Popups and errors during readme process.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pete22, Jun 3, 2009.

  1. Pete22

    Pete22 Private First Class

    Hello my geek friends,

    Last night spybot found a trojan. It was listed as a driver in Windows32. Spybot said to fix it by removing the file. But that it may not be all of the problem. I did remove the file. Then I ran AdvancedSystemcAre and it said my computer was hijacked.

    So this morning I started the readme and run routine.
    SAS found nothing
    MB found nothing
    Shortly after I started Combo fix SAS popped up and said it found a trojan.
    Then other programs started popping up too. When it finished I saved the log. But decided to start over.

    Ran SAS It found a trojan and I removed it.
    Ran MB found nothing.
    started Combofix again.
    This time SAS popped up again and said if found several trojans.
    I stopped Combo fix again. And restarted with SAS turned off.
    Ran Combo fix and it had an error in Hijackthis. I let it continue and but I kept getting popups that my home page had been changed to some microsoft address, did I want to allow that, which I didn't.
    I then ran MGtools.

    Since I can only send 4 with this message,I picked these messages to send
    File of SAS
    File of Combofix
    File of Hijackthis error
    File of MGtools

    Hope you can make sense of this.

    Pete22
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually that is a false positive. pev.exe is a program called PevFind which is used by ComboFix.

    We want to see the log anyway to insure the correct version was run.

    ComboFix does not run HijackThis. Did you mean to say you ran MGtools and that is when the HijackThis error appeared?

    Changed to which address? Your log shows the below is currently your start page:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ksl.com/index.php?nid=88

    Is this your desired start page?


    Your logs are clean. Are you actually having any malware problems?
     
    Last edited: Jun 5, 2009
  3. Pete22

    Pete22 Private First Class

    Hello Chaslang:


    I forgot to mention on my last post. When I finished the Mgtools program on 3 Jun 2009 all of the icons on my Quick Launch toolbar and most of the icons for my programs listed in Programs menu from the start button were ruined. I have fixed them now.

    XP has just been reinstalled on my computer. That's why I thought it was a malware problem. I am sorry that I did not include my problems in last post. I realized it just as I pressed the send button. I know we are supposed to wait for a reply before reposting.


    What caused me to do the readme and run routine:

    -Installed Programs keep disappearing.

    -Whenever I use my Maxthon 2 browser all the setting have been reset to the default.

    -Sometimes I when I go to Add/Remove programs the page stays blank. I use SAS to fix this problem

    -When add/remove came up properly, I still could not delete programs because it said the microsoft installer tool was damaged. So I had to reinstall it.


    I have decided run Combo.fix and MGtolls again and attach these files along with this post. If you don't see any malware on the new files, then please advise me what my options are. :banghead

    OK. I just bought SAS. In the past, I had SAS free and it did not cause problems. I realize now I need to turn it off while I do these tasks. I will also remove internet access while I do. Then I can't be infected while I run this, either. I will also disable winpatrol. If anything else pops up I will disable it and rerun the report so I get a good report for you.

    I don't know how to stop the windows notification that I have disabled stuff. So combo fix ran with no other popups except that one.

    I'm glad you want to make sure I did the right thing. I will attach my MBAM report.

    Oh yes, you are right. In the future I will take notes as I run each program. That way I can keep better track of the process. I got that same error today as well.

    Wasn't it you who wrote Hijack this? ;) So you would know whether the error in Hijackthis was caused by something other than malware.

    Today just after I finished MGtools, and was looking for the MGlogs this popup reappeared. See attacked picture.

    It was probably the same as all of the ones that kept popping up during the process last time. Instead of being a homepage redirect, it is a search redirect from google to iesearch. I have never heard of iesearch.

    If it is not malware, what should I do?

    You do a great service. Thanks for all of your hard work

    Pete22
     

    Attached Files:

  4. Pete22

    Pete22 Private First Class

    p.s. Avast settings are being reset to default everyday. That worries me.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MGtools makes no changes to any of this. It only makes a few registry changes to set some items back to defaults that malware frequently breaks. It also makes some fixes to adjust for changes that ComboFix makes and should not be.

    Like what?

    Just sounds like you may be having a problem saving settings which could indicate a problem with your user account permissions or a problem with your reinstall. This could be same reason things in install go away.

    Or perhaps another reason is just due to what you may have installed. You have WinPatrol blocking various changes and you have PC Tools Firewall Plus installed. Did you also install Threatfire with it? Try uninstalling WinPatrol and all of the PC Tools software and then see how things are working. Are you settings being saved now? If not, make sure that you are not using SAS Pro or Advanced SystemCare 3 to block any settings from being saved permanently. You should not be using WinPatrol anyway since you have SAS Pro installed.

    Not a malware problem.

    No malware problems. Try uninstalling the iems I mentioned above to see if you are just being confused by the programs that you are using.


    Yes and the log shows why I asked for it. You did not update to the correct version. You need to update everytime before you run a scan.

    No!

    It is just a problem that appears sometimes. Potentially a conflict with something else that is running. It is a long standing bug that has never been fixed and never will be since TrendMicro apparently does nothing to support necessary changes to HJT. It did not stop it from running.

    MGtools does not make any changes to your default search page and form the snapshot, it looks like it was just being reset to the Windows default setting.

    Nothing or allow the change since it is not a problem. WinPatrol is perhaps confusing you since it is blocking changes and sometime you need to allow changes when you are the one making them.
     
  6. Pete22

    Pete22 Private First Class

    Hello Chaslang:


    I am so glad you noticed that I had the wrong Malwarebytes. I downloaded it and ran a full scan.

    It found Malware!!!! I will attach the log. I want to deal with this before I go too far with the rest of your instructions.

    I was hoping the ruined icons would help you identify the malware. Is this one of the signs of this type of malware? If not, then there is still trouble in "River City."

    I have been using winpatrol since win98, so it is not likely to be causing these problems. I did install threatfire, but deleted it as best I could when I found out is was not a good idea.

    I did just buy SAS. Its setting maybe incorrect. However, I have noticed that CCleaner is cleaning stuff it should not. I am not sure if it is doing this because it was compromised by the malware or if the setting need to be tweaked. For example, file extentions that I am currently using are slated for removal. Files for a new program [I installed the day before and used for several hours] were also listed as from an unused application. So I have stopped using it. I also have stopped using pctools for now.

    I did not do the reinstall myself. I have also wondered if it needed to be done over.

    Before I change too much, lets deal with this malware and then see what we have left. Thanks for sticking with me until I found it.

    Thanks for using your brilliant mind to help others.

    :)

    Pete22.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is just a false positive due to the nature of what RockXP does in trying to recover passwords.

    Not really. Yes malware could potentially do this since it could do anything but this is just as likely to be a problem with Windows.

    Bad assumption. Programs change with every update and you should not be using it when you have the protection for SAS Pro installed. Double protection like this can be just as problematic as double antivirus programs.

    Not a malware problem. If you wish to discuss any problems you have with CCleaner, post them in the Software Forum. And infact we did not ask you to run the Issues tab.

    Are changing the subject from CCleaner to something else? Are you referring to Add/Remove Programs? Also a topic for the Software Forum and it never gives correct information.

    You're welcome but you don't have any malware to deal with so it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     
    Last edited: Jun 12, 2009
  8. Pete22

    Pete22 Private First Class

    Possible malware found in backup files of C drive found on F drive

    Hello again,

    After your last instructions, I tried to stablize Windows. I did a Scannow and it did find that several files needed to be repaired. I also copied the files on this hard drive in case windows died.

    This morning SAS was doing its daily run and said it found malware. When I looked at the file, the entries were found on my F drive, but were backup copies of information on my c drive. Then the computer started crashing. I had to reboot several times to get it to be stable. My Timeto program kept closing unexpectedly. Firefox kept highjacking my default internet browser.
    I am not sure I got the items from SAS cleaned off because of all the crashes.


    I then ran CCleaner, it ran fine.
    MBAM crashed.
    I was able to run Combofix.
    After combofix rebooted the host file had been emptied out. Winpatrol notified me and I refused the change. It also had the search engine changed from Google to something at msn again, just like before. I also refused that change. I am assuming this is a windows issue.

    I then ran MGtools.

    Please look at these logs one more time and confirm that these issues are not malware. if so I will wipe this computer clean and reload windows.

    Could it be possible that it is a hardware issue of some kind instead? like something on the motherboard?

    Pete22
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Possible malware found in backup files of C drive found on F drive

    Not problems. They were just old restore points that you backed up.

    Not related to what SAS had found. Sounds like you have Windows software/driver issues or hardware problems.

    Your logs are still clean. You need to complete 100% of my final instructions given in message # 7.
     
    Last edited: Jun 21, 2009
  10. Pete22

    Pete22 Private First Class

    Thanks for your patience Chaslang.

    Ok, thats sorta what i thought.

    Windows crashed, as you suspected, shortly after I sent my last message. I can only use lunix on it right now. Thanks to your warning of a windows issue, I had backups of almost everything. Thank you.

    For future reference: If I run the read me and run and there is no malware or only stuff in the restore, as per you or one of your assistance, and I am still having problems, it is probably a windows problem or a hardware problem.

    Any other big flags that I could learn that would help me guess that windows was at fault instead of malware?

    Maybe a better question? When should I suspect a windows issue instead of thinking it is malware? Or should I always assume it is Malware first?


    Thanks again,

    Pete22
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Not necessarily. No scans are perfect and malware changes all the time.

    It is not always so straight forward. We normally decide based on the description of the problems, the status reported by the logs, and an educated opinion which is not always going to be perfect since as I stated, malware keeps changing. Thousands of new infections each month.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds