Help Virus?!?

Discussion in 'Malware Help (A Specialist Will Reply)' started by THE_CANADIAN, Jan 3, 2008.

  1. THE_CANADIAN

    THE_CANADIAN Specialist

    alright well recently i dont remember but i clicked on a link to a site and it said that the site has moved and to please wait.. so i waited and then all of a sudden my avast! got a virus alert so i clicked moved to chest and then windows defender poped up to and they only had an option to ignore or delete so i clicked on delete and then avast! poped up again and i put moved to chest. From the name all i got was Trojan.. did my anti virus catch it? today i been noticing my computer getting randomly slow

    I had to log out and log back in and then my windows blocker poped this up.. could this be a virus ?? i clicked on keep blocking

    *shit the screenshot did not save but it was something like

    Name: -12252353515
    Unkown

    ........... im worried that i got a virus plz help

    i checked in avast! chest and got this
    -dat2F.tmp
    -dat2D.tmp
     
  2. THE_CANADIAN

    THE_CANADIAN Specialist

    URGENT EDIT

    Alright well i ran a avast! scan and it seemed to of found more viruses in a G:Windows/Temp/Altnet which i all moved to chest , i restarded my computer for the first time since gettin the virus alerts.. and now my computer will not connect to the internet!?!?!?!?

    So far the virus from avast! was Win32:Spyware-gen [Trj] , i really really really need help in getting this shit gone because i use that computer daily for important things especially since i got school projects and winter break is coming to an end!!

    This is completely stressing me out :eek

    I tried getting AVG installed putting it on a USB stick and then transfering it to the computer with out internet but while it start installing it gives me an error.

    WHAT DO I DO PLZ PLZ PLZ HELP
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    If you have not internet access you will need to transfer the files to and from the problem PC.

    Note: Deleting files in the Windows Temp folder should not have anything to do with internet access. I would expect that something you have done has broken your LSP chain. Possibly something related to a newdotnet type infection and a DLL getting removed. Doing the READ & RUN ME will help us figure this out.
     
  4. THE_CANADIAN

    THE_CANADIAN Specialist

    Alright well i followed the read and run first. I did everything in step 1 , 2

    For step 3 i ran the Combofix , Spybot(found nothing) and MGtool with out any problems. The AVG ran fine but in the begining it gave me a guard.exe error.. but still ran and did the scan.. dint seem to have made a log , it only found 1 infection that it said was very low risk.

    Hopefully i ran everything alright , still no connection with internet so AVG couldnt update.

    Thanks in advance for the help chaslang
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must be getting some kind of errors when you ran MGtools.exe. The logs are incomplete and what did run, ran incorrectly. Did you watch for the possible error messages given on the MGtools.exe download page? If you get any of those errors, you need to run the fixes.

    You don't need to rerun MGtools.exe now that it is installed. You can just run C:\MGtools\GetLogs.bat to run all scans. Try this and check for error messages.
     
  6. THE_CANADIAN

    THE_CANADIAN Specialist

    My bad , i ran the Xpfix and everything went well now.. i got a little confused because it said something like ignore error message.

    Here the Log with everything in it , i hope :D

    Thanx for quick respond
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below something you knowingly added?
    O24 - Desktop Component 3: Intelligent Explorer[ieplugin.com] OnScreen Portal - http://active.ieplugin.com/active/?14794449

    Your tcpip.sys file was changed on 01/03/2008. Did you apply somekind of performance tweak to your system to modify it?
    Code:
    "C:\WINDOWS\system32\drivers\"
    tcpip.sys     Jan  3 2008      359808  "tcpip.sys"

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [he64erknz6k] C:\WINDOWS\system32\he64erknz6k.exe
    O4 - HKCU\..\Run: [he64erknz6k] C:\WINDOWS\system32\he64erknz6k.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  8. THE_CANADIAN

    THE_CANADIAN Specialist

    nop , i have no clue what that is..

    Again no i did not run anything to make it faster.. but i ran avast! , lavasoft .. pretty much anti virus and spyware programs as a first defence to clean my computer.. maybe that changed something but as far a performance tweaks.. no.

    it seems to be running pretty good but at start up avast! seems to give me some errors (probably due to the no internet connections).. mainly all the problems are due to the no internet connection.

    So i guess my question is how do i get my internet connection back? its still not working and i have no clue what to do..

    My logs are attached.

    As alwas thanx for the help
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the log from Avenger.

    All of your issues with the internet could be related to what I was questioning about tcpip.sys being changed. Click Start, Run, and enter cmd and click OK. This will open a command prompt window. In the command prompt window type the below command and hit enter. It may ask you for your Windows XP CD if it finds problems so have your CD ready. Tell me what happens.

    sfc /scannow
     
  10. THE_CANADIAN

    THE_CANADIAN Specialist

    my bad , i attached the avenger log.

    I ran the Sfc scan and it scanned , then finished and did not find anything wrong.

    Any other ideals?

    **** EDIT *****

    i tried various troubleshooting things for my router etc.. eventually i had to completely reinstall and reset it.. now internet seems to be working fine.

    Final question , does my computer seem to be clean?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SFC will sometimes work quitely if it finds what it needs on your harddisk. Please do the below so I can check the status of your tcpip.sys file.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created



    Yes other than the queston of the tcpip.sys file you look clean but it could be the cause of your problems if infected. Do you have your Windows XP SP2 boot CD.
     
  12. THE_CANADIAN

    THE_CANADIAN Specialist

    here is the new logs

    and im not sure about the CD , ill check and see if i can find it.. im not 100% i have it or if it can with my computer as i bought this computer quite a while ago.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you will not need it This Time. ;) SFC was able to fix the tcpip.sys file from another file that was on your PC.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  14. THE_CANADIAN

    THE_CANADIAN Specialist

    Thanx alot Chaslang , extremely grateful :p
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds