Malware still present

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Chinook2, Oct 27, 2009.

  1. Chinook2

    Chinook2 Private E-2

    I got blasted with a bunch of Trojans (Vundo, Ertfor, FakeAlert, Agent). I ran Malwarebytes, CCleaner and SuperAntiSpyware on each user account until it appeared all the Trojans were removed. However, every time I followed a hyperlink on IE it directed me to a different website.

    I am unable to start in safe mode. I have issues with Adobe Acrobat which produces "Error 1402 could not open key" when either updating, repairing or uninstalling.

    I then followed the instructions in the Read and Run Me First. Again, every time I follow a hyperlink it directs me to a different site. I have attached the logs from all the scans. Thanks in advance for your assistance.
     

    Attached Files:

  2. Chinook2

    Chinook2 Private E-2

    And the final log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    When you run scans multiple times and do not give us the first logs which is what we really need, you prevent us from seeing what we need to see. That is why the READ & RUN ME emphasizes to only run scans once and not to run them again. The logs you attached from SAS and MBAM obviously show nothing but you have other logs from them they show what problem were removed. That is what we need to see. You need to now attach all of the below logs you can put them into a ZIP file to make it easier since you can only attach 4 logs max in any message
    Code:
    "C:\Documents and Settings\Stephen\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Oct 25 2009        1149  "SUPERAntiSpyware Scan Log - 10-25-2009 - 18-25-23.log"
    Oct 24 2009        1855  "SUPERAntiSpyware Scan Log - 10-24-2009 - 18-08-55.log"
    Oct 17 2009        1980  "SUPERAntiSpyware Scan Log - 10-17-2009 - 15-32-46.log"
    Oct 17 2009        1660  "SUPERAntiSpyware Scan Log - 10-17-2009 - 21-51-20.log"
    Oct 23 2009        5477  "SUPERAntiSpyware Scan Log - 10-23-2009 - 11-12-42.log"
     
    "C:\Documents and Settings\Stephen\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Oct 23 2009        4183  "mbam-log-2009-10-23 (17-06-18).txt"
    Oct 23 2009        2031  "mbam-log-2009-10-23 (17-29-10).txt"
    Oct 13 2009        1207  "mbam-log-2009-10-13 (15-42-28).txt"
    Oct 23 2009        1578  "mbam-log-2009-10-23 (17-34-15).txt"
    Oct 17 2009        4253  "mbam-log-2009-10-17 (00-21-56).txt"
    Oct 17 2009        1528  "mbam-log-2009-10-17 (12-04-43).txt"
    Oct 17 2009        2412  "mbam-log-2009-10-17 (00-57-46).txt"
    Oct 17 2009        1424  "mbam-log-2009-10-17 (16-49-44).txt"
    Oct 17 2009        1561  "mbam-log-2009-10-17 (01-14-51).txt"
    Oct 17 2009        2151  "mbam-log-2009-10-17 (01-10-41).txt"
    Oct 17 2009        1561  "mbam-log-2009-10-17 (07-37-10).txt"
    Oct 17 2009        3590  "mbam-log-2009-10-17 (07-32-08).txt"
    Oct 17 2009        1527  "mbam-log-2009-10-17 (01-24-29).txt"
    Oct 17 2009        1562  "mbam-log-2009-10-17 (07-42-44).txt"
    Oct 23 2009        1161  "mbam-log-2009-10-23 (10-18-02).txt"
    Oct 17 2009        1515  "mbam-log-2009-10-17 (07-53-21).txt"
    Oct 17 2009        1562  "mbam-log-2009-10-17 (09-26-06).txt"


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java(TM) 6 Update 15
    MyWay Search Assistant <-- should have been uninstalled in step 5 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 5 of the READ ME


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Oct 30, 2009
  4. Chinook2

    Chinook2 Private E-2

    Thanks so much for helping.

    I have attached the SAS and MBAM logs as zip files.

    I didn't realize the other software was present. I will unistall it.

    The ComboFix.exe file that I downloaded and used previously is not on my desktop. I expect it was deleted. I do have the first combofix.txt file on the desktop and a folder C:\Qoobox with some dat files and a quarantine folder.

    Should I download another combofix.exe to the desktop?
     

    Attached Files:

  5. Chinook2

    Chinook2 Private E-2

    I downloaded a new combofix.exe file and ran it with the script text file.

    Part of the way through a pop-up said: "Combofix has detected the presence of Rootkit activity and needs to reboot the machine". Computer rebooted and combofix finished its process.

    Balance of recommended procedures followed.

    New logs attached.

    Thanks again for all your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds