Infected machine

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jakki2, Aug 23, 2008.

  1. Jakki2

    Jakki2 Private E-2

    This is now another machine which i managed to get infected also.

    Symptoms are the same, no regedit, no taskmgr, cannot install some programs like CCleaner, Spybot etc...

    Machine still working kind a ok but have to get rid of the thingie...

    please help

    logs as follows:
     

    Attached Files:

  2. Jakki2

    Jakki2 Private E-2

    and the last log...
     

    Attached Files:

  3. Jakki2

    Jakki2 Private E-2

    And still some more information if any use.

    I cannot start into safe mode - bluescreen after driver loading.
    Computer won't shut down normally - actually it hangs pretty much everytime with just black screen. it says lot of different programs couldn't shut down for a some reason, progs like WINMINE.EXE, NOTEPAD.EXE NETSH.EXE etc...

    one more annoying thing is that i cannot access any virus scanner sites - they just don't load up :cry - which let's suspect that it is virus ? perhaps ?

    now when i'm checking through process explorer (which i have to unzip everytime as it corrupts in the meanwhile) there is enormous quatity of different progs started under some weird process - just before rebooted there were 8 notepads which cannot be closed.

    this ain't fully anymore...

    please help!

    with respect,
    jake
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It actually sounds like you may have a bunch of problems related to your Window Operating System and not so much that is malware. Even the MGtools programs did not run properly which often is a sign of OS issues.

    It also appears that SUPERAntiSpyware may have removed items for software you use from ARSystem. You should restore those from the Quarantine.


    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now run Ccleaner!

    Now attach the new C:\combofix.txt log.

    Now let's see why MGtools did not work.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  5. Jakki2

    Jakki2 Private E-2

    Chaslang, i appreciate your reply very much and would loved to try all that but there is now few problems ;)
    As it is my work machine i need it like all the time and i cannot try anymore something, so it is underway to have a clean install.
    Secondly i work lots in customer networks and wouldn't want to infect those with this nasty virus or so.
    last one, machine started to BSOD me, couldn't start (at any point) to safe mode and later not even to normal mode... regedit wasn't possible to use because once i fixed it either by hand or by some program - it was "broken" again. same thing with taskmgr... finally i entered in to recovery console so i could save anything that i need - mainly work related (backups should be taken would someone love to say ;) and while checking "listsvc" i recognized few dozens of virus/malware processes/drivers. before it BSOD me for the first time i had the Process Explorer open and i saw like 10 notepad processes open even thou i didn't had any visibly open...

    btw, any clue on what this were/is ? Which one is the best software to see my portable disk ? I need the files from there but don't wan't to infect any machines anymore ?

    BIg thanks for your troubles on this !!!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure that you delete all partitions, recreate partitions, format and then reinstall. If you don't understand this then post in the Software Forum about it.

    What are you referring too? I gave you a fix for malware problems but you are going to reinstall so I'm not sure why you are asking about this.

    Again I'm not sure what exactly you are asking about. If Windows does not see your portable disk, post in the Software or Hardware Forum. Or are you worried about your portable disk being infected? If so, you need to scan it and remove any malware found.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds