Malware Problems. A little help....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rayster, Oct 20, 2007.

  1. Rayster

    Rayster Private E-2

    Well I read the rules before posting any Malware Problems here, but I think it is outdated since its 2007 now.

    Can you guys provide me what to do? I am positive that my pc is infected with malwares.

    Before the great accident happen. my IE7 use to have a "Brush Paint" functions sometimes to others sites like what it was in MSPaint and it is color Pink. I thought this was a bug with the IE7, then I switch to Mozilla Firefox and its ok.rolleyes

    The worst thing I have done is downloading a Trojan Hunter from a P2P sites to get the Full Version. Of course I scan it before opening, which my NOD32 didn't detect anything. So I install it and move the crack files into its program directory.

    I open its shortcut in the desktop, and all of the sudden, all of my anti spyware/virus/ym etc. in my Tray Bar closes by itself. With the Option to send the Error to Microsoft or Don't Send. Then my Pc went freeze and hangs alot, so I decided to restart my pc.:cry

    Then use to scan with my Ad-aware and Spybot and they almost deleted almost all cookies. My NOD32 didn't find anything suspicious. I also use CCleaner to delete some of uneeded files and registry entry. Then restart my pc.

    After I recover my Tray Icons, one thing is not been solve. Everytime I open my YM it sign in me, then a pop sound will be heared and my YM closes by itself (Send Error/Don't Send). So I tried Install it again. But no luck, its all the same.

    For those experts and willing to help a poor guy here, I really appreciate it very much.

    I also use GoGoGoData Adbuster in my Tray Bar.

    I hope you can give instruction to follow so that I can make myself solve my problems from the help of you guys. ;)
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Rayster


    The Read Me guide if thats what your refering to as the rules are upto date as malware is moving on so to the steps in the guide move with the times too, just the original post was made in 06-23-04 but the edits to that post/thread are currently at 09-14-07 ( all applications mentioned in the guide for download are at their last known current version too )


    http://forums.majorgeeks.com/showpost.php?p=664939&postcount=2

    So please do run that guide and attach the logs requested.
     
  3. Rayster

    Rayster Private E-2

    I follow all.. So here's the files...
     
    Last edited: Feb 9, 2008
  4. Rayster

    Rayster Private E-2

    Here's the last 2, I hope you guys help me. ^_^
     
    Last edited: Feb 9, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the correct log from the BitDefender scan. What you attached is a log summary which is not useful and does not tell us exactly where things were found nor whether they were fixed.

    Also you skipped a required step! CounterSpy or AVG Antispyware should have been run right after running Spybot. Also a log from one them should have been attached. Also you did not follow the step for Spybot. You are using version 1.4 and version 1.5 has been available for quite awhile now. The READ ME is up to date but you need to click the links given in it to make sure you are using current tools.

    Why do you have so many newly installed drivers and DLL files? Was a lot of software just installed on this PC? On second look, it appears from your Program Files folder that you did just installed about 61 new programs since Oct 16 th. This can be a dangerous thing to do because it would be impossible to determine what software could be causing a problem (if problems occur) because too many thinks were installed in such a short time frame. In addition, it make it extremely difficult for us to locate any potential problem files on your PC since almost everything is new and this makes your logs huge with thousands of things to look at. This makes it even more important that you run the automatic scanners. So please run either CounterSpy or AVG Antispyware now and attach the log. Then continue on.


    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    The delete the below files if found:
    C:\WINDOWS\system32\TUKernel.exe
    C:\WINDOWS\system32\Sys32\NBRY.007_tobedeleted_old

    Also tell me what else is in the C:\WINDOWS\system32\Sys32 which is not a normal folder to have and appears to be very questionable.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
    Make sure you tell me how things are working now!
     
    Last edited: Oct 21, 2007
  6. Rayster

    Rayster Private E-2

    Whoa. I do not expect I broke some rules here. Sorry for that.

    By the way, let me clear this first before doing the scan:
    1.)I need to scan using CounterSpy or AVG Antispyware? Is this also a Online Scanner? If yes can you give a link?
    2.)Do I need to download the 1.5 version of Spybot and scan again? Same also with BitDefender because of wrong log files?
    3.)Or is it better for me to repeat all the steps from the beginning? If not where I should start? From step bla bla bla?...

    Thank you for the help. I can start the diagnose as soon as you reply.:p
     
    Last edited by a moderator: Oct 22, 2007
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they are not online scanners. They are in the READ & RUN ME and you only need to run one of them. We ask for CounterSpy first and if it cannot be run for any reason we ask that you then run AVG Antispyware in its place.

    For now, just uninstall the 1.4 version and installe the 1.5 version. Make sure you uncheck the option that enable Teatimer during the installation.

    Don't worry about it now. If we run into any problem trying to get things fixed, we may need to re-run it later and get the correct log.


    No you don't need to do that. Just run eiether CounterSpy or AVG Antispyware and attach the log. Then move on to the instructions I gave where you use ComboFix and continue from there.
     
  8. Rayster

    Rayster Private E-2

    Hello again chaslang, I already run my CounterSpy already 2x but I haven't found any Save Log in its interface. And there's no Tutorial for it like AVG-Anti Spyware.:confused

    And can see you what programs I installed in my pc? Can you recommend which one I uninstall? You said that there are 61 programs I installed. Maybe I too much install IE7's add-ons and right now I am using Mozilla Firefox. Should I uninstall all?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions in the READ ME give the below information
    If you still cannot get this log, just move on to the other steps I have given you.

    I'm not saying you should uninstall anything. I'm just saying that installing so much software in such a short time from is not a great idea. When and if you run into problems (like you have now) it will be difficult to determine what may be causing your problems since so much has been changed. In addition, as I already stated, it makes reading your logs extremely difficult because we are looking for new files while searching for possible malware. And since you have so many new files, it is almost very very hard to find any particular malware file when mixed in with thousands of new files.
     
  10. Rayster

    Rayster Private E-2

    I can give you anything like my Program Files so that you can check which one I should uninstall.

    And here's the last batch of my log files. :)
     
    Last edited: Feb 9, 2008
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't need any info on what is in C:\Program Files since it is already in your logs and that is why I mentioned that a lot of stuff was just installed. This forum is only for malware topics. You still have not completed what I requested in message # 5. You need to answer my questions and you need to attach the other requested logs.
     
  12. Rayster

    Rayster Private E-2

    I thought I already post about the HJT, GetRunKey, and ShowNew in my previous post in message #3-4?

    And I already deleted "C:\WINDOWS\system32\TUKernel.exe" the other day when I run the comfix...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was before running the instructions in message # 5. Message # 5 asks for new logs after the instructions have been followed.

    And you still have not answer my questions:

    1) Also tell me what else is in the C:\WINDOWS\system32\Sys32 which is not a normal folder to have and appears to be very questionable.

    2) How are things running?
     
  14. Rayster

    Rayster Private E-2

    Yap I deleted also the files I found in the Sys32 folder, the one you've mention earlier.

    And my system now is ok, it runs like before.

    Is my computer safe now?

    Please summarize what do you still need so that I can post it here. :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you post the follow up logs I have requested multiple times I cannot answer your questions.

    And in addition a question like "is my computer safe now" can never be answered with 100% certainty. If your logs do not show any malware, it really just means that we are not seeing any malware based upon what is in the logs. So when I see your logs I will be able to tell you whether your logs are clean or not. The only real way to know a system is totally clean is to re-partition (without backing up any data since it cannot be trusted to be clean), formatting, and then reinstalling from original CD (not copies) that came from Microsoft and from all of the other companies whose software you use.
     
  16. Rayster

    Rayster Private E-2

    Here are the log files.
     
    Last edited: Feb 9, 2008
  17. Rayster

    Rayster Private E-2

    Here's the last one.
     
    Last edited: Feb 9, 2008
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.

    You should uninstall the Sunbelt CounterSpy trial program now since we are finished with it.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  19. Rayster

    Rayster Private E-2

    I really thought of it cause my system is now running in normal speed unlike the times I haven't scanning for malwares. Thank you very much chaslang. ;)

    I did what you said, deleted all the unnecessary files and now reading the link you gave.

    Again thank you.:major
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds