Need argunt Help!! been Infected!! oppqo.dll etc.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Silent_Killer, Jan 1, 2008.

  1. Silent_Killer

    Silent_Killer Private E-2

    Hi,

    Am hoping someone can help me on here as I've been infected with some infections I cant even find on google.

    The last 4-5 days weird stuff has started happening. firefox stops working after a while and will not load up, win patrol keeps detecting oppqo.dll* wanting to start on startup, it was some different .dll then that yesterday, something else keeps coming up at start up which has started today, it says could not load KHFCD.exe, and unless I click ok most of my windows services / processes won't load, so I click ok for my windows services / processes to load at startup and after it says error loading KHFCD.exe in registry access is denied, however, windows loads up fine.

    I have run scans with AVG, Spyware doctor, ccleaner and windows defender and cleaned out a few infections, but most keep coming back after rebooting. my pc starts to run a little sluggish after a while too, not too bad but not normal at all, am running Windows Vista Premium with a pretty decent system spec.

    I've been thinking of doing a format but I would rather clean out my infections as I have allot of files I want to back up which might be infected.

    What do I need to do for someone to help me? show some logs / scans etc? am pretty stuck tbh, all I know what to do is do the regular scans with software.

    Regards
     
  2. abri

    abri MajorGeek

    Hi Silent_Killer!
    Happy New Year and Welcome to Major Geeks!


    Your symptoms sound familiar. If you would like us to help you, please go through the instructions in the READ & RUN ME FIRST and note those which apply to your operating system. You can reformat, but after the reformat, chances are equally good you will stumble upon the same infection again. If your symptoms are severe, scroll down to the bottom of the first page, find the link for your operating system and on the second page begin with Combofix. If you don't have a working browser, you will have to download the various tools onto a second computer and transfer them with a cd or flash drive. A read only cd would be the better choice. Whether you begin with Combofix or begin at the very beginning, you need to do ALL the instructions and post the requested logs to us so we have something to work with.

    abri
     
  3. Silent_Killer

    Silent_Killer Private E-2

    Thanks for the quick reply, am just doing some more scans and getting some logs now, the oppqo.dll has changed to hggdd.dll after I just done a reboot, this is strange :major
     
  4. abri

    abri MajorGeek

    Try to avoid reboots as much as possible right now.
    abri
     
  5. Silent_Killer

    Silent_Killer Private E-2

    I did some scans but I cant find the logs, I've looked where the vista cleaning procedure says but the logs aren't there and I cant find any logs anywhere?, I've tried running combofix but it closes its self without me touching the mouse or anything :( I've tried everything thing in the vista cleaning procedure expect Toggle System Restore.

    I don't know how useful these screen shots will be:

    Spybot:
    http://img231.imageshack.us/img231/9730/46410590xy8.jpg

    AVG anti-spyware:
    http://img404.imageshack.us/img404/7228/72227458jh0.jpg


    Spywaredoctor:
    http://img150.imageshack.us/img150/2863/22770068dc7.jpg
     
  6. Silent_Killer

    Silent_Killer Private E-2

    Sorry I forgot I ran that MG ok?, file is attached.

    Edit:

    Proper zip attached now.
     

    Attached Files:

  7. abri

    abri MajorGeek

    Hi Silent_Killer!
    Nice screen shots!

    The MGlogs.zip is missing almost everything I need. Before you begin, please make sure that msconfig is set to normal system start. You can check this by going to Start / Run and typing in msconfig. See that the normal system start box is checked.

    From your hijackthis, I can see there is plenty to fix, but in order to proceed with any degree of success, we like to get all the files at once so they can't mutate. Please go to the READ & RUN ME FIRST
    instructions and scroll down to the bottom of the page and make sure to choose those which apply to Vista. (If you did this already, please repeat this installation and allow it to install over the old one.) There are extra steps in the Vista version which run automatically which turn off your UAC and then turn it back on. I'm not sure why your zip file doesn't have the scans we need, but I'm hoping that by reinstalling the MGTool.exe, that it will create them all this time.

    The MGlogs.zip are located directly under C:\ (or whichever drive your operating system is in). I'm sorry for the delay, but I can see which bad files you have and I need the complete information on them in order to get them out of your computer.

    abri
     
  8. Silent_Killer

    Silent_Killer Private E-2

    Hey,

    I have set msconfig to normal, I guess I need to reboot now then? you said avoid rebooting, am hoping I don't have any problems when I do that now.
     
  9. Silent_Killer

    Silent_Killer Private E-2

    Ran MG again after setting msconfig to normal etc, dunno if theres files missing in the log still or not.

    Regards
     

    Attached Files:

  10. abri

    abri MajorGeek

    No. It'll be fine.
     
  11. Silent_Killer

    Silent_Killer Private E-2

    Hehe, posted at the same time, I've attached the new mg log in my post just before yours, I've done everything in the Vista cleaning guide expect the combofix and being getting the logs, I don't know if the right files are in the mg log now?
     
  12. abri

    abri MajorGeek

    That one didn't turn out right either, so it's time to hurry up and wait. I've asked the Man to look at it when he comes in. I know Vista's different, but you shouldn't be missing logs.

    abri
     
  13. Silent_Killer

    Silent_Killer Private E-2

    Ok, will hold on and wait for your guy mate, thanks allot for your time & help :major
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what I see in MGlogs.zip from message # 6, you are creating the ZIP file yourself. I say this because history.txt is in the ZIP file and that is not one of the logs that the program would put into the ZIP file. The only way it would be there is if you put it there. Is that what you are doing? If so you should not be.

    Then in message # 9 only GetUnKey.txt and runkeys.txt are in the ZIP file but hijackthis.log is clearly in the C:\MGtools folder and should therefore be in the ZIP file especially since it was there the first time. Again unless you are the one creating the ZIP file.

    Look in the C:\ folder. Do you have all of the below showing?
    Code:
    C:\MGtools         <--- the folder for all of the MGtools programs
    C:\MGtools.exe   <--- the installation file
    C:\MGlogs.zip     <--- the automatically built ZIP file containing logs

    If the C:\MGlogs.zip file is really the ZIP file you have been attaching, then I have to ask a few questions:
    • did you disable UAC and also try Run As Administrator
    • the second time you got your log did you rerun MGtools.exe or did you just double click on C:\MGtools\GetLogs.bat (running GetLogs.bat is the correct way to get all of the logs and you must make sure you wait for it to finish running. See the snapshot on the Using MGtools download page).
    • try running just C:\MGtools\ShowNew.bat by double clicking on it. What happens? Do you see any error messages? If so what are they?
     
  15. Silent_Killer

    Silent_Killer Private E-2


    I used the zip that was automatically made by MG in C:\ In post 6 I just added the extra text files from the MGTools folder as I thought you might need them, but the attached zip in post 9 is just the automatically zipped files MGTools made, thats the only log files MG created in there.


    Yes I did.

    I ran C:\MGtools.exe as thats what it told me to run in the Vista Cleaning Guide, it never told me to run GetLogs.bat, thats why its not making all the logs for me :wave , I have attached the proper logs (hopefully)

    I first ran it as normal and it said access denied, file not found and opened up this text file:

    ******************************************************************************
    * ShowNew.Bat - (c) 07/01/2006 By Chaslang *
    * This version supports Win2K, XP and Vista *
    * *
    * 12/16/2007 Version 2.09 Use Swwhoami to get more env info *
    ******************************************************************************
    * Most of the information reported below is not necessarily bad. You must *
    * not take any steps on any of these lines without consulting an expert. *
    ******************************************************************************

    Windows OS is

    Microsoft Windows [Version 6.0.6000]
    It's Wed January 2, 2008 12:40:04 AM

    ******************************************************************************
    ShowNew installation folder and files

    "C:\MGtools\"
    analyse.exe 13 Jul 2007 401720 "analyse.exe"
    chodefix.bat 7 Jun 2007 6146 "chodefix.bat"
    config.reg 12 Dec 2007 1552 "config.reg"
    disabl~1.reg 2 Aug 2007 120 "DisableUAC.reg"
    enable~1.reg 2 Aug 2007 120 "EnableUAC.reg"
    fixchode.reg 7 Jun 2007 738 "fixChode.reg"
    getdet~1.exe 30 Oct 2006 245760 "GetDetails.exe"
    getlogs.bat 15 Dec 2007 2950 "GetLogs.Bat"
    getrun~1.bat 31 Dec 2007 92680 "GetRunKey.bat"
    getunkey.txt 2 Jan 2008 168832 "GetUnKey.txt"
    getunk~1.bat 15 Dec 2007 1911 "GetUnKeys.bat"
    grep.exe 14 Apr 2003 80412 "grep.exe"
    hide.reg 26 Jul 2007 213 "hide.reg"
    hijack~1.log 2 Jan 2008 12668 "hijackthis.log"
    history.txt 31 Dec 2007 5777 "history.txt"
    iefix.reg 3 Apr 2004 1756 "IEFIX.reg"
    locate.com 14 Jan 2005 11254 "locate.com"
    ltime.exe 28 Oct 1986 13184 "ltime.exe"
    newfiles.txt 2 Jan 2008 942 "newfiles.txt"
    procdll.txt 2 Jan 2008 64107 "procdll.txt"
    proces~1.exe 1 Aug 2006 6656 "ProcessDll.exe"
    regfix.bat 18 Apr 2007 145 "Regfix.bat"
    runkeys.txt 1 Jan 2008 37415 "runkeys.txt"
    shownew.bat 17 Dec 2007 40888 "ShowNew.bat"
    swreg.exe 16 Dec 2007 156160 "swreg.exe"
    swwhoami.exe 16 Dec 2007 66048 "swwhoami.exe"
    TEMP 1 Jan 2008 "temp"
    unhide.reg 3 Aug 2007 213 "unhide.reg"
    vfind.exe 28 Dec 2007 49152 "vfind.exe"
    vunfind.bat 28 Dec 2007 861 "VunFind.bat"
    zia07964 2 Jan 2008 20128 "zia07964"
    zip.exe 14 Jan 2005 126976 "zip.exe"

    "C:\MGtools\temp\"
    junk.txt 2 Jan 2008 38 "junk.txt"

    33 items found: 32 files, 1 directory.
    Total of file sizes: 1,617,522 bytes 1.54 M
    3 Dir(s) 16,803,745,792 bytes free

    Edit by chaslang: Deleted most of inline log to speed up loading & refresh time for thread.


    I then ran it as administrator and it came up with this:

    http://img210.imageshack.us/img210/7080/13304585sk1.jpg




    Thanks & Regards
     

    Attached Files:

    Last edited by a moderator: Jan 2, 2008
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post logs inline like that! They are not properly formatted and as such are too hard to read. Also they clutter up the thread and make it take longer to load. You should have just attached the C:\MGtools\newfiles.txt log that was created. Please run C:\MGtools\ShowNew.bat again and then attach the C:\MGtools\newfiles.txt log that is created. Please do that now and then continue.

    I also noted something strange. Who is putting all of the ZIP files in the below folder:
    Who is creating these? Have you been doing this? The program will not do this.

    However please attach this one: MGlogs-3.zip

    Then delete all files in the below folder. Note Windows will stop you from deleting a couple from the current day. Malware could stop from deleting some of the others. Just delete what you can but don't just try selecting all at once since that will result in most of them not being deleted.
    C:\Users\roy\AppData\Local\Temp
     
  17. Silent_Killer

    Silent_Killer Private E-2

    Sorry for posting the log on here, am new here so I thought it should be ok. Yes I created them MJ zips, I was trying to figure out why it was not getting all the logs but it was because I was pressing the mjtools.exe as explained in the vista cleaning guide on here, not getlogs.bat, I will have to create the logs again as I would of deleted all the other zips as they where wrong, expect the latest one I posted, all this stuff is new to me :wave

    Thanks & Regards
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I''m not sure why the program is not able to put all of the logs into the ZIP file. The last MGlogs.zip file you attach still only has one of the 5 logs in it. Please download the newest version of MGtools.exe just uploaded last night. Get it from here: MGtools.exe Make sure you save it to C:\MGtools.exe.

    Now make sure that UAC is already disabled. Based on one of your previous logs UAC was not disabled. You can do this from MSconfig or you can double click on C:\MGtools\disableUAC.reg and allow it to be added to the registry.

    Then run MGtools.exe by double clicking on the MGtools.exe file. Note: Do not use Run As Administrator when running MGtools.exe.

    Watch the messages occurring in the command prompt window. Let me know of any error messages that you receive. Make sure that you do not interrupt the procedure from running until it is complete. Click on the below which shows you what the command prompt window will look like when the process has finished running.

    http://forums.majorgeeks.com/attachment.php?attachmentid=78790&thumb=1&d=1198613293


    Attach the new C:\MGlogs.zip file. If this does not contain all 5 of the individual log files (you can check it for yourself) then please attach each of the below log files separately:

    C:\MGtools\GetUnKey.txt
    C:\MGtools\hijackthis.log
    C:\MGtools\newfiles.txt
    C:\MGtools\runkeys.txt
    C:\MGtools\procdll.txt

    Those are the 5 logs that should be in MGlogs.zip. It really looks like there is something setup wrong in your environment that is making your PC believe that the C:\Users\roy\AppData\Local\Temp folder is what should really be C:\ The reason I say this is because ComboFix.txt is in your Temp folder and it should also be in C:\


    Now let's also try to fix some problems. First a couple of questions. What is the below process I see loading at startup?
    "EncAmok"="\"C:\\ProgramData\\Math error error.xy58py\""

    Is your copy of Spyware Doctor a paid version or free trial? If free, uninstall it now.

    Also uninstall WinPatrol and AVG Antispyware otherwise they could block the fixes. Do this now.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\roy\AppData\Local\Temp\khfcd.dll,c
    O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\roy\AppData\Local\Temp\hggdd.dll,#1

    After clicking Fix, exit HJT.


    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have the below icons on your Desktop (double click the thumbnail to expand it)
    CFScript.jpg
    • Now refer to the above image and use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\roy\AppData\Local\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.

    Make sure you tell me how things are working now!
     
    Last edited: Jan 2, 2008
  19. Silent_Killer

    Silent_Killer Private E-2

    Ok, I downloaded MGtools again and put the .exe in C:/ again, disabled UAC, ran MGtools as normal (not as administrator) that went ok without errors, but when I ran GetLogs.bat as normal it says:

    "zip error: Could not create output file <C:/MGlogs.zip>

    All finished getting getting Uninstall list. The log is in C:\MGtools\GetUnKey.txt"

    It also comes up with this:

    http://img142.imageshack.us/img142/4494/89777777777777777777777et0.jpg


    So I ran GetLogs.bat as administrator, I don't know if any of these are errors at the start:

    http://img176.imageshack.us/img176/5293/89777777777777777777777wf8.jpg


    I don't have a clue mate.



    The zip that MGTools is making still does not include the 5 log files but I think I have attached all the files for you, I am in the process of doing the next steps you have explained, I will report back when I have done so, I just have to nip out for a little while.
     

    Attached Files:

  20. Silent_Killer

    Silent_Killer Private E-2

    I've had to make a new post as I cant upload more then 3 files and you said to post them separately , hope this is ok.

    Edit:
    I cant find runkeys.txt.

    I don't have a clue mate.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then just run GetRunKey.bat and it should create a log.


    Okay we will have to added it to the things to fix.

    What about your copy of Spyware Doctor? Paid or Trial?
     
  22. Silent_Killer

    Silent_Killer Private E-2

    I did a reboot (been avoiding it as I was advised) and MJtools is working fine now, I have attached the automatic zip it created with all the logs :cool


    It came with Vista, its not a 30 day trial etc because its been running for a few months now, it could be a light version? is there a free light version? or maybe I have a paid for light version?

    I cant find 2 of them and theres some extra ones you should maybe look at before I go and fix:

    http://img184.imageshack.us/img184/9949/34644646464nb7.jpg

    direct link:
    http://img184.imageshack.us/img184/9949/34644646464nb7.jpg
     
    Last edited by a moderator: Jan 2, 2008
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to attach snapshots of HijackThis. The complete log is in MGlogs.zip.;)

    Yes you can fix the Itch ford four knob line and the EncAmok that I asked about.

    Also you can fix the one that says MSServer. It renamed the DLL file to pmkkj.dll. I'll add this to the ComboFix fix so make sure you check out the fix again.
     
  24. Silent_Killer

    Silent_Killer Private E-2

    I ran combofix the exact way you explained earlier with the text etc, but while it was scanning it just closed its self, I didn't touch nothing, my Internet stopped working too, I had to do a reboot to get it to work again because windows could not diagnose the problem, does it normally just close like that without saying its finished scanning or something? or did it still complete the scan, theres no log file been created, and why did my Internet stop working when running it? also, AVG is still popping up sometimes with .dll threats found.

    Edit:

    Forgot to tell you, after running hijackthis a couple of .dll are not loading up at start up now.

    Regards
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this is not the way it should work. Either your protection software or the malware is interferring with it. If a log was not created, it probably did not work properly. Attach a new MGlogs.zip file so we can determine your current status.
     
  26. Silent_Killer

    Silent_Killer Private E-2

    Attached.
     

    Attached Files:

  27. Silent_Killer

    Silent_Killer Private E-2

    Update:

    I opened msconfig just to have a look and avg detected a trojan called "dropper.agent.git" , avg then kept coming up with "trojan found dropper.agent.git" location program files, and found it in about 10 or so of my programs in program files, I healed them, I don't know if this was the right thing to do or not.

    I did a reboot as I updated some stuff, on startup I got the file missing error again which first came up a few days ago (mentioned it in my first post), , I had to press ok for most of the windows services to load: (it hasn't loaded up for about a day)

    http://img2.freeimagehosting.net/uploads/0b8fc62688.jpg

    AVG would not load after that, so I unplugged my Internet cable straight away and repaired the AVG installation and did another reboot. on start up I got this error:

    http://img2.freeimagehosting.net/uploads/a6da541007.jpg

    I pressed ok, AVG would not load again, but It ran when running it from program files.

    I've also come across something else which I didn't manage to get a screen shot off. sometimes in firefox when I go to save or uload a file a error comes up and then disappears and freezes firefox, I've also tried running combo fix again without success.

    I've attached a new MJTools log.

    edit:

    I've attached them 2 screenshots as the Image host site seems to be down
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I already know all of this. This is the malware that we are trying to clean and we MUST get the ComboFix procedure to work in order to fix it. You must avoid doing anything that we do not ask you to do. Running ANYTHING makes it susceptible to getting infected. Downloading anything can result in the download being infected. Installing anything (unless we ask you to) could result in infection. Even your antivirus and antispyware programs are currently infected.

    Let's start by uninstalling all of the below which will help us contain the infection since these items will not be running anymore. Uninstall the below:
    • AVG7 Free Antivirus
    • Java(TM) SE Runtime Environment 6
    • Spyware Doctor
    Then delete the C:\Program Files folders you see for AVG and for Spyware Doctor.

    After uninstalling the above reboot your PC and then do the below.



    Now run Ccleaner!
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    • Now run the C:\MGtools\VunFind.bat file by double clicking on it and be patient while it scans your whole hard disk
    • Now attach the new C:\MGlogs.zip file just created
    IMPORTANT: After you attach the above log it is critical that you not reboot or power down. You must keep your PC running until I create the next fix. You can unplug your cable to the internet while offline since we uninstalled some of your protection software (but it was not working properly anyway).
     
  29. Silent_Killer

    Silent_Killer Private E-2

    All done. The VunFind didn't take long to scan at all, I dunno if it scanned properly.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and save to RenV.exe from following link to Desktop (it must be on the Desktop)
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a log names Log.txt on your Desktop which will overwrite the one you just made. Attach the new Log.txt to your next reply.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\Windows\system32\pmkig.exe
    O2 - BHO: (no name) - {23B30639-18DA-4810-BACF-9C8C1719C365} - C:\Windows\system32\pmkig.dll
    O2 - BHO: (no name) - {46C100EC-840F-4AAE-8BF2-27E84A751058} - C:\Windows\system32\pmkig.dll
    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\vtuur.dll,#1


    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\roy\AppData\Local\Temp

    Now run Ccleaner!

    Now based on your previous logs, your PC did not appear to be in normal startup mode. You seem to be using MSconfig. See the READ & RUN ME and configure your PC for Normal Startup mode. And keep this way.
    • Now run C:\MGtools\GetLogs.bat by double clicking on it.
    • Now run C:\MGtools\VunFind.bat by double clicking on it
    • Now attach the below new logs:
      • Log.txt (it's on your Desktop)
      • C:\ComboFix.txt
      • C:\MGlogs.zip
    IMPORTANT: After you attach the above log it is critical that you not reboot or power down. You must keep your PC running until I create the next fix. You can unplug your cable to the internet while offline since we uninstalled some of your protection software (but it was not working properly anyway).
     
  31. Silent_Killer

    Silent_Killer Private E-2

    That set of events went without issues sir (for a change) rolleyes ;)
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's much better. We just have a few things I want you to delete manually.

    Delete the below files:
    C:\ProgramData\Math error error.52l04h
    C:\ProgramData\Math error error.xy58py
    C:\ProgramData\type loud upload.04w1a0

    Also delete the below folder:
    C:\ProgramData\third lies itch ford


    If you get the above deleted without any problems then your logs will be clean and you should get started on the below ASAP.

    Install the current version of Sun Java from: Sun Java Runtime Environment

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  33. Silent_Killer

    Silent_Killer Private E-2

    So far its looking good, I haven't notice any more malware or weird stuff happening. This is the first time Ive had malware this bad, I've allways done pretty much everything that the How to Protect guide has explained expect this time am going back to Avast & Spybot which I used when I was running XP, and now also running Sun Java instead of Java.

    What do you think of the Vista firewall? should I carry on using it or should I use another one?

    I cant thank you enough for helping me fix this malware, my hat goes of to you, and ya never know I could be back in a few months time (hope not) :wave
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need a realtime antispyware blocker. Spybot does not provide this unless you activate Teatimer which we have never liked.

    It's better than the one in XP but most think that it is still no adequate.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds