malware virus hijacked my .exe files

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by randyh43, Jun 17, 2010.

  1. randyh43

    randyh43 Private E-2

    My friends at Major Geeks,

    Please help me with a malware virus that has hijacked all of my executables.
    I recently had a similar problem you helped me fix but unfortunately someone using my computer has caused the return of new menace.
    ** The computer was stable for months after your last fix and I had previously downloaded and installed all of the "read and run me first" instructions. I am writng to you from another computer since I am unable to run my AV programs and Malware bytes programs from the computer that is infected etc. Please help!

    Thank you.
     
  2. randyh43

    randyh43 Private E-2

    log files for AV antivirus suite problem

    Dear Major Geek,

    I ran through the Read me first instructions.
    SuperAntiSpyware did not detect a virus. I don't believe it created a log.
    Attached is the log for Malwarebyts. 3 infections.
    The AV Antivirus suite virus that I have did not seem to allow me to properly run combo fix or root repeal or MGtools. I tried to run these but I find no log files for them. I kept getting the message file is infected cannot run and then my browser would open to ask to buy the AV Antivirus software etc.
     

    Attached Files:

  3. randyh43

    randyh43 Private E-2

    AV Antivirus suite

    Dear Major Geeks,

    I'm sorry for the multiple posts but I had to attach new log files that I was not previously able to get with the clean up tools installed during read and run me first. Attached is a new Super Antispyware log and root repeal log. I was not able to run Combofix having this virus. The one time that it worked it began scanning with the open dialogue box but after 5 minutes, I got the blue screen of death and windows shut down.
    I am sending a new Malwarebytes log in another thread.
     

    Attached Files:

  4. randyh43

    randyh43 Private E-2

    AV Antivirus virsus - Malwarebytes log

    Attached please find the Malwarebtyes log. Once again sorry for the multiple posts. It was difficult for me to get the files you needed working around this very nasty virus. I was still unable to run combo fix. I tried repeatedly with no luck. I'm desperate so I hope you can help quickly!
    Thank you very much !
    Randy
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me what happens when you try to run C:\MGTools.exe. Are you still having issues with exe files? Have you tried changing it to MGTool.com? Does that allow it to run?

    You can try this procedure to fix the exe files:
    http://www.dougknox.com/xp/file_assoc.htm --> scroll down to the ninth file fix.
     
  6. randyh43

    randyh43 Private E-2

    Hello Tim,

    Thanks for the quick reply. I was able to finally run MGtools.exe. Attached is the zip file. My executables are working now but I'm certain the virus is still in the back ground because both explorer and firefox are constantly redirecting me to other websites which never happened before. I also have avoided rebooting my computer since running Malwarebytes and Super Antivirus because upon reboot the virus has come back every time. It begins to give me the ad for the AV Antivirus software and bringing up dialogue boxes when trying to enter any program etc. I was unable to run Combo fix. Is this important? Do you need me to re-run it? I have a 32 bit system. Thank you very much for your assitance. :)
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  8. randyh43

    randyh43 Private E-2

    Dear Tim,

    Attached is the TDS Killer log file. When I ran this program, it did not prompt me to delete anything. It said it needed to reboot to finish the fix and once the computer rebooted the AV Antivirus started again. I guess I will now have to rerun Malwarebytes and SuperAntivirus. We are back to square one again. The first TDS killer log file I am sending was run before it asked me to reboot and after having stabilized the computer somewhat by running Malwarbytes and Super Antivirus. The second TDS Killer log file I am sending was run after it asked me to boot up again and after the all of the problems returned.
     

    Attached Files:

  9. randyh43

    randyh43 Private E-2

    Dear Tim,

    Further to the below problem, I re-read all of the "Read and run me first" instructions to see if I accidentally skipped any important steps. I realized that I accidentally ran SuperAntivirus as a quick scan instead of full scan.
    Upon running the full scan, the program found more viruses than the first time around. Upon following the reboot request, it seems to have eliminated
    the AV Antivirus suite however I am still carefully going through the rest of the cleap up instructions. I will revert with new logs for all clean up programs and then talk to you about toggle system restore etc.
    Thank you !
     
  10. randyh43

    randyh43 Private E-2

    Dear Tim,

    Attached please find new...
    1. Saslog.txt
    2. Malwarebytes log
    3. Combofix.txt
    4. root repeal log txt
    I will send the MGTools in another reply. The system seems to be stable
    but please review and instruct me on any final steps.
     

    Attached Files:

  11. randyh43

    randyh43 Private E-2

    Dear Tim,

    Attached please find the MGLOGS.ZIP file.

    Awaiting your final instructions.

    Thank you and thanks to everyone at Major Geeks. I don't know what people would do without you guys!
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I looks like the scans took care of most of it.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    Driver::
    B-Service
    File::
    c:\documents and settings\Randy H\Local Settings\Temporary Internet Files\Content.IE5\DSAGUM69\B-Service.exe
    c:\documents and settings\Randy H\Local Settings\Application Data\fiycxfux
    c:\documents and settings\Randy H\Local Settings\Application Data\kqmeshq
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. randyh43

    randyh43 Private E-2

    Dear Tim,

    I followed your instructions below. Attached please find the two files you requested. The computer is behaving normally. Let me know if we are good to go on your end as well or if we still have more clean up to do. Thanks a million to Major Geeks! You guys are like super heroes! :)

    Regards,
    Randy
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, although Combo said it removed them, they still exist. So let's have you ddownload The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  15. randyh43

    randyh43 Private E-2

    Hi Tim,

    I followed your instructions and ran Avenger, CCleaner and MGTools.
    Attached are the files you requested. I assume that when you re-run programs that are saving log files in the exact same location with the exact same file name that you are receiving the latest version of that log even though many times the computer does not prompt saying "there is already a file name with that name do you wish to overide it and save new etc. "

    My computer is running stable and booting quickly. No sign of the bad guys! Thank you !
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  17. randyh43

    randyh43 Private E-2

    Dear Tim,

    I followed all the last steps you gave me. The computer is running normally.
    Thank you very much for all of your help!

    All the best to everyone at Major Geeks!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds