PC is riddled w/ malware, adware, redirect etc

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gqfaz, Dec 3, 2010.

  1. gqfaz

    gqfaz Private E-2

    Hello. I have the Google Redirect, various adware that opens itself in new tabs, (one of which for some reason resizes my my browser from max to about 2/3rds of the screen when it does it) along with malware which seems to have installed additional malware and has hacked my hotmail and is sending spam to my contacts. I've read and run the Read and Run Me First, as well as the Vista (Windows 7) cleaning procedure. Actually I've done it a couple times before in regular and safe mode, and everything seems fine for a little while, (except for the Google redirect, that never goes away) but it all multiplies and creeps back in again.

    I've never been able to do it in full however, because a) Combofix wont work. The bar fills up, disappears, and then nothing. Nothing on the Task manager or under svchost services or anything that seems to be running. and b)Rootrepeal has NEVER worked for me. Even in the past when I seemed to have had less problems. I get a "FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x0000011c)" error message every time.

    Attached are the SAS, the Mwarebytes and the MGTools logs. Thank you so much for your help.
     

    Attached Files:

  2. gqfaz

    gqfaz Private E-2

    I also just did a free ESET scan which uncovered more garbage.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC without proper protection?

    You are almost 1200 database versions out of date with Malwarebytes. Thus you did not update it as requested. Also there is a new version out now too. You need to run it and then select update. After updating, it will likely ask you to reboot your PC. Please do so. After reboot, run a new scan and then attach the new log. Then continue on with the below.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O20 - Winlogon Notify: youma1 - youma1.dll (file missing)
    O23 - Service: Viewpoint Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new log from Malwarebytes
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. gqfaz

    gqfaz Private E-2

    Perhaps you are mistaken about the Mwarebytes thing. I followed every step, and installed the new Mwarebytes. Twice in fact, because my computer was starting to become unusable due to additional viruses that I had to do a system restore, so I downloaded it again after doing the restore. And when I just updated it, it said I've updated from version 5214 to 5257. All that aside, here are the logs. I threw in the TDS log as well. Thank you so much.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I was going direct from your logs. In the first message you posted, the Malwarebytes log show the below which was way out of date
    Code:
    Malwarebytes' Anti-Malware 1.46
    [URL="http://www.malwarebytes.org"]www.malwarebytes.org[/URL]
    Database version: 4052
    
    Now you have the below which is properly updated
    Code:
    Malwarebytes' Anti-Malware 1.50
    [URL="http://www.malwarebytes.org"]www.malwarebytes.org[/URL]
    Database version: 5257
    You did not address my question as to why you have no protection installed.

    It appears that my last fixed removed your remaining malware. Are you currently having any malware problems?
     
  6. gqfaz

    gqfaz Private E-2

    Guess I stupidly thought that having and running all of these programs qualified as protection. Which of the myriad of programs out there do you recommend? Not only for effectiveness but for efficiency in terms of not slowing my PC down? So far so good on the viruses, thanks! Except for one thing I forgot to mention. My hotmail acct has been hacked and is sending spam like crazy to my contacts. Any idea how to rid myself of this? Thanks again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After the fact scanning is not protection. You need to have active protection always running.

    The link in my final instructions address this.

    Are you sure that it is still happening? That is, are new emails going out. If someone had your login and password, you will have to change them. Also if they have stolen your contacts list, it is already too late to do anything about it. This is one of hundreds of reasons why you needed to have proper active protection. The safeset thing to do may be to change the password on your old account, and then see if you can have the account name either changed to a new ID or deleted. Then inform all of your contacts to ignore/delete any email from your old account ID and only pay attention to your new account.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds