strange problems...am i infected?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by _BIG_, Feb 12, 2013.

  1. _BIG_

    _BIG_ Private E-2

    so about a week ago i got hit with a few problems.
    youtube and any flash videos would only play through about 20 seconds.
    thought it was a flash/shockwave issue but a reinstall of each didnt help.
    spybot s&d found a few registry and tracking cookies and cleaned things up after a few repeated runs and all seemed fine.

    a few days later the problem came back along with downloads making it to 99% then failing constantly on almost all file types but especially on antivirus/antimalware install files and even when updating programs i already have installed.
    comodo dragon and google chrome all give me "click here if not redirected to page" messages 3-4times in a row before loading the google search page when searching from the address bar.

    random blue screens of death with the message "kernal_data_inpage_error"

    have tried various different things, norton security suite (from comcast) came up empty, bitdefender AV free found a few items n cleaned (also whatever is going on now prevents bdAV from loading in the system tray)

    now im trying the process of cleaning suggested here.

    any help is greatly appreciated.

    sidenote tdsskiller found 5 items before i found the majorgeeks tutorial and all items defaulted to skip (which i changed to quarantine, on second scan items were present again). this time around nothing was found.

    will update with hitman and mgtools info since i dl'd the x32 hitman and cant dl anything outside of safemode.
     

    Attached Files:

  2. _BIG_

    _BIG_ Private E-2

    ok so hitman had issues uploading the files to the cloud so i reran it with settings set as if i had no internet connection ( i have two logs now)

    still no progress yet but hopefully someone can help

    i also uninstalled adobe reader, flash, shockwave, silverlight, java before coming across this forum
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. I apologise for the late response. We have been short staffed lately and there are only a few of us here volunteering at the moment. I am currently reviewing your logs as I sip my coffee, and I will give you an appropriate fix asap. ;)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs

    delete this folder:
    C:\ProgramData\blekko toolbars

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Tell me what issues remain.
     
  5. _BIG_

    _BIG_ Private E-2

    hello and thanks for the help.

    i re-ran hitman pro and it still had an issue sending 2 files to the scanner cloud but removed a few things (log attached)

    i then ran junk remover which seemed to be stuck on deep registry scan for almost the whole day (which i didnt get a log from) today so i reluctantly closed it, restarted my computer and re-ran junk remover. it completed quickly this time and removed some files (log attached)

    i reinstalled my comodo dragon browser (my browser i use all the time where i originally noticed issues).

    on IE and comodo dragon i can now download files fine (no more slowing down @99% until download fails)
    comodo dragon doesnt seem to have any redirecting issues at all now either)

    ie still gives me a "Please click here if you are not redirected within a few seconds." message if i search from google.com or if i search from the address bar.

    ive been running my system off a ubuntu usb stick for most of the week awaiting your help as to not make anything on windows worse.
    again thanks for your help
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can ask about this in the software forum if you like. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. _BIG_

    _BIG_ Private E-2

    Sorry to be a pain but I'm not sure I'm out of the woods yet.

    last night i got another blue screen of death with the kernal error again as stated in my previous posts.

    also im curious about the "Please click here if you are not redirected within a few seconds." error in internet explorer as that was one of my original issues (which occured in google chrome, comodo dragon, internet explorer and firefox) but now seems limited to just internet explorer.

    should i re run any scans again or try another set of steps?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, no need to re run anything. ;) I was not seeing any malware. Please ask in the software forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds