Problem - scan logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Derwydden, Jun 6, 2010.

  1. Derwydden

    Derwydden Private E-2

    Hi

    My problem started about three days ago and it may be associated with installing the DZSOFT Favourites sidebar for Google. That programme did not work and was uninstalled but I started to get problems the next day.

    The initial problem was that when I made a Google search in IE (7 I think it is) and then clicked on the search result I started to get re-directed to an unrelated website such as K Directory. Then I started getting a rogue Spy Ware programme called Anti Spyware Soft telling me that I was infected with this that and the other.

    IE stopped working, my firewall can not be activated but Firefox does work. could not uninstall AVG antivirus programme to work or uninstall. I tried going back to a restore point and IE worked again and Firefox stopped working. The Anti Spyware Soft programme stopped coming up all the time but the redirects kept coming and after reinstalling Firefox transfered to it to. I was following some instructions on here and when I renabled all start up objects the Anti Spyware Soft came back.

    I undid the restore point so that at least I could used Firefox and started following these instructions in a strict way for Windows XP.

    Some logs are attached. However, I did have problems:
    When closing Malwarebytes I had an error message. Could not run ComboFix because ComboFix said that AVG scanner is running. Which it does not appear to be but I tried to uninstall it in add remove programmes but it would not initialise. In Roo Repeal I had the message "error - attempt to read from address: 0x01eco248"

    As I only have only 3 sets of logs then I have just posted those. If you can help me I would be most grateful to you.

    Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Part of your problem is with downloading cracks. Please read this:
    Warning about Porn, Keygens, Cracks, and other Illegal Software

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Please go here and download and run the AVG Removal Tool.

    After a reboot, run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    File::
    C:\WINDOWS\Temp\4.3779131591970675E7.exe
    C:\WINDOWS\Temp\a3569390.exe
    C:\WINDOWS\Temp\CR_208.tmp
    C:\WINDOWS\Temp\fla226.tmp
    C:\WINDOWS\Temp\ib1FA.tmp
    C:\WINDOWS\Temp\ib1FB.tmp
    C:\WINDOWS\Temp\ib1FC.tmp
    C:\WINDOWS\Temp\ib1FD.tmp
    C:\WINDOWS\Temp\ib1FE.tmp
    C:\WINDOWS\Temp\ib1FF.tmp
    C:\WINDOWS\Temp\ib200.tmp
    C:\WINDOWS\Temp\ib201.tmp
    C:\WINDOWS\Temp\ib202.tmp
    C:\WINDOWS\Temp\ib203.tmp
    C:\WINDOWS\Temp\ib3.tmp
    C:\WINDOWS\Temp\ib4.tmp
    C:\WINDOWS\Temp\ib5.tmp
    C:\WINDOWS\Temp\ib6.tmp
    C:\WINDOWS\Temp\ib7.tmp
    C:\WINDOWS\Temp\is20A.tmp
    C:\WINDOWS\Temp\is20C.tmp
    C:\Documents and Settings\Owner\Local Settings\Temp\173EBE.dmp
    C:\Documents and Settings\Owner\Local Settings\Temp\173ECE.dmp
    C:\Documents and Settings\Owner\Local Settings\Temp\831705f8-47bb-41d8-924e-ec9bfff2694ee83f7970715f11dfa21a001a4d42d488
    C:\Documents and Settings\Owner\Local Settings\Temp\resource.h
    C:\Documents and Settings\Owner\Local Settings\Temp\svh85.tmp
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\foivxmsmj\pkmayamtssd.exe
    Folder::
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\foivxmsmj
    Registry::
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "vhcnxowq"="-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Derwydden

    Derwydden Private E-2

    Hi Tim

    Thanks for you help mate!

    On the positive side I did remove: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

    In general I am still experiencing problems and in particular this page popped up in Firefox even after it's removal: news-11-today.com

    Still having some problems with the AVG:
    - When I ran the AVG remover it indicated that it could not find it. I ran it several times and I attach the last log called 'avgremover.log'.
    - AVG doesn't show up under add remove programmes although it's logo does show up next to this file: 'Microsoft Compression Client Pack 1.0 for Wndows'.
    -It does still show up on when I click Start and then Programmes. It shows as AVG free edition but if you click on that it says that the shortcut is missing.
    - Finally, when I ran Combo Fix by dropping the CFscript.txt onto it. It does as before say that 'Combo Fix has detected the following real time scanners to be active: antivirus:AVG 7.5.524

    I don't know how AVG can be still running but I did not want to continue with running the ComboFix scan without you saying that it is ok to do so.

    As I failed at that step (Combo Fix) I did not run the C:\MGtools\GetLogs.bat file.

    I appreciate your assistance.

    Thank you

    Regards
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. Derwydden

    Derwydden Private E-2

    Hi thanks again. I don't know how you manage to do all of this.

    After following the procedure things seem to be a lot better gain but not completly resolved. After the last procedure I forgot to say that Internet explorer started working again but with redirects. But now the problem of unwanted pages opening is much less (like one in 30 searches and sometimes without searching) and here is an example of what I get:

    http://4stroke.org/result.php?Keywo...f5702e3c4145708c2894f7ceafcb474db6f&Submit=Go

    http://electronicboats.com/key/?qs=...3819c1c995c80fde9b7a7f11f37d&t=books+military

    http://www.historyofwar.org/readingframe.html

    I confess I messed up a bit and omitted to run Ccleaner at the appropriate point. Also I reopened this thread by first saving the tabs that I was using in Firefox which in retrospect I thought might actually be keeping the Malware alive because it came up with the same bogus internet pages immediately.

    So I ran through the procedure again from memory and executed the orders correctly and the appropriate logs are attached.

    P.S. my internet Firewall which came with XP still won't open and I need your recommendation for the best antivirus

    Thanks a million
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have lots of remnants of AVG still on your system. Please go here and download and run the AVG Removal Tool.

    Now, run CCLeaner and then run ATF Cleaner by Atribune.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    You need to download and install an AV program as suggested here:
    How to Protect yourself from malware!

    As well as a firewall, which I would suggest being PCTools Firewall ( without ThreatFire!!).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds