Major Malware problem Please Help!!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TJMoose, Apr 5, 2011.

Thread Status:
Not open for further replies.
  1. TJMoose

    TJMoose Private E-2

    I got hit by a malware drive-by and I am having some problems removing all of it. When it happened my browser window closed but firefox didn't leave the processes in the task manager. Up popped an alert from a rogue "XP Home Security" and Windows Firewall, auto update & Microsoft Security Essentials all turned off. Ad-Aware started running a scan & an hour later I used Ad-Aware to remove the found threats. Before restarting I tryed to restart Microsoft Security Essentials because I wanted to run a scan with it too first. The Microsoft Security Essentials didn't start and the "XP Home Security" pop-up returned. I tried to run Ad-Aware again but I couldn't start it or anything else so I restarted. After the restart when I clicked on an exe I got the "Open With:" dialogue box. I restarted in safe mode and all exes reponded the same. However, Ad-Aware auto started again and when the update prompt came up I clicked yes and Firefox opened. I searched for a solution to the exe problem using google. When I tried to click on a link I was redircted to a different site. I clicked on google Cached and then used the link at the top to get to the current page I wanted. I found solutions of creating these files using the command prompt to open notepad and saving;

    fix.reg

    (contents)
    Windows Registry Editor Version 5.00

    [-HKEY_CURRENT_USER\Software\Classes\.exe]
    [-HKEY_CURRENT_USER\Software\Classes\pezfile]
    [-HKEY_CLASSES_ROOT\.exe\shell\open\command]

    [HKEY_CLASSES_ROOT\exefile\shell\open\command]
    @="\"%1\" %*"

    [HKEY_CLASSES_ROOT\.exe]
    @="exefile"
    "Content Type"="application/x-msdownload"


    &

    fix.inf

    (contents)
    [Version]
    Signature="$Chicago$"
    Provider=www.myantispyware.com

    [DefaultInstall]
    DelReg=regsec
    AddReg=regsec1

    [regsec]
    HKCU, Software\Classes\.exe
    HKCU, Software\Classes\pezfile
    HKCR, .exe\shell\open\command

    [regsec1]
    HKCR, exefile\shell\open\command,,,"""%1"" %*"
    HKCR, .exe,,,"exefile"
    HKCR, .exe,"Content Type",,"application/x-msdownload"


    I installed both and it fixed the exe problem.
    I then ran Malwarebytes' Anti-Malware and fixed the problems that were detected. I restarted and Windows Firewall and Microsoft Security Essentials restarted but Auto update did not. So I started googling for a solution a few sites said to run dds.scr and post the log so I downloaded it and ran it but dds.scr says it should only take 3 minutes to run but at 20 it froze and The "XP Home Security" pop-up was back. I killed dds.scr in the task manager and ran Malwarebytes' Anti-Malware again. This time I remembered to update Malwarebytes' Anti-Malware first and then I made screenshots of it before I fix the found problems.


    While Malwarebytes' Anti-Malware was scanning I made a hijackthis log here:

    (edited out)

    I also saved this Malwarebytes' Anti-Malware log before fixing:

    (edited out)


    After fixing Windows Firewall and Microsoft Security Essentials came back but still auto update refuses to turn on. I get this dialogue box;

    [​IMG]


    I have tried to fix this manually as it says but it won't work.

    Before restarting after fixing with Malwarebytes' Anti-Malware I saved the log that showed the results of the fix.

    Here;

    (edited out)


    Can someone please help me get rid of this peice of crap malware?

    Oh, also the redirecting of google links is still happening.

    Thank you for your time,

    TJ
     
    Last edited by a moderator: Apr 5, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. TJMoose

    TJMoose Private E-2

    Found help at other forum.

    Close Please!

    TJ
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds