![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello, a few days ago Trend Micro detected a virus located in C:\windows\assembly\GAC_32\Desktop.ini
I have tried so many things, but I can not remove it in any way, it redirects my web pages and causes my computer to freeze. I tried reading other threads about this problem and I read about ComboFix, but I am not an expert and I don't want to do more damage by running it, can someone please help me? |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
Now do not stop, please continue on with the below instructions too! ![]() v V V V READ & RUN ME FIRST. Malware Removal Guide
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Here are the report and the log.
|
|
#4
|
||||
|
||||
|
Did you miss this???
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
No, but it took me ages to follow all the steps because my computer keeps freezing. I did everything, but ComboFix only does the extraction and does not run and RootRepeal says "Error - RootRepeal does not support 64-bit OSs!"
Also Trend Micro stopped working, it says "starting your protection", but it doesn't start even if I wait for a long time. |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
Download OTL to your desktop.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Attach both of these logs into your next reply.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
nwktst it said "the ordinal 1108 could not be located in the dynamic link library WSOCK32.dll"
I didn't get any error messages when i entered the other commands. OTL only gave me OTL.Txt, I'm attachihng it here. |
|
#8
|
||||
|
||||
|
Quote:
Please uninstall anything relating to Searchqu Toolbar, Paretologic and Bandoo Media if they show. Please try renaming combofix.exe to b7ytDF.com and boot into safe mode to see if it will run at all. We need to run an OTL Fix
Code:
:otl
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=164&systemid=406&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
C:\windows\assembly\GAC_32\Desktop.ini
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=164&systemid=406&sr=0&q={searchTerms}
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll ()
C:\PROGRA~2\WI3C8A~1\Datamngr
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll) - C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll (Bandoo Media, inc)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll) - C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll) - C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll) - C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll (Bandoo Media, inc)
[2012/06/07 18:00:00 | 000,000,424 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Anti-Virus PLUS_dbsummary.job
[2012/06/04 23:01:48 | 000,000,448 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Anti-Virus PLUS.job
[2012/06/11 16:05:36 | 000,076,800 | ---- | C] () -- C:\Windows\Installer\{13851150-6554-632f-43c3-3e704e0e6a72}
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:4CF61E54
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:05EE1EEF
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:2F370DA6
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:115CEE00
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A724744F
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:AB689DEA
:commands
[EMPTYTEMP]
[RESETHOSTS]
[REBOOT]
For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options. To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
Quote:
Now run OTL again like you did in my post # 6. Attach the log. Also now see if you can run MGTools.exe again and see if it will produce a complete MGlogs.zip. Let me know about Combofix too please.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#9
|
|||
|
|||
|
No, it did not produce a new MGlogs.zip.
I renamend combofix, but it did only the extraction, even in safe mode. Here are the OLT report, the FRST log, the OLT log and the MGlogs.zip, MGtools showed me an error message "the ordinal 1108 could not be located in the dynamic link library WSOCK32.dll", but it finished the scan. |
|
#10
|
||||
|
||||
|
I'll try to keep you moving along while Kestrel13! is not around.
![]() Download this >> fixlist.txt Save fixlist.txt to your flash drive.
Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (See how to attach) Now boot into normal Windows can continue with the below. Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Now attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Here are the files, it's not working properly, trend micro disappeared (?), my desktop is messed up and sometimes it says I can't access my profile when i boot.
|
|
#12
|
||||
|
||||
|
Hopefully you will be able to get through the below. The issues you are having is due to the damage the malware has caused no doubt.
Uninstall the below if you can.
Reboot your machine and install the most current and up to date version of Java available here at the below link: Java Runtime 6 Now Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Run FRST again like you did in my post #8. Attach the log from doing so. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” Last edited by Kestrel13!; 06-13-12 at 17:53.. Reason: edited post to remove 90% of my fix. |
|
#13
|
||||
|
||||
|
Note that none of the below are problems and do not need to be fix. INeedHelp. has this software installed.
Quote:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local> O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#14
|
||||
|
||||
|
@Chas. Sorry. I was under the impression that searchautocomplete.com was a dodgy website, and also that datamngr.dll related to searchqu stuff as I swore I saw that in one of the logs.
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” Last edited by Kestrel13!; 06-13-12 at 18:01.. |
|
#15
|
||||
|
||||
|
Please explain what you mean.
It was not installed when you posted your first logs. You will have to install it if you use it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Just FYI that proxy is part of the Akamai software that is installed.
![]() |
|
#17
|
||||
|
||||
|
I'm just going to check new FRST log and new MGlogs.zip if that's okay with everyone.
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#18
|
||||
|
||||
|
Quote:
![]()
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#19
|
|||
|
|||
|
Chaslang i'll try to install trend micro again, but I do get an icon saying "starting your protection" and the control panel shows that it's installed...
Kestrel13! I attached the logs. It looks like it's working ok now. It does not freeze and I don't have any problems accessing my pprofile when I boot. Silly question (probably) ^^' "The 'Java8tm) Plug-In SSV Helper' add-on from 'Sun Microsystems, Inc.' is ready for use." Should I enable it? |
|
#20
|
||||
|
||||
|
Hi there.
Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue. After clicking Fix exit HJT. Please note, the 020 line relates to imesh, which is not installed on your computer right now. Was it something you once had installed knowingly? Please download Combofix as per the instructions in the Read and Run Me First procedures, to your desktop. Now we need to use ComboFix by sUBs
Code:
KILLALL::
File::
c:\progra~2\wi3c8a~1\datamngr\datamngr.dll
Folder::
c:\progra~2\wi3c8a~1
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Please note, the use of keygens, torrents, and "cracks" is an open doorway for malware to come straight through...
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
INeedHelp. (06-16-12) | ||
| Sponsored links |
|
|
![]() |
| Tags |
| combofix, desktop.ini |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Saving ComboFix to Desktop? | ldmetott | Malware Removal | 2 | 03-20-10 06:44 |
| Combofix Deleted all Personal Files - docs, pics, music, desktop, etc | TechGuy | Malware Removal | 10 | 02-18-10 15:40 |
| Combofix - Deleted Desktop, docs, programs etc | stevep119 | Malware Removal | 25 | 01-28-10 23:15 |
| combofix and desktop image issues | brucebb | Malware Removal | 7 | 09-06-08 16:15 |
| desktop time military after combofix anything else?? | therealstarlette | Software | 1 | 05-27-08 20:24 |