need help with removing a virus or malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mr.iceman08, Nov 14, 2011.

  1. mr.iceman08

    mr.iceman08 Private E-2

    Hi, The other day I was using Internet Explore because the site I was on wouldn't open with firefox so as I was on it after about 20mins this AVG 2012 popped up saying my computer was infected so I tried (X)ing out of it but couldn't it blocked be from everything so I turned off my computer so I could get to the task manager to kill the program and then delete it. I had believed it was over till I had to restart my computer after Microsoft Security Ess. told me to then some how another virus was found in the computer it was some System recovery at first I thought it was legit until I tried opening my computer and it was missing in the start menu along with every program on my computer not erased but just hidden as well as all files and folders in the computer system so after awhile of virus scans which found a lot of malware and bad stuff I went to go run ComboFix and it started up fine did what it would say on the one website and then when It found something it popped up some message that stated combofix was going to delete it or something I forgot exactly what it said well after clicking the okay my computer was frozen stuck for like 2 hour so I didn't know what to do so I turned the computer off manually and when I did the computer Came back up faster then I did before and then I did the steps again but when I got to the combofix the program froze on the (Scanning for infected files......) and it just stays on that with the little line blinking so I thought It was still working until 2hours later it was still like that so I have to turn the computer off other then that I was able to get the other programs to work so is there something I did wrong? my computer still has a virus because it keeps redirecting my browsers
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still missing your desktop icons and programs in the start menu? If you are, please run this:
    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    Now let's see if we can get Combo to run:
    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    Driver::
    iqjdazrk
    zedwuedk
    File::
    C:\Documents and Settings\All Users\Application Data\2dR85LBoe1wT5F
    C:\Documents and Settings\All Users\Application Data\~2dR85LBoe1wT5F
    C:\Documents and Settings\All Users\Application Data\~2dR85LBoe1wT5Fr
    C:\WINDOWS\system32\drivers\iqjdazrk.sys
    C:\WINDOWS\system32\drivers\zedwuedk.sys
    C:\WINDOWS\Temp\datBE.tmp
    C:\WINDOWS\Temp\datC0.tmp
    C:\WINDOWS\Temp\datC2.tmp
    C:\Documents and Settings\you\Local Settings\Temp\2089881152.dat
    C:\Documents and Settings\you\Local Settings\Temp\215871.mst
    C:\Documents and Settings\you\Local Settings\Temp\446.tmp
    C:\Documents and Settings\you\Local Settings\Temp\7.dir
    C:\Documents and Settings\you\Local Settings\Temp\57.tmp
    C:\Documents and Settings\you\Local Settings\Temp\A94.tmp
    C:\Documents and Settings\you\Local Settings\Temp\A95.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAX12E.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAX130.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAX50.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAX54.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAX94.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAC5.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAC8.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAD4.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAD6.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXADD.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAE4.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAE7.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXAEE.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXD5C.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXD66.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXD6B.tmp
    C:\Documents and Settings\you\Local Settings\Temp\AAXD6D.tmp
    C:\Documents and Settings\you\Local Settings\Temp\D28.tmp
    C:\Documents and Settings\you\Local Settings\Temp\FC4B.tmp
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. mr.iceman08

    mr.iceman08 Private E-2

    Hi, I tried the Grinler I was able to get icon back but some programs in the start>all programs didn't show when hovered over them. and I tried the instruction for the combo fix it didn't do What the diagram did as soon as I dragged the CFScript to the ComboFix icon (both on the desktop) it just launched the Combofix like I had doubled clicked it. I also noticed that when It ask me to update the combofix then when it freeze my computer up and I turn it off when I try it again it says to update again like it forget it updated in the first place or the update is going thru I even tried opening the program in safemode and that didn't even work I re-ran the MGtools I attached it.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then let's use Avenger:

    Download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon [​IMG]
    Extract avenger.exe from the Zip file and save it to your desktop.


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the [​IMG] button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. mr.iceman08

    mr.iceman08 Private E-2

    Here are the logs you requested. I also know that some of my system files the ones that do not have icons likes some MUI or DLL files or set to open with MS Paint I might have changed this when I was trying to stop a Virus could that be the trouble to the ComboFix not working?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a couple of things to clean up. However, you may need to reinstall some programs that may have become corrupted by the infection. You also may need to take you install disc and go to run / and type in:
    sfc /scannow
    to try to replace any corrupted system files. ( You also may want to post in the software forum for additional assistance ).

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\you\Local Settings\Temp\57.dir

    Tell me what other issues you are still having.
     
  7. mr.iceman08

    mr.iceman08 Private E-2

    Okay I did what was instructed for the Hijackthis and I even Restarted my computer but I am still being redirected even after uninstalling Firefox and Internet Explore and when I open the task Manager the Iexplore.exe is open even though I didn't open IE and it use alot of CPU and memory usage. I been using the Super Anti-spyware and I keep getting tracking cookies I delete them and the next time there is more.Also I believe I fixed the problem with the opening with MS paint the files look like there back to default.


    and I would like to thank you so far for all your help
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  9. mr.iceman08

    mr.iceman08 Private E-2

    Hi,

    Sorry for the delayed reply had to take a break due to frustration
    but I went and took my hard drive from the infected computer out and put it into my external hard drive enclosure and hooked it up to another computer and ran the TDSSkiller which it found a rootkit and cured it and I hooked it back up to the computer and was able to open TDSSkiller and comboFix both showed signs of threat the TDSSkiller said to skip so I did and then ran combofix.
    I also did the MBRcheck and the first time it showed a Fake Id and after doing the Combofix and TDSSkiller it came back green which I think is good I will upload both logs along with the TDSSkiller from the other computer which I will rename as TDSSkiller 11_18_2011_1st, and the one I ran on the main computer that was infected will be TDSSkiller 11_18_2011_2nd.
     

    Attached Files:

  10. mr.iceman08

    mr.iceman08 Private E-2

    Here is the Log files from the computer that the infected Hard drive was hooked up to.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to cure or quarantine those Hard disc infections. Re-run TDSSKiller and fix them. Then reattach a new log.
     
  12. mr.iceman08

    mr.iceman08 Private E-2

    Okay I re-ran TDSSkiller but there was no option for cure just Skip, Delete or Copy to quarantine I choose Copy to Quarantine. should I delete them or leave them in Quarantine?
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Leave them in quarantine for now. What malware issues are you still having, if any?
     
  14. mr.iceman08

    mr.iceman08 Private E-2

    Okay I'll keep them there. Knock on wood but I don't believe there any malware issue going on the two Main problems were Firefox and Internet Explore were being redirected and Internet explore Would open in the background opening random things leaving cookies behind and the Iexplore.exe was causing the computer memory to spike up but I haven't seen any redirecting or problem with internet explore. the only problem that I have is when I open the Administrator Tools the folder is empty the files aren't deleted just not in there but that might be because of the virus hiding things from the hard drive.

    I Want to thank you for all your patience and time helping me out!!!:-D!. I thought I would have to deal with the problem until I purchased a new computer
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So things are running well but you are missing all your files in the Admin. panel?

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:



    Tell me if that works.
     
  16. mr.iceman08

    mr.iceman08 Private E-2

    The program did add the icon in the start menu but the shortcuts like services, aren't there. they aren't even in the Control panel>Performance and maintenance> Administrator Tools I was able to put some shortcuts in there from looking at my other computer so It's not a big deal as long as I don't have to deal with the Virus And Malware.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you need any more assistance with restoring your shortcut and icons, please post in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds