Please Help Me out with nasty infection.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tyler_durden81, Jul 10, 2006.

  1. Tyler_durden81

    Tyler_durden81 Private E-2

    I've been trying to remove this thing for the last 10 hrs straight and im at a loss. Im New to hijackthis so whatever help anyone can provide me I would sincerely appreciate. Here's a list of what I've done so far and osme observations:

    I think whatever it is i got is from a file my GF installed that was within a copy of photoshop she got from a friend at college. It was installed2 days ago not long after the chaos insued. The Comp (fast amd comp plenty of Mem and XP serv. 2) started bogging down badly. I tried to run my AV (updated Panda) and it was goign along fine and i looked away and when i looked back i saw 272 infected files( I scan daily and never find anything other than cookies normally).
    I went to see what it was and it froze up, task manager had panda at 99% cpu. Had to end task and retried, it got way past the point it had before having found no viruses this time, then it froze again ( on the Photoshop exe located on my second harddrive with windows). Afterward i began downloading a few programs trying to find out what the problem was and i go a few odd msgs. The msot concerning was a msg coming from winpatrol that popped up every 5 mins telling me windows was trying to change file assosiations of files .JS, .VBS, .VBF, .WSF from windows script to panda antivirus files. Also random freezing and my dial-up connect kept fritzing out. I
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Tyler,


    Work through this guide below, do please make sure you take note of install locations and running instructions, especially for Hijackthis as the install and running instructions are very specific, while these steps look long they are very sucessufull in removing much of the infection on your PC and then from the logs you will have posted, the Malware experts here will be able to mop up the remainder.

    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  3. Tyler_durden81

    Tyler_durden81 Private E-2

    Hi and thanks for the response.

    While my comp was freezing up it caused me to double post. I had followed all the steps in the REATHIS FIRST column however i had pasted the Files in the other thread. I decided Go ahead and redo everything anyway since alot of things didnt work. A little better luck this time. Ill just describe a walkthrough of what i did and the results.

    :All programs settings were modified, where noted, as in the Guidelines, also everything was updated within 24 hrs:



    Entered in Safe Mode:

    1. Ran CCleaner 1.31 on Default settings. Didn't find anything but a couple cookies and temp files.

    2. Ran Microsofts's Malicious program tool and turned up 0 Infected files

    3. Ran Ad-Aware 1.06r1 and found a few MRU file references.

    4. Ran Spybot 1.4 and found 0 Infected files. (also immunized.)

    5. Ran Spydoctor and found nothing.

    6. Ran Microsoft defebder and found 0 infected files.

    7. Ran CwShred and Kill2me with 0 infected results.

    At this point I had to exit Safe mode due to my Dial-up.

    8. I rebooting in normal mode with msconifg set to normal. When i booted up RegMechanic started a scan and I let it go and it came up with 45 "Problems Found". 18 repaired, 27 restricted. when i looked into the file almost all the problems had to do with a string that said "CoolList control Failure to LOAD".

    9. Ran Bitdefender and found 0 infected files. (last few attempts at this It would not update or finish so IM seeing improvement).

    10. tried repeatedly to get Panda activescan to work but would not load up. Just stuck on 0%. I've got all the required software so It wasnt due to flaky intenret not downloading the active X. Still, couldnt get it to run so i do not have a Log for activescan.

    11. Ran Highjackthis.


    Everythings running a bit more smoothly. not getting all the error messages from wincontrol saying that file associations are going haywire. Internet is acting normal. But i still have some programs that arent detecting my firewall.

    thanks for the Reply, and hopefully you can see something in here thats causing my problems form earlier. "the main thing worrying me is how the virus was chaning my antivirus values, and lowering all my setting if not outrights disabling Panda every 5 minutes and shutting down the Firewall". Hopefully U can make something out of these logs and help me pick it out. I know the scans arent picking anything up anymore, but i never found an actual virus, just spyware, and i dont see that doing all the damage i had earlier. Anyway, Thanks in advance for taking a look.
     

    Attached Files:

  4. Tyler_durden81

    Tyler_durden81 Private E-2

    I got a reply to a new double post saying to upload logs. I have them here still. so im pushing this to top so someoen can find it. Still havent restated my computer. As in reply to the msg form the other thread Panda activescan still will not initaite, Hence no log. Thanks in advance
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually all you did was delay yourself from getting an answer by about a day. When you bump you go to the beginning of the forums new posts which is the opposite order in which we answer. Threads are answered from oldest to newest. So all you did was lose your place in the queue.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're first big problem is not malware. It is due to the fact that you never properly uninstall McAfee (see step 3 of the READ ME) before you install Panda on your system. This alone can screw up the ability of Security Center to work properly and it may never work properly afterwards. Sort of a Windows flaw! They never expected anyone to have multiple antivirus/security centers installed at the same time.

    You have all the below items related to McAfee (one is not McAfee - but we need to fix it):
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/redirects/support.asp?affid=370-9
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    Look in Add/Remove Programs and uninstall ALL McAfee software. It you do not find it installed, use HijackThis to fix all of the above lines. And then reboot your PC and after reboot delete the C:\Program Files\mcafee.com folder if it exists.

    Now are you having any malware problems. If so, itemize the actual malware problems you are having.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds