![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
All right so another of my computers is infected.
I saw that Personal AV somehow made it on there even though I havent used the computer in months. So I deleted the folder in the Program Files. Also in there is a folder called sFX which I cannot delete However there is still a problem. Firefox does not work as it gives me the timed out message. When it does work, all search engines do not work. Although I can go to the sites such as google.com or yahoo.com, search results do not show up. Also, when I try to doubleclick on the usb drive, it brings up Notepad and gives me an error with Catalyst Control Centre. Another error is with Generic Host Process for Win32 Services. Did everything in the read and run me first except step 6 This is because even after installing these programs they will not run. Superantispyware just wont install, giving me an error Any ideas? |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
btw here are the MGlogs which I forgotten to attach
|
|
#3
|
|||
|
|||
|
new MGlogs
|
|
#4
|
||||
|
||||
|
What is the below huge file? If unknown, you should delete it.
Code:
C:\Documents and Settings\Hiep\My Documents\ nf1258.exe Jun 18 2009 449548956 "NF1258.exe" Now you need to edit your C:\Windows\win.ini file and delete the below line at the end of the file. DLL_PATH=C:\Program Files\DoubleD\GamingHarbor Toolbar\4.1.3.20290 Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: Media Access Startup - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Media Access Startup\1.5.0.850\HPIEAddOn.dll O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\3.4.0.4340\NPIEAddOn.dll (file missing) O2 - BHO: System Search Dispatcher - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\Program Files\System Search Dispatcher\1.3.0.840\ssd.dll (file missing) O3 - Toolbar: GamingHarbor Toolbar - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - C:\Program Files\DoubleD\GamingHarbor Toolbar\4.1.3.20290\stb0.dll (file missing) O4 - HKLM\..\Run: [PersonalAV] C:\Program Files\PersonalAV\pav.exe O4 - HKLM\..\Run: [MSDRV] NetFilter.exe O4 - HKLM\..\Run: [pp] C:\windows\pp11.exe After clicking Fix, exit HJT. Now download The Avenger by Swandog46, and save it to your Desktop.
Quote:
Now see if you can run SUPERAntiSpyware, Malwarebytes, ComboFix, and RootRepeal. Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#5
|
|||
|
|||
|
Well I did everything you said but theyre still not working. Firefox is also opening another tab that looks like an ad everything I start it.
I did however get RootRepeal to work after a number of errors saying it could not read the boot sector. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Okay the infection may have corrupted some of your downloads and installations. So we will uninstall a few things and delete some previous downloads. Then we will get new copies and install them after a reboot. Follow the steps below in the exact order written.
Uninstall SUPERAntiSpyware and Malwarebytes now.
Quote:
Now download and install and update the below tools again:Now try to run SUPERAntiSpyware, Malwarebytes and ComboFix per the cleaning instructions. Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#7
|
|||
|
|||
|
Well I've run into a problem, that is I cannot uninstall Malwarebytes either by using the add/remove programs or by trying to delete the folder in Program Files.
Should I use Spybot's File Shredder to try to delete them (not sure if it will works) or no? And since SUPERAntiSpyware wasnt ever installed in the first place thats done I did the next step but I still cant run the programs besides CCleaner although it always shows up with 24KB in IE Temp Internet Files even after a few runs. Although, this computer has two accounts. Would that be a problem |
|
#8
|
|||
|
|||
|
I tried again and managed to uninstall Malwarebytes after trying again. Ran through the steps again and CCleaner had 0 bytes removed instead of the 24KB before I uninstalled Malwarebytes.
Still cant install those programs, Malwarebytes included. Should I uninstall Spybot as well? There is still the ad site that pops up along with the FirefoxStart homepage everytime I open Firefox or click home |
|
#9
|
||||
|
||||
|
First please run this: Resetting Registry and File Permissions
Then continue with the below.
Quote:
Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms. Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
Well I did everything. Still having the same problems though, cant install anything.
The malwarebytes installer runs but stops at the end of the percentage bar so I dont think it actually installed |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
Also what happens if you boot in safe mode and use the Administrator user account?
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
Same thing. Nothing works in either account in regular mode or safe mode.
I also cant get into the Administrator account in safe mode since I forgot the password to that. Also google searches are now being redirected while an ad showing a fake virus scan showed up once Gah is there anything I can do now? |
|
#13
|
||||
|
||||
|
First please run this: Resetting Registry and File Permissions
Now try installing the below ExploreXP program and tell me what exactly happens? ExplorerXP Please run this Win32KDiag - How to run and attach the requested log. Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Now attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#14
|
|||
|
|||
|
All right I did everything.
Installing ExplorerXP went fine, no problem in installing and it runs too However, the Win32KDiag didnt seem to work |
|
#15
|
||||
|
||||
|
So it looks like you can install programs. You just cannot install certain programs. Can you install and run the below?
Avira AntiRootkit Protection Also please try running the below online scan: http://www.superantispyware.com/onlinescan.html Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log. Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Well I cant install that first one. Gives me an error about the application configuration is incorrect
The second link worked liked a charm though. It managed to work and found plenty of stuff. After using that everything seems too work including malwarebytes, spybot and combofix. I reinstalled malwarebytes and it seems to work. Only did the quick scan and the logs are attached. Will run through the entire cleaning procedures tomorrow and attach logs (I hope this is the correct decision) Hopefully I'll be able to get rid of the ads that popup along with firefox homepage every time I open firefox |
|
#17
|
||||
|
||||
|
Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 09-18-09 at 01:01.. |
|
#18
|
|||
|
|||
|
Still getting that popup everytime I open firefox
Doing the steps and will post later |
|
#19
|
|||
|
|||
|
And here are the logs from the cleaning procedures.
Nothing found! And I fixed the popup by changing my homepage. Guess I'm in the clear? |
|
#20
|
||||
|
||||
|
That was going to be my next suggestion since your combofix log showed you had the below in your home page setting:
hxxp://www.theprizeday.com/today.php Since your logs are clean, and if you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Cannot open any antivirus websites or update Antivirus softwares | desai_amogh | Malware Removal | 1 | 04-16-09 16:39 |
| Programs wont open | ttocca | Software | 11 | 03-18-09 12:31 |
| I can't open programs or antivirus websites.... | waveball | Malware Removal | 9 | 01-22-09 21:47 |
| This virus wont let me open any programs | dysidous | Malware Removal | 2 | 08-02-08 20:06 |
| Windows XP "all programs" wont open | splitt3r | Software | 5 | 02-06-07 14:42 |