Malware desperation...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Abacaxi, Sep 18, 2010.

  1. Abacaxi

    Abacaxi Private E-2

    I started on Wednesday, som avast warning about a virus which was then removed. All well. Later that day my email addresses were hijacked so obviously something was wrong and avast found the same virus again, it was bubnix bubak something. I then read some of these threads and started trying the different combofix, MGtools, Superantispyware, Kaspersky online scanner and malwarebytes. Everyone found different stuff to complain about and I tried to correct things, as I've always been able to fix things myself before.
    But this morning no antivirusprograms would run, and the browsers don't open.
    I then downloaded the portable SAS version to another pc (this one) and renamed it and ran it on the infected pc. It hung scanning the registry keys.
    After that I rebooted, and doubleclicked Avast. Miracle, it started, but so terribly slow. Been already two hours, working, but still on 1%.
    so tired cant even write complete sentences anymore.

    Any solutions? please?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please try to follow everything in the READ & RUN ME FIRST. Malware Removal Guide

    You may need to try running the scans in safe mode and / or renaming them as suggested. We need to see the logs in order to assist you.
     
  3. Abacaxi

    Abacaxi Private E-2

    Ok, so I started with the different things on the list. As it was impossible to disinstall anything (pc crashed) I booted in safe mode and disinstalled malwarebytes. Pc crashed, but only after disinstall. Am now downloading all the programs again, as Internet started to function after MGtools removal and malwarebytes removal.
    will get back with logs.
    beijos

    edit: in safe mode, there's another user besides me, called administrator with a skater as avatar. I certainly never put any skater as admin of my pc, is this normal?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, it is normal to have the Admin account in safe mode. It assigned an avatar by default.
     
  5. Abacaxi

    Abacaxi Private E-2

    First three logs...

    All the scanning went well, except for combofix whixh froze the PC.
     

    Attached Files:

  6. Abacaxi

    Abacaxi Private E-2

    One more.
    Seems MGtools didnt work, there's no log in the folder indicated by the read me. will try again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where exactly are you looking for the log and what file name are you looking for?


    The C:\MGtools folder was created as I can see this in your ComboFix log which is strange since MGtools.exe was not supposed to be run before combofix.
     
  8. Abacaxi

    Abacaxi Private E-2

    Found it.
     

    Attached Files:

  9. Abacaxi

    Abacaxi Private E-2


    Yes sorry,

    I had already done all this yesterday or maybe on thursday, can that leave traces?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MGtools did not finish running. Please do the below and make sure you close all browser Windows before hand.

    Run C:\MGtools\analyse.exe by double clicking on it This is really HijackThis. You may see a license agreement from TrendMicro. You need to click the Accept button twice to accept this license. Then when the program loads, select Do a system scan and save a logfile

    When the above finishes running a notepad file will open with the hijackthis.log in it. Just close it. The file is already saved in your C:\MGtools folder.

    Now I need you to run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you allow GetLogs.bat to finish running. It will tell you when it finishes.
     
  11. Abacaxi

    Abacaxi Private E-2

    That was COMODO stopping it.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You say your problems began on Wednesday. That is the same day you installed DAEMON Tools Toolbar according to your logs. Did your problems start after installing this? Also it looks like you did not complete step 6 of the READ & RUN ME to disable this disk emulation software.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. Abacaxi

    Abacaxi Private E-2

    I really thought I disinstalled it, havent used daemon for ages. I disinstalled it instead of doing the DE disabling as part of the readme. My problems started before that. But instead you say I installed a toolbar?
     
  14. Abacaxi

    Abacaxi Private E-2

    I hope I didnt mess things up again.

    Logs:
     

    Attached Files:

  15. Abacaxi

    Abacaxi Private E-2

    Good morning.

    Things got worse this morning so I am again using the uninfected computer, with my son cursing me...

    In normal mode nothing would run, so I started in safe mode, and did a rootrepeal (i really need to do something, can't just sit there and look at it slowly getting worse). Rootrepeal showed two strange files under the Skype folder, so I force deleted them. Hope that was ok.
    I also uninstalled combofix and malwarebytes.
    Tried to uninstall MGtools, but the computer won't let me, saying Windows Installer didn't load.

    After that I booted in normal mode, managed to open a browser, and am now trying a Kaspersky online scan. Extremely slow.

    EDIT: should I give up and just format the whole thing?

    Avast is giving error messages.
    Acer ePower technology is giving error messages about a PSD disk that isn't mounted.
     
    Last edited: Sep 19, 2010
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happen after posting your logs in message # 14 where everything was still working? Was the PC being used by anyone for anything other than coming here to repair it? All we removed in the last fix would not cause the problems you mentioned.

    What exactly would happen and what were you trying to run? Did the PC boot up okay and could you login?

    Very bad idea. As stated in the READ & RUN ME, you should only being doing what we ask you to do. Doing things on your own could result in you deleting necessary files for your PC to operate.

    Why?? There is no reason to do this and how did you "uninstall" ComboFix?

    MGtools is not truly installed and does not require or use an installer program like this and you should not be removing it anyway until requested. We cannot help you if you remove the tools you need to give us the information required to give you this help.

    Things were proceding just fine. I'm not sure why this should be necessary. What is your current status? You will have to attach a new log from MGtools after running the GetLogs.bat file so we can get some new information.

    What error messages exactly and when do they occur?

    I have no idea what this is but this was not occurring previously and nothing we have done would affect any Acer files. What have you or someone else been doing in between fixes and exactly what did you remove with RootRepeal.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In addition to the new MGtools log, see if you can do the below.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  18. Abacaxi

    Abacaxi Private E-2

    I'm sorry chaslang, I panicked this morning when everything was slowing down again.

    And of course I started messing with it again. I perfectly understand if you get so tired of me you decide to drop my case, anyway, here's the last developmens:
    At one point in my desperation (I couldn't even save workfiles on the memory card, computer would just freeze) I started to suspect COMODO which I had installed somewhere along the way, before looking for help here.

    It was impossible to disinstall.

    So I booted safe mode, opened a dos-window and deleted the comodo-directory.

    Then I booted a couple of times, until the PC started to work again. :)
    I then managed to disinstall it properly from the control panel.

    Strange thing: At one point during the whole process I noticed a folder called VritualRoot (wrong spelling like that) under C:\

    It is now gone.

    TDSS comes out clean it seems.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. Abacaxi

    Abacaxi Private E-2

    Right now it's working fine, I think. That is, I'm finally at work.

    MGtools gives an exception error, but finishes. Ran it twice, second time with avast stopped. Same error.
     

    Attached Files:

  21. Abacaxi

    Abacaxi Private E-2

    Ok, good morning!

    PC working fine, error messages disappeared.

    Did a Kaspersky online scan, and it found Trojan-Dropper.

    Am very very tempted to start messing with this. But will wait this time.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated earlier, you are not supposed to be doing anything except what is requested by us. Kaspersky did not find anything valid. These are all false detections.


    Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. Abacaxi

    Abacaxi Private E-2

    Ok, will do all the stuff.
    Thanks so incredibly much for your patience!

    PS: why don't you guys have a donate-button? I'm far too not geek for that kind of tees your're selling on jinx (you could design a white shirt without any prints?)...I would have bought a tee anyway, but stuff never arrives here in Brazil.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Donate to your favorite charity. That would make us happy. ;)
     
  25. Abacaxi

    Abacaxi Private E-2

    :)
    Will put some more money into KIVA circuit.

    beijos
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds