Please help me make sure my computer is secure.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rikimaru, May 18, 2010.

  1. Rikimaru

    Rikimaru Private E-2

    Hi all, I've always ran a firewall and anti malware software and been concerned with my computers security in general. But for a while I hardly ever scanned my computer and only ran windows firewall, until the AV virus came around it messed up my computer good.

    I got Super anti-spyware and PC Tools firewall and all was great for a few months until one day the firewall shut down and I got loads of pop ups and I did scans with SAS and Malware bytes and I kept finding and delete loads of infections over and over.

    The main problem I have is the firefox re-direction that a few other people on here seem to have, when I google something and click the link my browser often get re-direction to fake search wesbites etc.

    Anyway last week while I was getting all these infections I decided not to log onto my internet banking until my scans came back clean, when they did and I logged on, someone had broke into my account and stolen all the money in there by pretending to pay a fake bill.
    I only had a few hundred in there and I'm getting it all back from the bank which is good news but obviously now I need to make sure my PC isn't infected and make it as secure as possible, I'm hoping you guys will help me with this.

    I switched firewalls to Comodo and downloaded and installed AVG and deleted a ton of infections. Then I tried to fix the browser re-direction problem and found this forum where a lot of people seem to be having the same problem.

    So I have done the 'READ & RUN ME FIRST. Malware Removal Guide' and hoping some of you could help me with the results.




    I couldn't run the Combofix.exe because I don't have a printer to print out the instructions for when closing firefox.

    When trying to download MGtools I got this message:

    "C:\MGtools.exe could not be saved, because you cannot change the contents of that folder.

    Change the folder properties and try again, or try saving in a different location."

    I did managed to do SAS, Malwarebyes and Rootrepeal and have attached.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just download ComboFix to your desktop, then double click it.

    Same goes for MGTools.exe. Although we would like you to save it to the root folder ( C:\MGTools.exe ) you can download it to the desktop and run it from there.
     
  3. Rikimaru

    Rikimaru Private E-2

    Hi, sorry about the long wait in the reply, I was out jogging.

    I've tried to run comobfix and got lots of error messages like "Cannot access hidec.exe, "installation failed", "Cannot open nircmd.cfxxe"

    It also won't let me download MGtools to my desktop either or any other folder, I get the same error message.

    Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please try booting to safe mode and see if you have the same problem. If so, create a new user account with admin. privileges and see if you can install and run them through that user account.

    Have you tried doing a system restore to a point before this started?
     
  5. Rikimaru

    Rikimaru Private E-2

    Hi thanks for the reply.

    I tried to reboot in safe mode but everytime I do my computer restarts and says there was an error loading windows, and provides the boot options again.

    I haven't tried restoring but I will do that next to try get rid of the re-directing problem. Should I be worried about the rest of my computers security though?

    After the whole online bank hacking situation. I mean obv I should be worried in general but if I'm getting clean scans from AVG and SAS and have Comodo running do you think I'd be safe to return to the internet banking world?

    Thanks.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, I can't make a pronouncement on your system with out seeing the other logs.

    Is the main issue one with redirects only?

    If you have downloaded MGTools and put it on your C:\ drive, then click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  7. Rikimaru

    Rikimaru Private E-2

    Yeah the main issue is re-directs or sometimes a new window opens and sends me somewhere.

    I tried doing everything again and I still get the combofix error msgs and still can't download MGtools.

    During the Malwarebyts quick scan the same files I already scanned and deleted came up too I think.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to run this at all?

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  9. Rikimaru

    Rikimaru Private E-2

    Hi Kestrel thanks for trying to help.

    I did what you said and able to run the program, it found some malware deleted it then requested a reboot which I accepted.

    I have attached the log.

    Thanks.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good. Now try and run both combofix and MGTools again. Let us know what happens and attach the C:\Mglogs.zip if successful.
     
  11. Rikimaru

    Rikimaru Private E-2

    Hi Kestrel, I first tried to run combo fix and it said I didn't have the correct permissions, though my user is an admin user. I created a new user account anyway and it started to run but it then said I may have the virus 'Virut' and combo fix has been compromised.

    I then rebooted because the system seemed to crash, I logged back onto my original user and this time combofix ran correctly, although I got stuck on the preparing logs screen for about 20 minutes so I again rebooted.

    Do you want me to run MGtools now or run combofix again?

    Thanks.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think your only option might be to reformat and reinstall windows. :( We will leave TimW to have the last word on that though. If combofix is correct in it's report about you being infected with virut (and it usually is) Then I don't think you have any alternative than to reformat.
     
  13. Rikimaru

    Rikimaru Private E-2

    Ok I'll wait to see what TimW says.

    What is Virut? Is there any other way I can confirm I have it?

    Like I said Combofix did run the 2nd time and scanned and deleted files but it was preparing the logs for 20 mins so I decided to close it down.

    Thanks.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, let's just wait and see what TimW says when he logs in again tomorrow. He will be winding down for the evening now before going to bed.
     
  15. Rikimaru

    Rikimaru Private E-2

    Ok thanks Kestrel.
     
  16. Rikimaru

    Rikimaru Private E-2

    Hey Kestrel, is it just the partition with windows installed on that I need to format? I have a C: drive with it on and an E: with music, movies, games etc. on that I'd like to keep.

    If it is just the C: Drive I might just do it now anyway, but if it's both and theres a chance to save me from doing it then I will wait.

    Cheers.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just wait for Tim ;)
     
  18. Rikimaru

    Rikimaru Private E-2

    Haha I had a feeling you would say that.

    Ok I will wait.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Without seeing the ComboFix log and not being able to run MGTools to get that log, the safest thing to do is to go ahead and reformat the C: drive, as long as you have no exe files on the partition in E:. Do not reinstall anything from a thumb drive or other media at that time. Make sure all programs are fresh downloads. DO not move any exe files to the E: drive.

    Once you are back up and running, then proceed with doing the scans anew to make sure there is no infected files on the partition.
     
  20. Rikimaru

    Rikimaru Private E-2

    Hi TimW, I tried running MGlogs and it worked, I was able to download after running TDS Killer.

    I've attached the MGTools log.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you attach the ComboFix log?
     
  22. Rikimaru

    Rikimaru Private E-2

    I searched combofix.txt and I found it in a folder in C:\Combofix\Combofix.txt...I hope this is it. I've attached it.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The good news is that you don't have a virut infection. Let's just do this:

    You need to disable the AV portion of Comodo since you also have AVG running.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Benjamin\Local Settings\Application Data\Q8T6845
    C:\Documents and Settings\Benjamin\Local Settings\Application Data\rQVN4I4g
    C:\WINDOWS\system32\zigaweje
    
    Folder::
    C:\Documents and Settings\Benjamin\Application Data\Mozilla(2)
    C:\Documents and Settings\Benjamin\Application Data\Mozilla(4)
    C:\Documents and Settings\Benjamin\Local Settings\Application Data\Q8T6845
    C:\Documents and Settings\Benjamin\Local Settings\Application Data\rQVN4I4g
    C:\WINDOWS\system32\zigaweje
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run CCLeaner and make sure these folders are cleaned out:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Benjamin\Local Settings\temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  24. Rikimaru

    Rikimaru Private E-2

    Hi TimW, ive done what you said and im up to the point of running getlogs.bat but as soon as I ran it in cmd.exe it gave the error "the process cannot access the file because it is being used by another process" and it has stayed like this for about 10-15 mins now. How should I proceed? Thanks.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why are you running it in cmd.exe? Just right click the getlogs.bat and run as administrator.
     
  26. Rikimaru

    Rikimaru Private E-2

    I'm on windows XP so I double clicked. I tried right click and run as admin but I can't find that option.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah, right. If you still can't get it to run, delete it and download a fresh copy of MGTools.exe and let it over ride the old one.
     
  28. Rikimaru

    Rikimaru Private E-2

    Ok I deleted the Getlogs.bat downloaded MGtools.exe and ran it again. I then tried to run getlogs.bat again and I got the same error messages.

    Was that what you wanted me to do?
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, this is the poo. Are you sure you are waiting long enough for it to run?

    Did you do the Combo fix and do you have that log to attach?
     
  30. Rikimaru

    Rikimaru Private E-2

    Yeah I did the combofix, I've attached the log.

    I've left it for about 40 minutes after running getlogs.bat I get that error message about 5 times over in cmd and then the screen never changes.

    EDIT* I also ran CCleaner and added the folder you said into the advanced settings part to make sure they were cleaned out.
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Check in task manager that it is not still running. Your combo log is good and I am seeing an MGLogs.zip from today's date at a little after 5pm. ( Is that what you already attached?)

    What issues are you still having?
     
  32. Rikimaru

    Rikimaru Private E-2

    Ok I rebooted and tried running getlogs.bat again and this time it worked I think. It ran in cmd.exe similar to what MGlogs does. I got various "Cannot create output files MGlogs.zip" errors but then when it ended it said my logs had been saved to MGlogs.zip but it is not there in my C:

    Thanks.
     
  33. Rikimaru

    Rikimaru Private E-2

    Basically after last nights car crash of everything going wrong my system started running really really slow, which it wasn't doing before.

    But after everything going kinda well today, my system has speeded back up and seems to be running fine, I also have not had any browser re-direction so far today.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Car crash? I certainly hope no one was injured.

    Do a search for the new MGLogs.zip.....it should be where we tell you it is --> C:\MGlogs.zip.

    It may not be real important as I think you are clean, but the log would tell me that.
     
  35. Rikimaru

    Rikimaru Private E-2

    My fist almost injured my dumb computer :) lol

    I searched for MGlogs.zip and could not find it I decided to reboot as that worked for everything else and the MGlogs.zip file has suddenly appeared... I have attached it.

    Thanks.
     

    Attached Files:

  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately all that was in that was the Uninstall keys log. Try doing it in safe mode. I would really like to be able to pronounce you clean.
     
  37. Rikimaru

    Rikimaru Private E-2

    Ok I was able to boot in safe mode which I couldn't do before and ran getlogs.bat without any problems and I think it worked this time. I've attached the logs.
     

    Attached Files:

  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, that worked. Let's remove an empty folder and a reg key.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\Benjamin\Local Settings\Application Data\prvlcl.dat
    c:\windows\system32\drwtmlby.dll
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
    "eveninit"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  39. Rikimaru

    Rikimaru Private E-2

    Tim I'm having trouble flushing my system retore. I can see no system restore tab on My Computer > Properties.

    Thanks.
     
  40. Rikimaru

    Rikimaru Private E-2

    No matter I fixed this by doing it in safe mode instead.

    I will now run through the 'How to protect yourself from malware!' guide and hope that something like this doesn't happen again :)

    Thankyou very much for your help TimW and Kestrel.

    I was also wondering if there is a place to look for news updates on Malware...new widespread viruses and how to prevent getting them and such, like a malware blog.

    Well I will stick around the forum anyway but hopefully I won't be back in this part of it again :)

    Thanks for the help and cya around.
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. BleepingComputer.com is a good place to check on latest malware threats. You can also become a member/friend on FaceBook and get alerts that way.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds