Desltop virus plz help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by GoodZwell, Sep 30, 2014.

  1. GoodZwell

    GoodZwell Private First Class

    HI again,

    Ok my son downloaded a tv program viewer trying to watch one of his shows but of course the file and program he installed was nothing of the sort.

    Run through the read and run before posting. Not sure if the problem is fixed but it seems to be working better. Here are the logs. sorry ran Spybot but couldn't seem to find the log file that was save, but I did find the text file when I opened Spybot.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We require logs from:

    • RogueKiller
    • Hitman Pro
    • MGTools
     
  3. GoodZwell

    GoodZwell Private First Class

    Sorry I must have missed those instructions. I'll look again. :*(
     
  4. GoodZwell

    GoodZwell Private First Class

    So I've looked again at the Windows 98 and ME Malware Removal/Cleaning Procedures. On my screen it says only to download and run. "SpyBot - Search & Destroy" and "MGtool9x"

    I've run Spybot and I submitted what I could find.

    MGtool9x is not compatable with Win 98 it's telling me.

    So do I follow those instructions or should I try something else? I'm lost sorry! :(
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Why are you trying to run instructions for Windows 98? You have Windows XP.
     
  6. GoodZwell

    GoodZwell Private First Class

    OMG I'm sooo sorry.. not a good multi tasker. Trying to trouble shoot two machines and I forgot it's running XP not Win98. So stupid, I'm sorry. I'll post something more tomorrow. :-o
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How did you get on? :confused
     
  8. GoodZwell

    GoodZwell Private First Class

    Sorry haven't had time to see if I've gotten rid of the problem yet. I'll try and finish up today! :)
     
  9. GoodZwell

    GoodZwell Private First Class

    Just ran RougeKiller and finished and closed fixing nothing, and there supposed to be a file on the desktop called RKreport[1].txt , but there is nothing on the desktop.

    Firefox pops up to this page when Rouge is finished. http://www.adlice.com/kernelmode-rootkits-part-3-kernel-filters/

    I did find a file"RKreport_SCN_10162014_121927.log" using the "Report" button and saved that to my desktop and will include it in the attachments.

    Now running Malwarebytes.
    No threats detected but including the log.

    Running TDSSKiller
    there is no Zip file to extract. Running now

    Hitman:

    Has found files. Log attached. I didn't see how I was susposed to ignor so I just saved the log to desktop and hit the close button.

    Thanks for your help.
    :)
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [Suspicious.Path] HKEY_USERS\S-1-5-21-1177238915-823518204-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | smoother : C:\Documents and Settings\GoodZ2\Application Data\SmootherWeb\SmootherWeb-Installer.exe -> Found

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    • Re run Hitman and allow it to remove all that it finds.
    • Re run Malware Bytes and attach log.
    • Where is the missing MGlogs.zip?? I need to see that too please, it's most important.
     
  11. GoodZwell

    GoodZwell Private First Class

    Rogue Killer found something else it didn't like but I follow your instructions and left that unchecked.

    Ran Hitman, found a bunch of stuff but when I hit next it redirect me to there page to buy the product. Guess my trial period has expired. So nothing got deleted or quarantined. Also it does not create a log on the desktop. I've had to open the report and then save it to desktop myself.. Hope this is the correct thing to do?

    Running Malwarebytes:
    found nothing attaching log

    MgTools running it. attaching the log this time. Sorry for some reason I miss that step altogether last time.. sorry. My bad.

    Hope I didn't miss anything this time.


    :)
     

    Attached Files:

    Last edited: Oct 17, 2014
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is this what RogueKiller didn't like? Let's fix it please...


    [​IMG] Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:

    • [PUM.Desktop] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore | DisableSR : 1
    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Documents and Settings\GoodZ2\Local Settings\Application Data\globalUpdate
    C:\WINDOWS\system32\MyOSProtect.dll
    C:\Documents and Settings\All Users\Application Data\Systweak
    C:\Documents and Settings\GoodZ2\Application Data\systweak
    C:\Documents and Settings\GoodZ2\Local Settings\Application Data\RocketTab
    C:\Documents and Settings\GoodZ2\Application Data\10019
    C:\Documents and Settings\GoodZ2\Application Data\AFJDR
    C:\Documents and Settings\GoodZ2\Application Data\SmootherWeb
    C:\Documents and Settings\GoodZ2\Application Data\systweak
    C:\Documents and Settings\GoodZ2\Application Data\YXHLC
    C:\Documents and Settings\GoodZ2\Local Settings\Application Data\com
    C:\Documents and Settings\All Users\Application Data\Systweak
    C:\Program Files\globalUpdate
    C:\Program Files\predm
    C:\Program Files\Super Optimizer
    
    :reg   
    [-HKLM\SOFTWARE\Classes\AppID\{BAB04997-93AD-4C13-805A-0409199700BB}]
    [-HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}]
    [-HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}]
    [-HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}]
    [-HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}]
    [-HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}]
    [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467]
    [-HKU\S-1-5-21-1177238915-823518204-682003330-1003\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    • Reboot the machine again. Re run Hitman Pro. Does it still find anything? If so attach log.
    • Re run RogueKiller (just a scan) and attach log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  13. GoodZwell

    GoodZwell Private First Class

    Wow is this a normal or rather bad infection?

    Just ran RougeKiller and finished and deleted what you told me to, and closed , and there supposed to be a file on the desktop called RKreport 2.txt , but there is nothing on the desktop. Rebooted.

    JRT: After running JRT when I went back to your instructions using firefox it seems to work much better but it opened up two other pages on it's own.

    Running OTM now:

    attaching log

    Ran hitman attaching log as it found a tracying file.

    Ran Roguekiller:
    It poped up a similar page as before but this time it said I needed to fix windows. Attaching a jpe and log file. Which is still not saving to desktop. Have to get the log from the reports button still.

    Attaching a couple of Jpeg's , to a second post, not sure they'll help but maybe you could explain to me why they are showing up?



    Thanks for your help.
     

    Attached Files:

  14. GoodZwell

    GoodZwell Private First Class

    second part

    sorry not sure but I might have duplicate a file or two.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    AVG 2012 <<< This is out of date now, surely??

    Do you feel comfortable about going into the Windows Registry yourself and deleteing it?

    HKU\S-1-5-21-1177238915-823518204-682003330-1003\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{AE07101B-46D4-4A98-AF68-0333EA26E113}


    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  16. GoodZwell

    GoodZwell Private First Class

    Yes I can do that but it's been a while since I've done that. Can you provide a little more detail in the process. I think I can just search the above mentioned and find it that way right while in the registry using, "regedit" , then using the search function?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Skip the Registry step, do this instead. ;)

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  18. GoodZwell

    GoodZwell Private First Class

    Ran fixme.reg and it seemed to work fine.

    Running avenger:

    rebooting.


    Thanks for your help.
     
  19. GoodZwell

    GoodZwell Private First Class

    Ran fixme.reg and it seemed to work fine.

    Running avenger: including avenger.txt just in case.

    rebooting.

    Everything work according to your plan. ;)

    Thanks for your help.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's great, much better. How are things running? Ready for final steps? :)
     
  21. GoodZwell

    GoodZwell Private First Class

    Replying from my laptop.

    I'm not sure if everything is working correctly or not but the programs you told me to run did run and seemed to fix what you wanted fixed. So I'll try using the computer tomorrow and see if it redirects me or tells me I need to fix windows or I have a virus that needs to be fixed. lol. Oh one question though. Every time I open fire fox, default is Google, the icon above the search pane usually has a different icon on it every day, well in Explorer at least it does. Will when I open it with Firefox it's a little man with a speech balloon above his head that says "Click Me". Is that normal for Firefox? Never did click on it. I'll take a screen shot of it and post it for you tomorrow.

    Again thanks for all over your time and hard work. You guys are very good at what you do, thank you for that. ;)
     
    Last edited: Oct 19, 2014
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes see how it runs and let me know. I would indeed like a screenshot of what you described. Thanks.

    Also do this in the mean time:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  23. GoodZwell

    GoodZwell Private First Class

    Hi. sorry didn't get a chance to use this computer today but I did run the program and got the screen shot. see attached.

    Thanks for your help. :)
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There's still another log from OTL you need to attach please. ;)
     
  25. GoodZwell

    GoodZwell Private First Class

    Ok.. this is the third time I've tried to upload the file. computer is running really slow at the moment and the internet connection seems to be ify. Might be due to the linksys router 6500 I'm using seems to loose connection now and again. Can't get it to stop that. Any how I've tried to upload the file but majorgeeks upload window keeps telling me I've already uploaded that file. Wierd. So I'm copy and pasting the text instead. Including a screen shot of that problem.

    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    File "C:\Documents and Settings\GoodZ2\Application Data\AFJDR" deleted successfully.
    File "C:\Documents and Settings\GoodZ2\Application Data\YXHLC" deleted successfully.
    File "C:\WINDOWS\Tasks\AFJDR.job" deleted successfully.
    File "C:\WINDOWS\Tasks\YXHLC.job" deleted successfully.
    Folder "C:\Documents and Settings\GoodZ2\Application Data\10019" deleted successfully.
    Folder "C:\Documents and Settings\GoodZ2\Application Data\SmootherWeb" deleted successfully.
    Folder "C:\Program Files\Enigma Software Group" deleted successfully.
    Folder "C:\Documents and Settings\GoodZ2\Local Settings\Application Data\com" deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You attached extra's but not the other one. That's the one I need please! :)
     
  27. GoodZwell

    GoodZwell Private First Class

    I've tried to upload it and it won't upload. Please see the jpeg on the previous post. I Copy and pasted the results from the "Avenger.txt" file also. IT Will not upload.

    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    File "C:\Documents and Settings\GoodZ2\Application Data\AFJDR" deleted successfully.
    File "C:\Documents and Settings\GoodZ2\Application Data\YXHLC" deleted successfully.
    File "C:\WINDOWS\Tasks\AFJDR.job" deleted successfully.
    File "C:\WINDOWS\Tasks\YXHLC.job" deleted successfully.
    Folder "C:\Documents and Settings\GoodZ2\Application Data\10019" deleted successfully.
    Folder "C:\Documents and Settings\GoodZ2\Application Data\SmootherWeb" deleted successfully.
    Folder "C:\Program Files\Enigma Software Group" deleted successfully.
    Folder "C:\Documents and Settings\GoodZ2\Local Settings\Application Data\com" deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, regarding the screenshot you supplied me with... it's normal by the looks. https://support.mozilla.org/en-US/questions/1025706

    Now...you keep attaching an avenger log!! I need a log from OTL please. Not the extras log (you already attached that) I need OTL.txt please.
     
  29. GoodZwell

    GoodZwell Private First Class

    My bad. :-o
     

    Attached Files:

    • OTL.Txt
      File size:
      109.1 KB
      Views:
      2
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing anything else to do but for you to delete these:

    • C:\Documents and Settings\All Users\Application Data\ParetoLogic
    • C:\Documents and Settings\GoodZ2\Application Data\ParetoLogic

    So if you are still having issues please explain.
     
  31. GoodZwell

    GoodZwell Private First Class

    :cool Thanks again for your help.. Haven't had a chance to use this computer but my wife is not complaining about it so I guess it's good. I'll try and use it tomorrow and if I'm not having any problems I won't reply. No news is good news. You are the best and again thanks for making my life happier. Happy wife is a happy life. :) Cheers.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I quite agree... LOL

    Okay, I'm going to post final steps, so you can follow them as soon as possible unless something else is wrong.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
    GoodZwell likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds