Help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by beckyayala, Jul 12, 2009.

  1. beckyayala

    beckyayala Private E-2

    Hello,

    Two days ago I started receiving numerous pop-ups and pop-unders. My McAfee alerted me that Automatic Updates are turned off which I did not do. I tried to turn them back on and I still got the warning. I ran Ad-Aware SE and it picked up Win32.Trojan.Tibs. I followed the steps in AdAware and restarted, then rescanned and the trojan was still there so I went looking for ways to remove and found your site.

    I followed the steps outlined in Run First. I had no programs to remove from the Add/Remove link. I only have one version of Java. I set MSconfig to Normal Startup Mode. I emptied the quarantine folders of Ad-Aware and McAfee Security Center. I emptied the recycle bin. I ran CCleaner to remove the temporary files. I enabled the viewing of hidden files.

    I downloaded SuperAntiSpyware, Malwarebytes, RootRepeal, and MGtools. When I tried to download ComboFix from bleepingcomputer I got the following error:
    C:\Documents and Settings\Beck\Desktop\ComboFix.exe could not be saved, because an unknown error occurred. Try saving to a different location.

    I tried to download ComboFix again and got a 404 page not found error. I then found alternate download sites and got the same results when trying to download (error upon download, then 404 errors,) so I could not run the ComboFix file.

    I ran SAS, it found infections, I followed steps and upon reboot I got these errors:

    error loading C:\windows\system32\lafetupa.dll The specific module could not be found.

    error loading C:\windows\system32\zoyokava.dll The specific module could not be found.

    I then ran Malwarebytes,RootRepeal, and MGtools. They also found infections and I followed the steps.

    I am still not able to turn on Automatic Updates, but the pop-ups are gone. I believe I am still infected. Any help with this is appreciated.
     

    Attached Files:

  2. Elder_Usr

    Elder_Usr Sergeant

    Hello Beckyayala,

    We are currently reviewing over your logs, and will be back with you shortly with further instructions.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay. Somehow your thread was overlooked as needing a fix.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - AppInit_DLLs: c:\windows\system32\lafetupa.dll,C:\WINDOWS\system32\vozekadi.dll

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. beckyayala

    beckyayala Private E-2

    Hi, I didn't get the second alert that there was a new message here. Tonight my system seems to have picked up something new in addition to the others. My desktop is a weird blue color with a huge black box in the middle stating:

    Your System is Infected!
    System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed.

    Also I cannot access Task Manager, it is greyed out on the menu. And automatic updates got turned off. And I keep getting a big red X in the bottom right corner telling me to click here to download software to fix this.

    I just close the bubble for the red X when it comes up.

    Should I restart the whole process over, or just follow the steps from your last message?

    Thanks,
    Becky A
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just finish what I posted in my last message and attach the requested logs. We will decide what to do next after seeing these new logs.
     
  6. beckyayala

    beckyayala Private E-2

    I ran analyse.exe and only checked the boxes requested.

    I downloaded Avenger and ran it as requested. I clicked on the "Yes to Reboot?" but upon reboot the logfile did not pop-up. I checked the files and folders to see if they were deleted and I only had to manually delete C:\WINDOWS\system32\tupuwuku I tried to find the avenger.txt file and it is not at C:\avenger.txt. I ran a search and it did not show anywhere.

    I redownloaded MGTools and ran it and the log is attached.

    My desktop is still a weird blue with the black warning box. TaskManager is now working. There is no longer the red X on the toolbar.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we have a little more to do. This time before trying to run Avenger, make sure that you shutdown Ad-Aware's Ad-Watch and also shutdown McAfee's protection too since they are probably interfering with the cleaing proces.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101760&l=dis
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
    O4 - HKLM\..\Run: [msupdate] msupdate.exe

    After clicking Fix, exit HJT.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now try to run ComboFix again that you could not run earlier.


    Also to be safe, let's get the current versions SUPERAntiSpyware and Malwarebytes installed and run new scans.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • the logs from ComboFix if it ran
    • the new logs from SUPERAntiSpyware and Malwarebytes
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. beckyayala

    beckyayala Private E-2

    Thank you for the help!

    1. I disabled McAfee and Ad-Aware.
    2. I ran analyse.exe and fixed the requested lines.
    3. I ran Avenger and again the log did not pop-up nor can I find it on my computer. It did delete all the files except C:\WINDOWS\system32\drivers\Disk&V.sys
    C:\WINDOWS\system32\drivers\EA-Pogo.swf.sys which I manually deleted.
    4. I downloaded and ran ComboFix.
    5. I deleted SuperAntiSpyware and then redownloaded, installed and ran.
    6. I deleted Malwarebytes and redownloaded. I installed and when trying to perform the quick scan I received this error:
    Run-time error '5' :
    Invalid procedure call or argument
    I tried deleting and redownloading but still got the error when I tried to run.
    7. I ran CCleaner.
    8. I ran GetLogs.bat.
    9. I enabled McAfee.

    My desktop is back to normal, task manager works, no signs of any problems. The only weird thing is my clock is ahead by 17 minutes. It has been this way for months and everytime I try and change to the correct time it will take the change but minutes later it is back to the wrong time.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you got them deleted? The ComboFix log which I assume you ran after manually deleting them shows the below 3 files which all need to be deleted. Do any of these still exist? If so, delete them. I'm guess the .sys one will still be there.
    Code:
    2009-08-09 08:27 16 ----a-w- c:\windows\system32\drivers\EA-Pogo.swf.sys
    2009-08-09 08:26 16 ----a-w- c:\windows\system32\drivers\Disk&V.sys
    2009-08-09 08:41 16 ----a-w- c:\windows\system32\drivers\.sys
    Not sure this is related to malware but let's finish 100% of your cleanup and then see if the time will remain correctly set.

    The below file could be the Avenger log. Please attach it:
    Code:
    2009-08-12 03:00 1224 ----a-w- c:\program files\gksq.txt
    Do you use these iWin.com games I see installed? This stuff is not recommended!

    After doing the above, reset your clock and then reboot your PC.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! Also is your time correct?
     
  10. beckyayala

    beckyayala Private E-2

    I thought I deleted them and I just checked and they are not there.

    I have bought many games from iWin, BigFish, Playfirst, and Alawar. Are these games or companies not safe? Is there a safe company to download games from because I enjoy the games as a relaxer after work but I will definitely not do it anymore if they are the cause of this!

    I did the clock reset, and rebooted. I ran MGTools and attached the log. It has been 20 minutes and my clock is still showing the correct time! Everything with the system seems fine.

    Thank you again for your help,
    Becky
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One of them is still there. You need to delete the below file. Yes that filename begins with just a period.

    C:\WINDOWS\system32\drivers\.sys


    iWin games is not malware and should not be causing you any problems (hopefully). It is just a history of things like this and WildTangent games that were associated with adware and popups in the past and thus the reputation still lingers even though they should not be problems. If you use it then keep it.

    If you get the .sys file deleted then move on to the below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. beckyayala

    beckyayala Private E-2

    I finally deleted that .sys file. I completely missed the period the other times.:-o

    System is running fine so I did the cleanup and am all protected again.

    Thank you so much for all your help!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds