Roommate Covered My PC In Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Hee, Feb 19, 2008.

  1. Hee

    Hee Private E-2

    Hi!

    Back on 2/14, my roommate used my computer. She swears she only went to AOL Mail & Facebook, but I don't believe her. Even if she did, she's the type to click YES on everything she sees without reading it. Suffice to say, my computer is cover in Trojans & Adware.

    Symptoms:
    My system is slow as molasses, random webpages pop up, my Internet Security keeps resetting itself, I get "buffer overload" errors, & sometimes hundreds of rapid-fire 'blank' webpage tabs open up & cripple my system. I've even noticed strange ads superimposed on repectable website (Yahoo.com, Cnn.com etc). My system won't let me manually delete alot of stuff & I struggle with the Add/Delete Software function. On start up, I get a strange "Kmode" error upon start up & the icon for my C Drive is a big red X.

    I've run the following in an attempt to clean my system up:

    Ad Aware
    CW Shredder
    EST NOD 32 Antivirius
    ComboFix
    Spybot Search & Destroy
    Super Anti Spyware
    MGTools

    All of these programs helped, but something is still not right with my system. I've attached the required logs per the Sticky post. If you can, please help! :cry
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a few things to take care of:

    Please uninstall:
    Java 2 Runtime Environment, SE v1.4.2

    Then install:
    Java Runtime 6

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    I do not know what these are:
    C:\WINDOWS\SYSTEM32\43AEA1E35D.sys (Find this and move it to a folder on your desktop and rename it to some thing else, in case it is a needed file)
    C:\WINDOWS\TWljaGVsbGUgQWJib3R0 ----> remove this if you don't know what it is.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. Hee

    Hee Private E-2

    My computer is almost 100% better! It's speed has returned to normal, the error windows are non-existent, & the pop-ups have seemed to disappear. The only thing that's still noticeable is the big, red X that is showing as the C Drive's icon. I've attached the logs you requested. Thank you so much for giving my computer back to me!

    Quick question, should I be worried about passwords & credit card info on my computer? Should I get everything changed?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just to be sure:
    Please download VundoFix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will reboot your computer, click OK.
    * Please post the contents of C:\vundofix.txt.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.
     
  5. Hee

    Hee Private E-2

    It said it found no infected files & didn't create a log. Does that mean I'm infection free?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I believe so ...however we are still researching the red X ......in the meantime:
    Lets do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    *How to Protect yourself from malware!
     
  7. Hee

    Hee Private E-2

    I've deleted everything except the strange system file in a folder on my desktop. Am I ok to delete it?

    "C:\WINDOWS\SYSTEM32\43AEA1E35D.sys (Find this and move it to a folder on your desktop and rename it to some thing else, in case it is a needed file)"

    I've also done the system restore step & am looking through the link you provided.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Leave it in that folder but change the extention from .exe to just .xxx and if things continue to work ok then delete it (The file had a date a few years ago, which is why I was hesitant to remove it).

    As far as the Red X:
    Did this just occur now or was it there since you first started this thread? Can you attach a readable snapshot of this so we can better understand what it looks like? Use a tool like below which is great for capture just rectangular areas. It is the second of four programs listed on the page.


    FastStone Capture 6.0

    After attaching this snapshot, apply the below registry patch and tell me if it fixes the red x.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  9. Hee

    Hee Private E-2

    I've attached the pic...but after I added that stuff to my registery, the C Drive icon is back to normal!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet ..you can thank Chaslang for the registry patch. :)

    If everything is working...go ahead and remove that file we moved.
     
  11. Hee

    Hee Private E-2

    File removed & I've followed the steps in the "How to Protect Yourself from Malware" link. I've installed Avast! Antivirus & Spyblaster, as well as changed to Firefox & my Internet Security settings, as recommended.

    Thank you, Chaslang! And thank you sooooo much Mr. TimW! I would have been lost without you! My Hero! :) :heart
     
  12. Hee

    Hee Private E-2

    Just noticed a problem....my D & E Drives are no longer in 'My Computer'. Is that something I can reinstall with my original computer CDs?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the control panel / admin. tools / computer management / disk management and tell me if those drive are showing there.
     
  14. Hee

    Hee Private E-2

    Sorry for not responding, I've been sick with the flu. The drives weren't in Disk Management, but the were in System>Hardware>Device Manager. They were showing a Code 39 Error: Drivers are Missing. I managed to fix it by following the directions in this MajorGeeks Link: http://forums.majorgeeks.com/showthread.php?t=145532

    It gave me 2 drives for my 1 CD-RW drive in My Computer, but that's ok. Better to have more than none at all!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So you are the one that gave me the flu ....you must have sneezed on one of your replies...:D Glad you got things running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds