security system 2012

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tm711, Jun 17, 2011.

  1. tm711

    tm711 Corporal

    On Wednesday night I was surfing the internet and went to a bad link. I got stuck with XP security system 2012. It would not let me run MalwareBytes even after I changed the name. I also could not use the internet because every time only the this security 2012 website would appear.
    I ran ReadMeFirst,with the exception of Mbam. Logs attached.
     

    Attached Files:

  2. tm711

    tm711 Corporal

    root repeal log is too big to upload...........so what do I do?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You could break it up into two text files?

    Reviewing the logs now... :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Java(TM) 6 Update 22 <--- uninstall outdated java.


    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    bfukydcn
    File::
    c:\windows\system32\drivers\ouve.sys
    C:\Documents and Settings\All Users\Application Data\131iwo186jg7g
    C:\Documents and Settings\Caitlin\Local Settings\Application Data\131iwo186jg7g
    C:\Documents and Settings\Caitlin\Templates\131iwo186jg7g
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. tm711

    tm711 Corporal

    I tried to split up the root repeal report. I had to copy it to Word to do it, and even then it was like 120 pages long. I tried to post and still said it was to big. I have done everything else you told me. Logs attached.

    I can now get on the net. Still get an occasional redirect, but none the last 3 times I have logged on (I log on dowload, logoff, run the download as per your instructions, log on again, etc). I will keep logging on/off and see how it goes.
     

    Attached Files:

  6. tm711

    tm711 Corporal

    last of 4 logs.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, the logs look lovely, sqeaky clean, so you have to be sure about those redirects... use the machine a while and report back to me so I can give you final steps if all is well. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds