I guess I'm next in line for help with Yoog

Discussion in 'Malware Help (A Specialist Will Reply)' started by gqfaz, Jan 6, 2009.

  1. gqfaz

    gqfaz Private E-2

    Ok, I think I may have gotten rid of DCads following all the malware removal instructions. Now I need to get rid of this Yoog search. I've attached th ComboFix log. Thanks.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gifWelcome! to MajorGeeks.com!http://www.majorgeeks.com/images/grenade.gif

    Please follow the instructions in the READ & RUN ME FIRST link given further down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in Safe Mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is advised that after completing the READ & RUN ME you also read this sticky:
    4. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. gqfaz

    gqfaz Private E-2

    Whats the dael with this forum? Has it blown up too large for any of you folks to help me the way I've seen people helped in the past? I've already followed every step in the Malware Removal process. Downloaded and run every single friggin program. CLEARLY, the majority of the time, people that have done that still havent gotten rid of Yoog or DCADS, and I still have both. Could I please have some specific help as to what lines of registry, .dll files, or whatever that I need to delete, and not just a copy and pasted standard response??????????
     
  4. gqfaz

    gqfaz Private E-2

    I repeat, I've run every single program and tool in the Vista Malware Removal Guide, plus C-cleaner (plus ad-aware, plus defragging for the hell of it). Your instructions never actually say which logs to save and attach (they really don't, look it over) so I'm not sure where the logs are saved in the some of the other programs I've run from the Guide. Please give me a SPECIFIC response as to which logs to attach, and where I can find them (I'll run the damn programs again if I have to) with the understanding that I have done ALL of your "do this first" procedures. Please don't take 4 days to give more of the exact same "follow the malware guide" stuff.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you would actually take the time to read and follow instructions we wouldn't be wasting time as we are. I see clearly in the READ ME where it says, if you're still having problems to attach the logs you got after doing the scans but if you never ran them of course you don't have them.

    If you want help, follow instuctions!

     
  6. gqfaz

    gqfaz Private E-2

    Ok, I missed the "if you're still having problems" part, but seriously, why did you first assume that I didnt run the scans and then when I point blank told you I did TWICE, did you say "you never ran them of course you don't have them." Are you messing with me? Anyways, its been over a week so I figured I'd run them all again so everything is up to date. Apparently, you can nly attach 3 files, so I'll post a second reply with the MBAM log. Here you go:
     

    Attached Files:

  7. gqfaz

    gqfaz Private E-2

    Annnnd here's the MBAM log. Thanks.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I'm not messing with you, I assumed you didn't run the scans because you did not attach the requested logs you would have if you had read thoroughly and followed every step initially. Over half of the member in this forum "follow the instructions" but never post a log nor know what to do.

    Yeah, again if you read a little closer you'd see our guides explain everything.:)
    That is not what was stated:
    "but if you never ran them of course you don't have them."
    We are inundated with requests for help as many sites have stopped doing malware removal. So it is time consuming for those that volunteer to have to ask or repeat instructions.
     
    Last edited by a moderator: Jan 13, 2009
  9. gqfaz

    gqfaz Private E-2

    Excuse me, I did everything you asked. You were so busy arguing semantics and quoting every last line of my response, that you never actually HELPED me in any way, whatsoever. I re-followed the instruction word for word; they didnt work so I re-ran everything and posted all 4 logs according to your proper attachment procedures. Will someone please help me? :major
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs are clean however I have added a few questions/comments below.

    First, are you familiar with the following folders? I would check to see what is in them and if it's nothing your familiar with I would delete them.
    Next, go into Control Panel and uninstall the following items.
    Next I would like you to install the current version of Sun Java: Sun Java Runtime Environment

    Finally...
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.
     
  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Also, if you're still having the Yoog issue, then please see the thread below. Once complete, let me know the results and how things are currently running.

    Yoog Removal
     
  12. gqfaz

    gqfaz Private E-2

    Hmmm my main longish reply didnt seem to go through.. Here goes again... Sorry its taken so long to respond, I've worked a ton of hours lately, and this stuff takes time. I followed your additional instructions: no dice. I did all the computer maintenance stuff, I updated all the programs in the malware removal guide, re-ran everything, re-followed your additional instructions just in case, followed the Yoog removal guide, and I still have Yoog and DCADS. I ran Adaware but was unable to run Kaspersky or Micro Housecall, because, infuriatingly, they are telling me I either dont have the latest version of Java, or that its not enabled. It certainly is the updated version and its clearly marked as being enabled in Firefox in every which way. In all of this, only one thing didnt show up that you said to delete. In the Yoog Removal, everything you said would be there was there and was deleted (again to no avail) but there was no apparent Yoog file in the C:\Users\Faisal\AppData\Roaming\Mozilla\Firefox\Profiles\7gmsih0a.default folder. There is some serious hidden :crap in my computer masquerading as something innocent. I havent cut a single corner, when I was supposed to be in Safe Mode, or Running as Administator, or closing Browsers, or Disabling other anti-spyware stuff, I've followed it all. I'm at a total loss. :banghead:banghead:banghead:banghead:banghead
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry BJ has not been around for awhile and you thread slipped out of sight. If you still need help, please do the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {045E075D-9C55-42F5-81C2-67D4A26F39AC} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O8 - Extra context menu item: &Search - ?p=ZRfox000

    After clicking Fix, exit HJT.


    Now we need to use ComboFix again.
    • First delete the old copy of ComboFix.exe from your Desktop.
    • Download the current version from here combofix.exeand make sure you save it to your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. gqfaz

    gqfaz Private E-2

    Sorry its taken me so longto respond. I had followed your latest instructions and it didn't make a whit of difference so I didn't bother responding with the attached logs, since this is the 4-6th time you guys have attempted to help me, I've followed all the instructions, and I still have DCADS and Yoog. My situation is now much worse. Not only do I still have those 2 viruses, but my PC is running at 100% all the time and despite all the various reasons and attempted methods from researching online (apparently there are many, many different causes of this) I haven't been able to make much of a dent in it. I'm starting Windows using only the basic services necessary, and virtually zero startup programs and its still spiking at 100% even when I open almost any program. Its making my fan work so hard that I recently smelled a burning electrical smell, so needless to say, I'm freaking out. To make matters worse, when I just tried to follow your latest instructions again (actually for the 3rd time) and attempted to drag the notepad instructions onto the Combofix logo, I got a message "!!ALERT!! It is not safe to continue! The contents of the Combofix package has been compromised. Please download a fresh copy from http://www.bleepingcomputer.com/combofix/how-to-use-combofix Note:You may be infected with a patching virus (Virut)"
    So I tried that and that also didn't work; same thing. I just re-followed your malware removal guide, and still all the same problems. UGH. Heres the latest MGLog for whatever its worth. Please help. :banghead:cry
     

    Attached Files:

    Last edited by a moderator: May 21, 2009
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is way too long since you last ran everything so we would really need all new logs. However if ComboFix is detecting that you have a Virut infection, this would be a new problem that you did not have previously and it has nothing to do with Yoog. You also have some other new infections that you previously did not have and this is probably happening because your PC has no protection software installed.

    If you do have a Virut infection, you are possibly looking at a total clean reinstall but I will try to give you a fix to see what happens.

    Do you have a bootable copy of your Vista CD? If not, did your PC come with a factory recovery CD or a factory recovery partition?

    {Edit} I cannot give you a starting fix. You do not have your PC in normal startup mode as requested in step 1 of the READ & RUN ME. You need to do this now and then reboot. After reboot, you need to run MGtools.exe again and then attach the new C:\MGlogs.zip file.
     
    Last edited: May 21, 2009
  16. gqfaz

    gqfaz Private E-2

    Well Combofix inadvertenly told me a have a Virut infection I suppose: Combofix as I've stated would not run. I downloaded the 30day trial of ESET, and that is the only thing that was at least blocking the infection. I say "was" because the little box in he corner is now saying "error while cleaning" as opposed to the previous "blocked-quarantined." I understand it has nothing to do with Yoog. I do not currently have a boot CD. Is that something that can be created, or ordered? I'm dreading wiping my hard drive... Let me ask you this: Of all the woebegone, doom-is-upon-us sites that basically tell everyone they are screwed and need to reformat if they have this virus, there is only one that I've seen say otherwise, although I'm very skeptical because they seem to want to promote their product. (although its free) http://remove-malware.com/antimalware/my-tools/so-what-is-virut-and-why-is-it-sooooo-evil/ What do think of this? I'll do as you say and reattach the MGLogs.
     
  17. gqfaz

    gqfaz Private E-2

    Here are the 4 logs required.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should be able to purchase one. Possibly from the company you bought your PC from or you will have to buy one in a store or direct from Microsoft. You really should have the Windows Vista boot DVD. and infact since you have not even updated your system to Service Pack 1 (which you really need to do) you should get the Vista SP1 DVD.

    You don't have to if you don't have a Virut infection and right now it is hard to tell for sure, but I do see varying file sizes for many of your Windows system files which is not making me think you are free of this infection. If fact your Windows\system32 folder is showning many many files were modified on 5/19. Did ESET say anything about a Virut infection being found? Is 5/19 the date you ran ESET?




    First let's clarify a few things:
    • Those are not "their products". Those are tools freely downloadable and we even use them in this forum and have them available at MGs for downloading. The UBCD4Win is Windows XP, 2000, and 2003. It is not for Vista which you have and you would need a copy of your Windows Boot CD to make the disk being mentioned. In addition you would need another clean PC on which you could make the CD so that you could make a CD is not carrying the infection which would just spread to any PC you run it on.
    • Even if and antivirus program (run by any special method) is able to disinfect the files, the end result in many cases is the many many files could be corrupted anyway. The end result is many programs will not work, or will not work properly. You could have lots of errors and corrupted Windows files. And in the end there is still no guarantee that the virus has really been completely removed. Thus your system cannot be trusted and operation will be unreliable.
    • Removal attempts can result in an unbootable PC since many necessary files could windup being deleted which is why backing up personal data first is critical.
    • A format and reinstall is the fastest and especially the safest solution? Why bother working thru many, many special procedures (which we are too busy to guide you thru, making special CD, ....etc) taking many days of additional waiting time in between posts only to keep resulting in one failed removal attempt after another. This would be irresponsible of us and a waste of your time and ours. Yes if we were able to sit in front of your PC and try a few tests, we could possible fix things. But trying to explain various things to you in a forum like this where it can take 2 to 4 days inbetween our posts back to you could result in weeks of PC down time. And during this time, the infections you have could potentially be causing other problems, downloading more infections and possibly stealing information.
    • In our forum, we rarely say a reinstall is necessary. However newer forms of PE file infectors like Virut have become impossible for automated viruscan programs to properly disinfected and the result can be thousands of files that may need to be manually replaced. If a person has lots or time to waste and the reliability of their PC and data is not important to you them then by all means they can experiment with a variety of tools
     
    Last edited: May 27, 2009
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We can continue working on this if you wish and I will post some additional steps below. ComboFix removed some of the items related to Yoog but did not get all of them for some reason.

    I suggest that you uninstall the expired demo for RegGenie which may have been infected as soon as you installed it. Also if RegMechanic is just a trial, you should uninstall it too.

    Note that even Eset could have become infected itself which could be the reason it seems to have stopped working. How long was the trial period for?


    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds