (in Application Data I think) to the point that the folder name was too long according to MGTools. I've noticed these before but I don't know why they are there.

    I'm still havingt some issues. There's the Recycle Bin issue of saying it's corrupted. I'm still getting the "Interactive services dialog detection" regarding Paint. I'm also having a problem with PING.EXE in Task Manager taking up almost all RAM and at least half of the processor.

    I also still have the Google redirection issue going on.
     

    Attached Files:

  12. programmer04

    programmer04 Private First Class

    It may not be just Google, though. I also get an occasional pop-up when I go to other sites, including this site. I've avoided any site, except this one, that requires a username and password until this whole problem is resolved.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  14. programmer04

    programmer04 Private First Class

    The Google redirection and pop-ups seem to have been resolved. Still receiving the "nslookup.exe" error message. Also, still getting the "Interactive services dialog detection" message and the message about the corrupted Recycle Bin.

    (edit)
    CORRECTION: Just as I submitted this message, a pop-up window for some other website came up.
     

    Attached Files:

    Last edited: Dec 13, 2011
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Do you have your install disc? You may need to do some repairs. What popped up?
     
  16. programmer04

    programmer04 Private First Class

    best-giveaways.com seems to be what usually pops up, but various others have too.
     
  17. programmer04

    programmer04 Private First Class

    It's definately not happening nearly as often as it was.
     
  18. programmer04

    programmer04 Private First Class

    Google redirection still happening (or happening again). I was searching for an answer to the "Interactive services dialog detection" issue on Google when I was redirected to yellowpages.com when trying to go to answers.microsoft.com. I tried again and again and again but was constantly redirected to various websites. I even tried to go to other websites from Google, but with no success.
     
  19. programmer04

    programmer04 Private First Class

    Among the sites I'm redirected to:

    ampnetwork.net (preceded by a number, such as 1.50912895.ampnetwork.net)
    63.209.69.107/search/web/
    search-fast-results.com
    tazinga.com
    yellowpages.com

    Not just happening to Google. Can't connect through Yahoo either. Very frustrating.
     
    Last edited: Dec 13, 2011
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run TDSSKiller and be sure to fix/cure this:
    Code:
    \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    16:11:44.0803 4176    \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip 
    .

    Attach the new log.
     
  21. programmer04

    programmer04 Private First Class

    There's no option to fix or cure. Options are skip, copy to quarantine, or delete.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Choose either copy to quarantine or delete.
     
  23. programmer04

    programmer04 Private First Class

    Done.
     

    Attached Files:

  24. programmer04

    programmer04 Private First Class

    So far, so good with the Google searches. No redirections yet.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if they return. In the meantime:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds