Went through the read me first.. I think I still have virus in my computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by ihatetrojan, Jun 16, 2009.

  1. ihatetrojan

    ihatetrojan Private E-2

    I was watching a movie online yesterday in fairyshare.com and everything froze.
    I manually turned off the computer and turned it back on and there were these random beeps from my computer. I realized I had some kind of virus, so I first tried to restore my computer, but the restore points were all deleted and it had also disabled my superantispyware.. So I downloaded Trend Micro free trial and came to this site and did everything it told me to do.
    I think I had virus before because internet had been pretty slow.
    Everything worked fine except the combofix.
    I downloaded onto my desktop, turned off all browsers and anti-virus software, but just didn't load up for some reason.
    I don't know how I got superantispyware to work.. clicked runSAS.exe and it worked..
    attached are the logs.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you saying you were running with no protection installed before this? Why ?

    Is your copy or Spyware Doctor a paid version or free trial? If just a trial then uninstall it now.

    Uninstall cleancop and Internet Explorer Guide V2 which are considered malware.


    Also uninstall the below outdated versions of Sun Java per step 1 of the READ & RUN ME.
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) SE Runtime Environment 6 Update 1


    You have left overs from Symantec and also McAfee that need to be removed.Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: GoExtension Class - {41410178-A480-4E9A-B776-BD617E155154} - C:\Program Files\GOSearch\GoExt.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {D063771C-94D6-4748-A4A1-3686A9D686AD} - (no file)
    O2 - BHO: (no name) - {DAEFDC31-17CF-4B40-9BCA-6C996077E080} - (no file)
    O2 - BHO: (no name) - {FBBB44AA-B7CA-4AFF-8A16-EE719A85E3B8} - (no file)
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
    O4 - HKCU\..\Run: [ieguide_v2] C:\Program Files\ieguide_v2\ieguideupdate.exe
    O4 - HKCU\..\Run: [cleancop] C:\Program Files\cleancop\CleancopUpdate.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O9 - Extra button: G¸¶ÄÏ - {28EF4C11-5850-45C8-99E8-83D98C8EA9A1} - http://www.gmarket.co.kr/index.asp?jaehuid=200001554 (file missing)
    O9 - Extra 'Tools' menuitem: Áö¸¶ÄÏ - {28EF4C11-5850-45C8-99E8-83D98C8EA9A1} - http://www.gmarket.co.kr/index.asp?jaehuid=200001554 (file missing)
    O9 - Extra button: ¿Á¼Ç - {37AD4B83-9515-433A-866B-BED686C86838} - http://event.go.co.kr/wizauction/ (file missing)
    O9 - Extra 'Tools' menuitem: ¿Á¼Ç - {37AD4B83-9515-433A-866B-BED686C86838} - http://event.go.co.kr/wizauction/ (file missing)
    O9 - Extra button: ¸Þ°¡ÆÐ½º¹«·á¿µÈ­ - {48BB3017-3CCC-440B-B238-59850C0FBDD8} - http://event.go.co.kr/megapass/event.php?pid=ebiz (file missing)
    O9 - Extra 'Tools' menuitem: ¸Þ°¡ÆÐ½º¹«·á¿µÈ­ - {48BB3017-3CCC-440B-B238-59850C0FBDD8} - http://event.go.co.kr/megapass/event.php?pid=ebiz (file missing)
    O9 - Extra button: CJmall - {577C8740-E9C0-405C-900A-8047D3D8635B} - http://event.go.co.kr/barcon/c.php (file missing)
    O9 - Extra 'Tools' menuitem: CJmall - {577C8740-E9C0-405C-900A-8047D3D8635B} - http://event.go.co.kr/barcon/c.php (file missing)
    O9 - Extra button: ½Å¿ëÄ«µå/´ëÃâ - {E2CCCAC1-C931-4E3A-B4F1-129C4A7A6201} - http://yesmoney.co.kr/ (file missing)
    O9 - Extra 'Tools' menuitem: ½Å¿ëÄ«µå/´ëÃâ - {E2CCCAC1-C931-4E3A-B4F1-129C4A7A6201} - http://yesmoney.co.kr/ (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O15 - Trusted Zone: *.download.com
    O15 - Trusted Zone: http://*.wedisk.co.kr
    O15 - Trusted Zone: http://*.wedisk.net
    O15 - ESC Trusted Zone: http://*.update.microsoft.com
    O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} -

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Wonkyo Jung\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. ihatetrojan

    ihatetrojan Private E-2

    Hi, thank you so much for your help.
    I am on the deleting from the Temp file step and I was wondering if I'm supposed to delete everything in the folder (including folders) manually?
    Also, I accidentally downloaded the new java when I uninstalled the older version..
    I uninstalled Cleancop, then it came back after reboot so I uninstalled it again.
    When I rebooted after the Norton Removal, the computer got stuck in the Welcome page so I had to manually turn the computer off and on go to safe mode and ran the removal the second time and the reboot worked then.
    Same thing happened after avenger and the computer failed to reboot by itself.
    Also, before I got your reply, I ran Superantispyware, trend micro, and anti-malware because the computer was getting worse and tried to delete the virus and they failed to delete a rooktit agent and a trojan virus. Whenever I clicked quarantine and remove on Superantispyware, there would be a warning saying system authority is turning off the computer because of DCOM Server Process Launcher..
    I was wondering if this will help and as soon as i get the reply about deleting the files, I'll post the mgtool log.
    I'll post the avenger log now since I have it.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can delete everything or just delete the files as requested. Anything in the Temp folder is not needed. That is why it is a Temp folder. ;)

    Until I see new log from MGtools, we cannot continue. I know you are anxious to get your PC fixed but per our instructions in the beginning of the READ & RUN ME, you should not be doing anything that we do not request. Also to avoid the additional delays, you should have just followed my instructions which said delete all files in that temp folder. If I was worried about folders I would have said delete all files and folders. ;)

    Also please do the below.



    Please double-click the RootRepeal.exe previously downloaded.
    • Select File then Scan
    • On the Select Drives form select drive C by "ticking" the box for drive Cand click OK
    • When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
      • C:\WINDOWS\system32\drivers\UACyaiwjvcpsxtqpvu.sys
    • reboot your pc!
    After reboot, download/install/update and run the scanning tools you couldn't run!

    Now run Malwarebytes and first update it. Then run a new scan. Attach the log.
     
    Last edited: Jun 21, 2009
  5. ihatetrojan

    ihatetrojan Private E-2

    I deleted everything in the temp folders. (sorry.. I'm just horrible with computers and I didn't want to have misunderstood you and do something stupid)
    I ran the MGtools, root repeal and did what you said, updated malwarebytes and did a quick scan and attached the log.
    The avenger log is just the one I put up on the post before.
    Also my date and time on the computer says 5/22/09 and an hour early.. It's always been like that and I'm wondering if I should fix that.
    Again, thank you so much for using your busy time to help me. I really appreciate it.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Malwarebytes log shows that you took no action. Did you fix what it found? Check again. You need to make sure you fix the problems, BEFORE saving the log.

    Don't know why you would leave it incorrect! ;)

    Now let's continue.

    Are the below all things you knowingly installed?
    O4 - HKLM\..\Run: [ezautodesk] C:\Program Files\ezautodesk\ezautoupdate.exe
    O4 - HKCU\..\Run: [Fileguri] "C:\Program Files\Freechal\Fileguri\Fileguri.exe" PathFileguri /background
    O4 - HKCU\..\Run: [DonkeyLotto] C:\Program Files\DonkeyLotto\LottoUpdate.exe
    O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe


    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.




    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program


    Now run avenger.exe by double-clicking on the EXE file saved to your Desktop in the previous fix.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 23, 2009
  7. ihatetrojan

    ihatetrojan Private E-2

    I heard that changing your time and date prevents ur computer from getting infected by certain viruses so that's why I had left it..rolleyes
    The programs you indicated.. Virtual Expander is a program from a flash drive that I use so it shouldn't be any problem. The other two, my sister had downloaded and I have removed the program so I don't know why they are still left on the computer.
    I moved all the files and folders to my documents and left only the icons for running programs.
    I re-scanned with malwarebytes first and will attach the log again.
    Also avenger and mgtools are attached.
    A lot of the symptoms seems to be disappearing but the internet explorer randomly goes "back" as if I had actually clicked the back button.
    Thank you so much for your help. :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay so we will remove them while doing the next fix.

    Uninstall the below software:
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [Fileguri] "C:\Program Files\Freechal\Fileguri\Fileguri.exe" PathFileguri /background
    O4 - HKCU\..\Run: [DonkeyLotto] C:\Program Files\DonkeyLotto\LottoUpdate.exe

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now see if you can run ComboFix per the instructions in the READ & RUN Me

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\combofix.txt if you were able to run ComboFix
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. ihatetrojan

    ihatetrojan Private E-2

    Hi, combofix actually ran this time and I got the log for it.
    Thank you again for your help and everything seems better except for the occasional "back" I told you about. (it happened while I was writing the reply...)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may not be a malware issue, but let's finish your cleanup first since there is more to do now that we have your ComboFix log. I do suggest in the meantime that you try using another mouse.


    What are the below files? If unknown, delete them now.
    2009-04-12 00:59 . 2009-04-12 00:58 226864 ----a-w- c:\documents and settings\Wonkyo Jung\Application Data\SecurityPatch\SecurityPatchUnIn.exe
    2009-04-12 00:58 . 2009-04-12 00:58 2452800 ----a-w- c:\documents and settings\Wonkyo Jung\Application Data\GoodFile\SecurityPatchSetup_GoodFile.exe
    2009-04-12 00:58 . 2009-04-12 00:57 1958200 ----a-w- c:\documents and settings\Wonkyo Jung\Application Data\GoodFile\powerpc1.0_goodfile_setup.exe
    2009-04-12 00:57 . 2009-04-12 00:57 210432 ----a-w- c:\documents and settings\Wonkyo Jung\Application Data\GoodFile\GoodFileDownLoad_UnIns.exe
    2009-04-12 00:57 . 2009-04-12 00:57 246312 ----a-w- c:\documents and settings\Wonkyo Jung\Application Data\GoodFile\GoodFileDownLoad.exe
    2009-04-12 00:56 . 2009-04-12 00:56 317992 ----a-w- c:\documents and settings\Wonkyo Jung\Application Data\GoodFile\GoodFileDownLoadAgree.exe



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. ihatetrojan

    ihatetrojan Private E-2

    I use a laptop so I don't use a mouse...
    Here are the logs.
    Thank you so much for your help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can still use a mouse on a laptop. ;) Then you should look at the sensitivity settings on your touch pad. Problems like this are almost always hardware related.

    Your logs are clean but you did not answer my question about the SecurityPatch folder and files.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. ihatetrojan

    ihatetrojan Private E-2

    I deleted the security patch stuff.
    My computer seems clean! Never thought it was possible!
    Thank you so much for all your help and best of luck in everything you do.
    God Bless~
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds