extremely badly infected pc

Discussion in 'Malware Help (A Specialist Will Reply)' started by cuchulain64, Sep 19, 2008.

  1. cuchulain64

    cuchulain64 Private E-2

    a Work colleague asked me to look at his pc as it was extremely slow and redirecting internet explorer.

    I followed the read and run me first but malwarebytes anti-malware would not run at all until after combofix. I thought better to run out of sequence than not at all.

    I think the pc is clean now but attach the logs for confirmation.
     

    Attached Files:

  2. cuchulain64

    cuchulain64 Private E-2

    MGtools logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any anti-virus software installed....?

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 8

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  4. cuchulain64

    cuchulain64 Private E-2

    Hi Tim

    You are correct there is no antivirus on this pc, I thought best to clean it and then install avg or some other free antivirus before i give it back.

    i have followed you instructions however internet explorer no longer connects to the internet after i removed java.

    if i open a command prompt i can ping the server at my work using ip address and the control panel and system show no problems with hardware.

    manually setting ipaddress, subnet and gateway make no difference, and no other browser is installed.

    on reboot there is an error message re bthelpnotifier.exe (which is a program installed by the isp who provided brodband previously) which reads "the procedure entry point getprocessimagefilenamew could not be located in the dynamic link library psapi.dll"

    the log files you requested are at
     
  5. cuchulain64

    cuchulain64 Private E-2

    sorry hit key in error before i'd finnished

    Thanks
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this ( and by the way....you should download another browser such as FF) ...

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\soaautmo.dll

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me what problems you are still having.
     
  7. cuchulain64

    cuchulain64 Private E-2

    Tim

    I have downloaded firefox on another pc and installed after carrying out your last fixes.

    when restarting i get an end program box stating Cardreaderlookupwindow the program is not responding.

    but there is no cardreader attached unless he has a usb one.

    Pc seems to run ok but still no access to internet through either browsers but i can ping a known external ip address and get reply.

    thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Removing Java would have nothing to do with not connecting.

    This will probably be an issue you should address in the software section.

    Have you flushed your dns cache? This probably has to do with your new isp. Have you spoken with them? Can they ping you?
     
  9. cuchulain64

    cuchulain64 Private E-2

    how do i flush cache?

    if connecting is only problem should i sort this out, install AV program and return pc?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / type "cmd" without quotes.....in the command prompt, type:
    ipconfig /flushdns
    enter....when complete, type exit.

    Yes, your logs are clean ...let's clean up from the scans and then you can install a AV program and you should check that when returned, it connects.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
     
  11. cuchulain64

    cuchulain64 Private E-2

    Tim
    thanks that did the trick, still not sorted internet conection out yet but that's another story.

    Thanks for your help
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds