virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by wolfx28, Oct 7, 2008.

  1. wolfx28

    wolfx28 Sergeant

    okay so im seriously getting pissed, until lately I have been impressed with Avira and now im totally Fing over it it keeps showing TROJAN DETECTED i hit delete it comes back, goes away for a while so i go into safe mode and delete the problem myself come back onto windows and it pops up right away with a new virus and i hit delete and it restarts my computer right when i hit delete then it boots up and says my computer is infected with spywear and not only that i get this thing that pops up like all the time saaying some windows error its looks exactally like the windows security that would come up saying ur firewall is off (mine isint) and it says trojan is in your system and click here to resolve and i hit it and it takes me to a site i just assumed spywear and ran spybot and got like 72 things got rid of them all and the problem still remained so im really angry guys anyone who can help would be great

    BTW i will NEVER get avira again i hate it

    EDIT: i just decided to look into my processes that were running and i stoped one that i dident recognize and the ico that kept saying " you have spywear on this computer" went away sorryy dident get a chance to write the name down i will keep an eye out if it starts up again :

    EDIT 2nd time: haha sorry but i went into my start up items and it is there the one i closed it magically puts itswelf in there casue i like JUST got rid of a few start ups before the restart and now its there anyways its called brastk and its in the system 32 folder ofcoase:p and also i clicked it cause it actually looked like a windows program ( the spywear notifer) and it installed XP antispywear 2009 and when i try to open that it instantly closes

    EDIT again Avira just came up with another trojan detected and it says c:documents and setting\owner\local settings\temp internet files\content.IE5\QQ500B18\pipo[1]

    Wolf
     
    Last edited: Oct 7, 2008
  2. Lev

    Lev MajorGeek

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. wolfx28

    wolfx28 Sergeant

    yeah i've done that all before i have the programs segested in there

    so the problem remains

    Wolf
     
  4. Lev

    Lev MajorGeek

    That's why we ask that you post the logs requested ;) Not all the applications listed just remove problems - they also provide countless information to the Authorized Malware Fighters so they can see what is going on in your registry and make suggestions as to how to resolve the issue you are experiencing. Without them, nobody is any wiser or able to help you.
     
  5. wolfx28

    wolfx28 Sergeant

    exactally what logs do you want?

    Wolf
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you follow the instructions they tell you which logs to post! For example, assuming you have Windows XP, you will see the below:

     
  7. wolfx28

    wolfx28 Sergeant

    heres first 2 logs
     

    Attached Files:

    Last edited: Oct 10, 2008
  8. wolfx28

    wolfx28 Sergeant

    not sure if you wanted the HJT log but i threw it in

    Wolf
     

    Attached Files:

    Last edited: Oct 10, 2008
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach only the logs requested. See this: HJT Tutorial - DO NOT POST HIJACKTHIS LOGS

    We still need the logs from COmboFix and SUPERAntiSpyware.

    Also your MBAM log shows you did not fix anything. Did you fix these items and give us the log before fixing?
     
  10. wolfx28

    wolfx28 Sergeant

    i added SAS log in the edit of my last post and heres the combo fix sorry for confusion

    EDIT um i am quite sure i did try and fix the problems through mbam not before the log and i dont believe there were any errors

    Wolf
     

    Attached Files:

  11. wolfx28

    wolfx28 Sergeant

    i actually havent been getting any virus warnings today so maybe the programs actually fixed everything but is there anything in the logs that say i may still have trouble

    Wolf
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need to do the below.

    Uninstall Messenger Plus! Live & Sponsor (CiD) as highly suggested in the READ & RUN ME. You installed malware when you installed this.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 2

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O4 - HKLM\..\Policies\Explorer\Run: [F1dSG062iO] C:\Documents and Settings\All Users\Application Data\ajcbwbgz\oridoleh.exe
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)

    And is the below something you recognize as valid? If not, fix it too?
    O4 - Global Startup: run_startmenu.cmd

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. wolfx28

    wolfx28 Sergeant

    okay im at the HJT part and im pretty sure there are a few more there that you missed like:

    HKLM\..\Run: [brastk] C:\WINDOWS\system.32\brastk
    (thats actually in there 2 times and i know that thats bad)
    HKLM\..\Policies\Explorer\Run: [F1dSG062iO] C:\Documents and Settings\All Users\Application Data\apotinab\mzijytkz.exe

    and theres 2 others with AOL toolbar do i need thoes

    Wolf
     
  14. wolfx28

    wolfx28 Sergeant

    When i do the CFscript.txt thing and drag it to the combo fix it dosent do anything it shows a little bar load and then nothing

    BTW im running XP

    Wolf
     
  15. wolfx28

    wolfx28 Sergeant

  16. wolfx28

    wolfx28 Sergeant

    sorry one other thing theres some malware or virus thats diabling my task manager it says disabled by administrator yet im the only person on this computer

    wolf
     
  17. wolfx28

    wolfx28 Sergeant

    okay well i have managed to get my task manager back and i did the MGtools log so i have that just nothing is happpeneing with the combofix


    Wolf
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not miss them. They were not in your previous log. And the mzijytkz.exe one was previously named oridoleh.exe. When things like this happen, you need to just finish instructions and continue on. If anything is left over or new pops up like this, we would just get it in the next round of fixes. What you also need to do now is avoid rebooting or powering down your PC except when we request it. Your malware is spreading and mutating when you do.

    Now about my previous fix. Since ComboFix did not work, we need to come up with a different fix. I will base this new fix on what is in your current MGlogs.zip file and I will use Avenger instead of ComboFix. I will post this in my next message.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {621483C7-EF15-1660-0E71-00BE5E159BBC} - C:\Program Files\lxgaheb\StrUiDb.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Policies\Explorer\Run: [F1dSG062iO] C:\Documents and Settings\All Users\Application Data\apotinab\mzijytkz.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop (yes overwrite the previous file of the same name). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Shutdown your Avira Antivirus program now.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner!

    Now download and run the current version of MGtools from here: MGtools.exe


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. wolfx28

    wolfx28 Sergeant

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now put your PC into normal startup mode with MSconfig. You are still in selective startup mode.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Your logs are otherwise clean. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Oct 18, 2008
  22. wolfx28

    wolfx28 Sergeant

    okay i did that but i decided to run another malwarebytes scan so i did and it came up with 40 malware i removed them but im just not sure if like there gone so i went through all ur steps before doing this

    Wolf
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are new problems. What have you been doing? You may be getting these new infections because you are not properly protected which is what by instructions in message # 21 wanted you to do but the link got chopped off in step 10. I just added the link back in to step 10.

    Did you fix them? You log shows you took no action.

    Update MBAM to the current version that just came out and run a new scan. Make sure you Quarantine the problems then attach a new log.

    Are you having any actual malware problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds