possible malware problem. RRM logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by magnanimous, May 24, 2009.

  1. magnanimous

    magnanimous Private E-2

    First indicator that something was wrong with my computer was when I was surfing and a thing poped up saying that my computer was at risk for viruses, it appeared to be a program trying to search for threats on my computer. I already have AVG and did not install such a program and have seen similar things in the past and have always just closed them and ran a scan on AVG, however when I clicked the X in the right top corner of the pop up another window opened saying "thanks for downloading" and something about my computer now being protected or something. Under the start menu a new program had been installed, I can't remember the name of it. I then did a scan with AVG and got rid of things it found, thought it was fixed. Returned to IE, "Insecure Internet activity. Threat of virus attack" screen showed up giving me two options...one to download something to fix the problem or to continue on to the unsecure site. I chose continue. I kept getting the same error message as I was trying to navigate the web.

    I then ran my CCleaner and Superanti-spyware.

    Then tried to google the "Insecure Internet activity. Threat of virus attack" problem and when I tried to click on links a pop up for other search engines and other sites would show up, not sending me to the URL i clicked on from the google search.

    At one point I came across a site that suggested using spybot search & destroy. Downloaded it, it wouldn't run.

    I then would cut and paste the URLs instead of clicking on them, and came across the site "howtogeek.com" for help. Started topic "how to remove: 'insecure internet activity. threat of virus attack'"

    It was suggested that I download and run MBAM. I did this, it would not run. I was instructed to redownload it giving it a new name. I did, it still would not run.

    I was then suggested to follow the guide(s) at majorgeeks.com

    I have followed everything on the read & run me first malware removal guide.

    Went through "Windows XP Cleaning procedure" and followed the instructions there.

    SUPERAntiSpyware found items and got rid of them, got a log. :)

    Malwarebytes anti-malware would not work. I had tried it earlier with no luck, but tried again anyhow; it still woudldn't work. Even tried to run it in safe mode.

    combofix.exe would not run either.

    followed MGtools instructions. It did run, got a log. :)

    The problem with "Insecure Internet activity. Threat of virus attack" thing stopped happening, so something worked. :major

    However I'm still having the problem with google searches. And my laptop running slow, but I thought I just had too much stuff on my laptop so i bought an external hard drive that i put everything on a few months ago...which helped a little.

    I've had this same problem in the past, about 6 months ago i think which is when I got the CCleaner and SuperAntiSpyware...which fixed the problem back then.

    If it matters I have all important files backed up already incase things get worse.
     

    Attached Files:

  2. magnanimous

    magnanimous Private E-2

    Update to the problems...my laptop got severely worse. It now won't open any program whatsoever. I've disconnected the internet from it because of the massive pop ups it was getting...about to do a system restore.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Try doing the below. I prefer you do this in normal boot mode but you can try safe boot mode if you cannot run in normal boot mode.

    First you must disable Spybot's Teatimer. See this: How to disable Spybot's TeaTimer

    You should not be running Teatimer with Ad-Aware's Ad-Watch enabled and also you really should not use Ad-Watch with AVG8 installed which has its own antispyware built-in. Disable AVG8 and Ad-watch before trying to do the below!!

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe,
    O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
    O1 - Hosts: 94.232.248.66 antivirprotection.com
    O1 - Hosts: 94.232.248.66 www.antivirprotection.com
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Amanda Frehner\Local Settings\Temp

    You were way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now also try to run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • the logs from SUPERAntiSpyware and Malwarebytes if they ran.
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. magnanimous

    magnanimous Private E-2

    Thanks for all of the suggestions.
    However the laptop will not allow me to open any programs, even in safe mode, can't open spybot to begin with. It also won't let me do a system restore. Probably should have done that to start with since I have nothing important on the laptop.
    For whatever reason Compaq made it so I can't restore it unless I'm in windows, so doing it at startup is impossible, unless you know another trick. Already went through all the F keys.
    I'm going to contact Compaq and get restore disks and try to go from there. Otherwise I'll just replace the hard drive.
    Thanks again, all the info you gave me will help with the new Asus laptop I just bought...which came with restore disks thankfully.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Restore has nothing to do with Compaq. System Restore is a Windows feature.

    Now it sounds to me like you did not mean System Restore but rather meant a factory restore which returns a PC to the state it was shipped. This I cannot help you with. You could check in the Software Forum or on HP's website to find out how to do that.

    A possible option, that may or may not work, would be to put this hard disk into another PC as a slave drive and run scans on it while in the other PC. Also you could then manuall delete the C:\WINDOWS\system32\twex.exe file I mentioned but it will not be on the C drive when slaved in the other PC. It will be whatever drive letter it gets as a slave drive.
     
  6. magnanimous

    magnanimous Private E-2

    Thanks, I'll check into HP's website.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let us know what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds