Malware, trojans, adware... ugly situation

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Fernando Magallanes, Jul 20, 2009.

  1. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hello!:wave

    The tittle says it all. Here are the logs I was able to get.

    NOTE:

    MB - it began to run, then it came to a halt right after I began the scan. The computer does not allow me to run the program (same happened after I ran SAS, luckily I was able to get that log...).

    RR - It said that 'our kernel couldn't be loaded, please see the author'...

    I've been successfully aided before, thus I'malways appreiating the job of the people here. The help is very much appreciated!

    Much oblige

    FM
     

    Attached Files:

  2. Fernando Magallanes

    Fernando Magallanes Private E-2

    Sorry - I forgot to include the MG log!!

    No Bumps intended!

    FM
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Fernando

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Fernando


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Note: Giving all users "Administrator Accounts" is a very bad idea.

    * I strongly suggest that you increase your installed RAM.
    Total Physical Memory ------- 512.00 MB
    Available Physical Memory --- 88.96 MB

    * Question: Is " Fta_Caribe_Fta_Para_todos Toolbar " something you knowingly installed and use?

    Step 1:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Open Malwarebytes Anti-Malware - after updating the definitions database, try again to run a Quick Scan.

    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt
    • mbam-log.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  5. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hi Dr.
    Thanks. I changed the administrator to only 1. Also, that toolbar was downloaded on purpose, but I have erased it (I never liked it, actually I don't like toolbars...).

    The RAM does need to be increased. I will be working on getting more after the fix. Thanks for all the advise.

    Now. I ran all the steps (MB - I uninstalled it and installed it again, and it worked).

    Things are feeling a bit better with the overall performance of the computer.

    Much obliged

    FM
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, Fernando



    Download Registry Search (see the link titled RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, and enter the below 2 strings (use copy and paste)
      • {17DDD097-36FF-435F-9E1B-52D74245D6BF}
      • {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file to your next reply.

    Now we need to remove a left-over from Symantec:

    Run Norton Removal Tool (SymNRT) 2009.0.5.26 > reboot > run it a second time.

    Thanks!
    dr.m
     
    Last edited by a moderator: Jul 27, 2009
  7. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hello Dr.!

    Thanks again. Did all the steps, and attached the log. crossing my fingers

    thanks for your help

    FM
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Fernando

    I have a couple of things for you to do.

    We need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Please attach the C:\combofix.txt log to your reply.

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited: Jul 30, 2009
  9. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hello Dr!

    Thanks. It ran smoothly, no problems. The computer has been handeling better, no more annoying messeges of infestation.

    Much oblige

    FM
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Another bad CLSID to get rid of!

    We need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Please attach the C:\combofix.txt log to your reply.

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  11. Fernando Magallanes

    Fernando Magallanes Private E-2

    Hi Doc,

    I ran the Combofix, but I had to re-download it; actually last time I also had to re-download it in order to run it; sorry I did not mentioned that before, just thought of it as a glitch...

    I did download it and ran it, attached is the log. The computer is running better as we speak, but that the combofix disappears out of the blue is kinda weird, aint it?

    Thanks

    FM
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi!

    Let's get rid of this last item and hopefully the next log will be clean! * Please do not wait to run this - run this fix promptly without delay.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Please attach the C:\combofix.txt log to your reply.

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds