MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Closed Thread
 
Thread Tools Display Modes
  #1  
Old 05-06-10, 12:23
moleman1812 moleman1812 is offline
Private E-2
 
Join Date: May 2010
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Bandwith stealing malware

The malware is uploading 4 mbps form my computer making loading web pages a pain and online gaming impossible also there is a fake Windows Security Alert in the tray.
Attached Files
File Type: zip MGlogs.zip (193.2 KB, 3 views)
File Type: txt RootRepeal report.txt (690 Bytes, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 05-06-2010 - 03-24-00.log (2.0 KB, 3 views)
File Type: txt mbam-log-2010-05-02 (21-20-14).txt (1.7 KB, 3 views)
Sponsored links
  #2  
Old 05-06-10, 12:28
moleman1812 moleman1812 is offline
Private E-2
 
Join Date: May 2010
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Bandwith stealing malware

one more log
Attached Files
File Type: txt ComboFix.txt (26.8 KB, 2 views)
  #3  
Old 05-06-10, 23:32
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,786
Thanks: 63
Thanked 7,842 Times in 4,258 Posts
Default Re: Bandwith stealing malware

Welcome to Major Geeks!

Note: Running things like Limewire and uTorrent are also stealing your bandwidth especially if you allow them to run when you are not explicitly using them.

The cleaning procedure took care of most of your problems, but we still have some work to do.

First, your Symantec software which is installed is totally broken and not protecting you. So you have been basically running with no protection. Please run the below then reboot. After reboot run it one more time.

Norton Removal Tool (SymNRT)


Uninstall the below old versions of software:
J2SE Runtime Environment 5.0 Update 3
Java(TM) 6 Update 18
Spybot - Search & Destroy 1.4

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
O3 - Toolbar: (no name) - {90222687-F593-4738-B738-FBEE9C7B26DF} - (no file)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} -

After clicking Fix, exit HJT.


Now we need to use ComboFix to remove a bunch of malware files.
  • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
  • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
  • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
  • Open Notepad and copy/paste the text in the below quote box into it:
Quote:
KILLALL::

Driver::
ccEvtMgr
ccSetMgr
CLTNetCnService
comHost
ISPwdSvc
LiveUpdate
LiveUpdate Notice Ex
SymAppCore

DirLook::
c:\program files\system

File::
c:\windows\Tmiruxekuv.dat
c:\windows\Djevuneburimuq.bin
c:\documents and settings\User\Application Data\jasltw.dat

Folder::
C:\Temp\tn3
C:\WINDOWS\system32\re9

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below
Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.


After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


Then attach the below logs:
  • C:\ComboFix.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
  #4  
Old 05-09-10, 01:10
moleman1812 moleman1812 is offline
Private E-2
 
Join Date: May 2010
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Bandwith stealing malware

here are the logs, the fake windows alert is still there though. What internet projection software would you suggest
Attached Files
File Type: txt ComboFix.txt (24.6 KB, 1 views)
File Type: zip MGlogs.zip (191.7 KB, 1 views)
  #5  
Old 05-10-10, 00:32
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,786
Thanks: 63
Thanked 7,842 Times in 4,258 Posts
Default Re: Bandwith stealing malware

Quote:
Originally Posted by moleman1812 View Post
here are the logs, the fake windows alert is still there though.
Yes I know. We did not fix it yet. We had to fix other things first and needed to get you to run Defogger first too as originally requested in the READ & RUN ME. Locating an infected driver is now what we will be doing next. Locating it will also not fix it. It is just the first step to eventually fixing it.

Quote:
Originally Posted by moleman1812 View Post
What internet projection software would you suggest
We will get to this after we finish your cleanup.


Now please run this Finding TDL with RootRepeal and attach the log from this version of RootRepeal if it runs.


Now run this GMER - running with a random name and attach the log from GMER if it runs.


Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
  • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
  • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
"%userprofile%\Desktop\TDSSKiller.exe" -v
  • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
  • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )



Now we need to use ComboFix
  • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
  • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
  • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
  • Open Notepad and copy/paste the text in the below quote box into it:
Quote:
KILLALL::
File::
c:\program files\system\smss.exe.gpref

Folder::
c:\program files\system
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below
Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.


Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


Then attach the below logs:
  • the RootRepeal and GMER logs if they ran
  • C:\ComboFix.txt
  • C:\MGlogs.zip
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Sponsored links
  #6  
Old 05-10-10, 22:21
moleman1812 moleman1812 is offline
Private E-2
 
Join Date: May 2010
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Bandwith stealing malware

there you are
Attached Files
File Type: zip MGlogs.zip (193.6 KB, 1 views)
File Type: txt TDSSKiller.2.2.8.1_10.05.2010_20.43.17_log.txt (11.6 KB, 2 views)
File Type: txt rootrepeal.txt (560 Bytes, 1 views)
File Type: txt CFlog.txt (24.8 KB, 2 views)
  #7  
Old 05-10-10, 22:22
moleman1812 moleman1812 is offline
Private E-2
 
Join Date: May 2010
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Bandwith stealing malware

one more
Attached Files
File Type: txt gmer.txt (1.6 KB, 2 views)
  #8  
Old 05-12-10, 05:58
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,786
Thanks: 63
Thanked 7,842 Times in 4,258 Posts
Default Re: Bandwith stealing malware

You're logs are clean now. If you are still getting a Windows Security Alert now it is due to the fact that you have no protection installed and this is normal and will remain that way until you properly protect your PC or disable it and the latter is not recommended.

If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
  2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
      • Notes: The space between the combofix" and the /uninstall, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
  3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
  4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
  6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  7. Go to add/remove programs and uninstall HijackThis.
  8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
    related to MGtools and some other items from our cleaning procedures.
  9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning procedures pointed to by step 7 of the READ ME
      for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.
  10. After doing the above, you should work thru the below link:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Someone stealing my wireless bandwith jaruler Hardware 10 10-22-09 15:22
Malware Eating Bandwith BrandNewLP Malware Removal 2 02-14-08 02:54
malware stealing my hardware content biddersspot Malware Removal 6 10-04-07 02:47
Getting More Bandwith? drusmooth Hardware 1 08-25-05 21:53
More Bandwith For My Biz? drusmooth Hardware 3 06-11-05 01:42


All times are GMT -5. The time now is 07:58.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger