Please help, malware removal, at my wits end

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ferdia6, Aug 16, 2010.

  1. ferdia6

    ferdia6 Private E-2

    Hello, any help you could give me would be greatly appreciated.

    I appear to have malware on my computer and have had it for over a month. It could also be spyware, viruses and trojians too, not sure.
    I've tried nearly 10 different viurs/malware scans and the problem persists. I can only assume its a rootkit type of infection.

    Basically IE, firefox and google chrome will randomly open new windows linked to malicious websites, also, clicking on links in google etc. make malicious websites load, instead of the intended link.

    I have followed all the steps in the removal thread and will post the logs below. MG log is attached.
     

    Attached Files:

    Last edited by a moderator: Aug 16, 2010
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    *attaching remaining log*
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    
    File::
    c:\windows\Alcmtr.exe
    
    Folder::
    c:\documents and settings\admin\Local Settings\Application Data\qvsowtfgn
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    I am curious about this driver and it's corresponding file:

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\docume~1\admin\LOCALS~1\Temp\asbp2poa.sys
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Could you please get this: asbp2poa.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:


    log retrievable @ C:\collect.zip

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also include the jotti results and the collect.zip.

    Are you still being redirected? I doubt it though as combofix dealt with what I believe was the main cause of your issues.

    Tell me how the machine is running.
     
  5. ferdia6

    ferdia6 Private E-2

    Many thanks for your reply Kestrel13

    Unfortunately, I have searched my C drive for the file you were looking for and can not find it. It appears to have dissapeared

    I searched in C/documents/admin/local settings/temp and it's not in there.

    To be honest, since following the malware removal steps on the forum, the problem has not re-created itself since. No new or suspicious windows/links have opened in a day.
    You are right about combofix probably fixing it


    Sorry but the run %systemdrive% command didn't give me a zip file in the C drive either...
    I can't link you a Jotti zip as the file you wanted me to scan didn't exist (anymore?)
    I've attached a new MGtools zip.

    Thanks again for your help I really appreciate it

    Ferdia
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well it appears that you did not run my combofix script. You need to do this now and then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. ferdia6

    ferdia6 Private E-2

    Ran CF and log attached.
    Then I re-ran MG and log attached again

    Thanks,
    Ferdia
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's better. Okay, let's kill off that service...

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    asbp2poa
    
    File::
    c:\docume~1\admin\LOCALS~1\Temp\asbp2poa.sys 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. ferdia6

    ferdia6 Private E-2

    Thanks, log attached again
     

    Attached Files:

    • log.txt
      File size:
      27.5 KB
      Views:
      2
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget this part!


     
  11. ferdia6

    ferdia6 Private E-2

    Oh sorry

    here it is
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's better, I feel more at ease with what we just removed out of the way.

    delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. ferdia6

    ferdia6 Private E-2

    Fantastic, thank you very much for all your help with this
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome! safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds