Still having problems after running through READ ME FIRST

Discussion in 'Malware Help (A Specialist Will Reply)' started by mbroerman, Nov 15, 2009.

  1. mbroerman

    mbroerman Private E-2

    I think I may have gotten some malware after clicking on a link in an email about a week ago. When I clicked the link, it opened my browser and it went to a blank page. I thought it was just spam but shortly after my computer began running extremely slow. I ran through all the READ ME FIRST steps and the cleaning procedures for Windows XP (I ran through it all in Normal Mode, not Safe Mode)

    I have attached all the logos. I had trouble with the MGTools. I ran it from my C:// drive and my desktop, but it always stopped at the same point. I don't think I got all the way through the process, but I let it run for more than 48 hours, so I assumed it wasn't ever going to complete. I attached a screenshot of the final screen I got to. I also have HijackThis, and since that is the step the MGTools stopped on, I attached a separate log of the HijackThis scan incase the MGTools didn't complete.

    Any help would be appreciated. Thanks
     

    Attached Files:

  2. mbroerman

    mbroerman Private E-2

    Attached are the remaining logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And that is how we want it to be run. ;)

    You should only run it as instructed from C:\ It basically ran thru the most important scans. Even HijackThis was already completed. The only missing items were from scans we really don't need since your logs are fairly clean other that what was removed already. We just have a couple minor things to do.

    Your biggest issue is that you have no protection installed and you need to do something about this.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. mbroerman

    mbroerman Private E-2

    Thanks for the help... but I;m still having problems. My processes in the task manager are always running at 100% and the performance is veeeerrry slow. Also, I'm getting redirected in firefox away from certain pages (such as support.microsoft.com) and sent to a "malware removal" site called free-scanner-online.info. Then a bunch of pop-up alerts happen telling me that my computer is infected.

    I've attached another MGTools.zip and a HijackThis log (because I still can't get completely through the MGTools process). Any help would be appreciated. Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be specific! What processes are talking all of the CPU time?

    Does this also happen when using Internet Explorer.

    As stated in my previous message, HijackThis is running properly. You don't need to attach a log from it as it is already in the MGlogs.zip file.

    The only security issues I see in your logs are that you have NO PROTECTION installed. You need to install antivirus, antispyware, and firewall protection ASAP.
     
    Last edited: Nov 22, 2009
  6. mbroerman

    mbroerman Private E-2

    "Be specific! What processes are talking all of the CPU time?"\

    Something called mg.exe is always taking up CPU processes. When I am not running any programs... it it the only thing taking up CPU

    "Does this also happen when using Internet Explorer. "

    Yes! It seems like the malware is taking over browser search results. When I type URLs directly in the address bar, I can get to the proper destination. When I use the browser search in FF and IE and then click on any results (in Google or Bing), the malware takes over.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of your logs showed any such process name running. Are you sure about the name or was it not running when you got the logs? Run MGtools when this process is running. Download and use the latest version of MGtools to get this new log.

    Below is a list of what was seen running in your last logs
    Code:
        Showing Running Processes and Memory Usage                                  
        ----------------------------------------------------------------------------
    Image Name                   PID Session Name     Session#    Mem Usage
    ========================= ====== ================ ======== ============
    System Idle Process            0 Console                 0         16 K
    System                         4 Console                 0        220 K
    smss.exe                     644 Console                 0        404 K
    csrss.exe                    692 Console                 0      3,992 K
    winlogon.exe                 716 Console                 0      1,248 K
    services.exe                 764 Console                 0      4,096 K
    lsass.exe                    776 Console                 0      1,488 K
    svchost.exe                  940 Console                 0      8,068 K
    svchost.exe                 1032 Console                 0      4,656 K
    svchost.exe                 1132 Console                 0     23,324 K
    svchost.exe                 1256 Console                 0      3,920 K
    svchost.exe                 1508 Console                 0      4,360 K
    explorer.exe                1624 Console                 0     20,852 K
    spoolsv.exe                 1764 Console                 0      6,692 K
    Support.exe                 1916 Console                 0      4,276 K
    DSentry.exe                 1924 Console                 0      2,676 K
    Directcd.exe                1932 Console                 0      5,692 K
    iTunesHelper.exe            1952 Console                 0     11,700 K
    acrobat_sl.exe              1988 Console                 0      3,236 K
    acrotray.exe                2004 Console                 0      3,472 K
    reader_sl.exe               2036 Console                 0      3,204 K
    NotifyAlert.exe              200 Console                 0      1,396 K
    SUPERAntiSpyware.exe         212 Console                 0        612 K
    ctfmon.exe                   232 Console                 0      4,144 K
    DLG.exe                      316 Console                 0      3,276 K
    OSA.EXE                      340 Console                 0      3,940 K
    qbupdate.exe                 356 Console                 0      8,568 K
    svchost.exe                  540 Console                 0      3,648 K
    AppleMobileDeviceService.    620 Console                 0      2,828 K
    nvsvc32.exe                 1000 Console                 0      3,504 K
    svchost.exe                 1648 Console                 0      5,244 K
    wdfmgr.exe                  1884 Console                 0      2,344 K
    iPodService.exe             2108 Console                 0      4,572 K
    alg.exe                     2380 Console                 0      3,880 K
    wuauclt.exe                 2884 Console                 0      4,308 K
    rng.exe                     3632 Console                 0      1,388 K
    MGtools.exe                 2760 Console                 0      5,460 K
    cmd.exe                     2848 Console                 0      2,560 K
    ntvdm.exe                   3068 Console                 0      2,964 K
    tasklist.exe                3584 Console                 0      4,840 K
    wmiprvse.exe                 364 Console                 0      6,084 K
     
  8. mbroerman

    mbroerman Private E-2

    I got it fixed. Thanks for all your help. I think it had something to do with that "mg.exe" file/process that was running. I ended that process and then did scans with McAfee, Avira, Malwarebytes, and SuperAntiSpyware. It found a couple of viruses and unwanted items.

    I think because mg.exe was running, that the virus scan couldn't see it cause it was in use. I don't know why you couldn't see it in your "process report". As soon as I quit it, ran the scans and restarted, the problem cleared up.

    Thanks again for all your help.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I can say is that it was not in the process list in your logs so it was not running at the time of your last scans. If you could see it yourself, those logs would also show it since it would not have been a hidden process if you could see it.

    And without seeing logs from the last scans that you ran with McAfee, Avira, Malwarebytes, and SuperAntiSpyware, I cannot comment on what they found. They could have just been things in quarantines or system restore that we already previously removed especially if you had not complete all of my final instructions given in message # 3.

    Also note that if you have both McAfee and Avira installed, you need to uninstall both of them now and then reboot. After reboot, only install one antivirus.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds