Malware Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dannyboy2008514, Jun 22, 2008.

  1. dannyboy2008514

    dannyboy2008514 Private E-2

    hi ever since my girlfriend was downloading cheap game demo's on google well i think my internet is highjacked,when i hit the ctrl,alt,del well i can see iexplorer and running high to
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the logs from the first run of SAS and MalwareBytes.

    In the meantime:

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 3"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5
    Messenger Plus! Live --typical cause of a LOP infection.

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Boonty Games
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste Boonty Games into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT
    .

    Find and delete:
    C:\Program Files\temp01

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and the SAS and MWB logs.
     
    Last edited: Jun 22, 2008
  3. dannyboy2008514

    dannyboy2008514 Private E-2

    i did what u told me to do here are the new logs
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not do what I asked you to do about the logs:
     
  5. dannyboy2008514

    dannyboy2008514 Private E-2

    there i started from the beginnintg and followed everything and explorer is still highjacked says this iexplorer and running at 65,704 when explorer is running at 7326
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The instructions in the Read and Run sticky were written for a purpose ---> they work if followed correctly.

    Please move MGTools.exe to the root of the C: drive ( C:\MGTools.exe) not where you put it: C:\Documents and Settings\Danny\My Documents\MGtools.exe.

    Then run it until it tells you it is finished -> you are lacking a few reports in the MGLogs.zip.

    You also did not uninstall Messenger Plus! Live.
     
  7. dannyboy2008514

    dannyboy2008514 Private E-2

    do i have to start from the beginning or just do what u said to do with mgtools
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Move MGTools to the C: drive where I specified it to go.

    Uninstall Messenger Plus! Live

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  9. dannyboy2008514

    dannyboy2008514 Private E-2

    there you go mister i did what youm asked now help my please asap
     

    Attached Files:

  10. dannyboy2008514

    dannyboy2008514 Private E-2

    do you think im gonna get rid of iexplorer anytime soon,doesnt look like its harming anything but internet explorer is so slow
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and Bitscan.
     
  12. dannyboy2008514

    dannyboy2008514 Private E-2

    there you go do you think u can get back to me before 12 00 thanks man i hope all this can get rid on iexplorer,it was running at 100 000 when the bit defender onlince scanner was going lol thanks man
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you scan any downloaded media from Limewire and any other torrent you use.

    Bitscan could not remove these items so lets see if avenger can:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run SpyBot and attach that log along with the avenger log...and also tell me what the PID number is for the iexplorer in task manager.
     
  14. dannyboy2008514

    dannyboy2008514 Private E-2

    i did what you said about deleting them with abvenger,but as soon and i saw the online scanner failed i searched them and delweted them myself,so here the log it says not found probably cause i already deleted thenb,another question my advast in my toolbar where the time is never came back and the time stayed the same like french time,so yeah thanks for all of this i cant find where the log it for spybot :( the iexplorer pid number is at 22.726
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We can reset your clock...ComboFix changed it. When you run spybot it produces a log for you....save it to the desktop as a txt file and attach it to the next reply. That PID number does not look right....are you sure that is the PID number and not the usage amount?
     
  16. dannyboy2008514

    dannyboy2008514 Private E-2

    im at work what time will you be offline
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm in and out....so just attach the logs when you have the opportunity to do so.
     
  18. dannyboy2008514

    dannyboy2008514 Private E-2

    cool thanks alot and about my antivirus you didnt get back to me on that one you only talked about the time,ttyl thanks again
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is your question about your anti-virus? Are you talking about the program or just the time setting that may be next to your AV icon in the system tray?

    You can reset that by going to the control panel / Regional and Language / customize / time tab and changing it to the format you prefer.
     
  20. dannyboy2008514

    dannyboy2008514 Private E-2

    again i did run spybot waited like 2 hours and no log pops up at all and i cant find where to get it,please help and my question about my antivirus is,that i cant see it anymore in my system tray where the time is,i fixed the time thanks here's what i see after spybot is donek i found it here
     

    Attached Files:

  21. dannyboy2008514

    dannyboy2008514 Private E-2

    and the pid number cant see what u mean but the other is at 30 000 about ansd all numbers beside are 0's and stay 0 not like other ones change sometime to 2 and back to 0
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try using add/remove programs and uninstall Avast...reboot and run CCleaner and then download and install Avast again.

    I don't recognize that PID number. It may be Avast or a firewall being active.
     
  23. dannyboy2008514

    dannyboy2008514 Private E-2

    damm thanks 4 getting avast back,i tryed ccleaner i guess it cleaned stuff out but still nothing,i still cant see where pid number is damm all i see in task manager is image name which is iexplore.exe next collum is user name which is danny next colum is session id the number is 0 next colum is cpu number flicks from 02 to 03 back to 00 and last collum is mem usage which is now at 55,456
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser are you using? And is this process using memory when you are not on the internet at all....IE physically unplugged?
     
  25. dannyboy2008514

    dannyboy2008514 Private E-2

    Windows® Internet Explorer version 7.00.6000.16674 (vista_gdr.080415-1732) and ieplorer only openes when browser is open,besides that all is ok i guess but its still annoying that my explorer is hickjacked
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it wasn't running...IE7 wouldn't open. It is a legitimate system file/process. :)
    Have you cleaned out your temp internet files?

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  27. dannyboy2008514

    dannyboy2008514 Private E-2

    i did what u did and damm iexplorer is still popping up shit computer its a real pain in the *** i really dont want to reformat my computer but it look like im gonna have to ah,got any more idea's
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you are running Internet Explorer...that process is going to run....end the task in task manager and see. What exactly are you worried about?
     
  29. dannyboy2008514

    dannyboy2008514 Private E-2

    when i end the iexplorer well it closes my internet page,well i can tell you this when i go in c: program files/internet explorer i see(iexplore.exe-iedw.exe-ieproxy.dll-explore.exe-hmmapi.dll-custsat.dll-looks like somwthing is generating iexplorer cause when i delete it well it comes right back not to long after
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Will you please believe me that it is a system file and the process in task manager is just showing that you are using Internet Explorer!! Leave it alone. :)
     
  31. dannyboy2008514

    dannyboy2008514 Private E-2

    ok but its wierd though that i just appeared not long ago,and also that when i have more then one internet page well my internet goes slower than before and the mem usage is higher and higher
     
  32. dannyboy2008514

    dannyboy2008514 Private E-2

    i rthink ill save what i can and just reformat, thank you alot ttyl next problem
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No it is not weird...having more pages means you are using more system resources...but if you would rather reformat, that is your call.

    This is no longer a malware issue.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have a file named explorer.exe in this folder. Delete the below file:

    C:\Program Files\Internet Explorer\explore.exe

    This file appears to just be a copy of iexplore.exe which is Internet Explorer. The real explorer.exe is in your C:\Windows folder and is signifcantly larger.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds