malware/virus please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rotika, Jan 28, 2015.

  1. rotika

    rotika Private E-2

    Hi and thanks in advance.

    I am running windows 7, 64 bit. I have completed the read and run and there is something in this computer. I am attaching logs, I cannot find the log from rogue killer log, it doesn't seem to be anywhere.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please then re run RogueKiller again and then attach the new log.

    Re run Hitman Pro and have it remove all that it finds.

    C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} <<< Delete this.


    Could you please get this: aqqmxo.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:



    log retrievable @ C:\collect.zip

    Also re run Hitman again and attach new log. And also attach the collect.zip.
     
  3. rotika

    rotika Private E-2

    Hi,

    I have done all and attached logs for Rogue Killer and Hitman. However, when I try to get 'aqqmxo.sys', command prompt window only flashes on and off, no logs anywhere.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'd like you to delete this file: C:\Windows\SysNative\drivers\aqqmxo.sys

    Question: Are you deliberately set up to use a proxy? Let me know...
     
  5. rotika

    rotika Private E-2

    I cannot find the file ' C:\Windows\SysNative\drivers\aqqmxo.sys ', I went thru all windows files and tried searching, windows just keeps telling me 'no match found' :confused.

    As for proxy, I wasn't aware of it ....
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\Windows\SysNative\drivers\aqqmxo.sys 
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:63181;https=127.0.0.1:63181 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:63181;https=127.0.0.1:63181 -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:63181;https=127.0.0.1:63181 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:63181;https=127.0.0.1:63181 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    • Now re run RogueKiller and attach new log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. rotika

    rotika Private E-2

    Have done as requested, logs attached.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there rotika, how are things currently running for you? :)
     
  9. rotika

    rotika Private E-2

    To be honest, I am not really sure, just got out of work where I've been most of the day/night. I'll check it out and let you know.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, let me know when you can. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds