He wants to be a DJ...now my computer is infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by blue2gnt, May 19, 2009.

  1. blue2gnt

    blue2gnt Private E-2

    A friend of mine has a program that he tried to install on his machine, but apparently it doesn't work with his sound card. After offering to let him try it on my machine, my precious computer now has the equivalent of the AIDS virus...This is the worst infection I've ever seen.

    I've followed all of the steps in the readme and the requested logs are below. The only two things that could not be followed explicitly are:
    - I am unable to uninstall AVG antivirus. When running the uninstallation procedure, I get an endless loop of confirm dialog boxes asking me if I want to quit setup. Therefore, I have both AVG and Superantispyware installed. I wanted to install HijackThis to use it for uninstalling AVG, but typing "HijackThis" into a browser window shuts the browser down. I also cannot shut down or disable AVG during the Combofix scan process.
    - I cannot type the words "firewall" or "AVG" (among others, presumably) into any browser window without the browser automatically shutting down also.

    Notes:
    *I have no firewall other than windows firewall installed, as my AVG one just expired. Again, typing the word "firewall" into google shuts down the browser.
    *I can manually start windows firewall, but a few minutes later it disables itself.
    *The infection resulted immediately after installing VirtualDJ software...who knows where he got the file, probably a P2P site.

    A big thanks for your help...a fresh windows reinstall is very much not an option right now, as I have neither the time, nor the original install disc to do so.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG is an antivirus program and the free SUPERAntiSpyware is only an after the fact antispyware scanner. There is no problem having both of these installer.

    HijackThis is not a program uninstaller even though there is a place under Misc Tools labeled like that. It merely tries to run the same uninstall as in Add/Remove programs.

    Did you uninstall the program your friend installed? I still see a folder for Virtual DJ. I'm looking thru your logs now.
     
  3. blue2gnt

    blue2gnt Private E-2

    I am unable to uninstall the program. When attempting to do so, I get the error message: "Could not open INSTALL.LOG file"
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I finish looking at the rest of your logs and build a fix, see if the below will uninstall it.

    Your Uninstaller! 2008
     
  5. blue2gnt

    blue2gnt Private E-2

    Will do, thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 11

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. blue2gnt

    blue2gnt Private E-2

    Thanks.
    The only hiccup worth nothing in the process was that when running combofix, I am still getting the error message saying that AVG is currently running, even thought I right clicked and disabled it before starting combofix.

    Not sure if that caused a problem or not. Here are the two new logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean now but let's just remove the entry in Add/Remove Programs for Virtual DJ


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  9. blue2gnt

    blue2gnt Private E-2

    Thanks again for all your help, so far so good.
    I did get a success message to the above instructions.
    I can now access windows update again, and can freely type whatever I like in search boxes. I am running freshly updated antivirus from Avast, was able to uninstall AVG (finally) and am in the process of shopping for a decent free firewall. Got any recommendations, or does windows firewall suffice?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These were all addressed in the link I gave you in my last message.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds