Malware problems. SHOCKER!

Discussion in 'Malware Help (A Specialist Will Reply)' started by jham.utd, Dec 1, 2009.

  1. jham.utd

    jham.utd Private E-2

    I'm currently in the process of doing the pre thread cleanup and I followed all the steps including unchecking the 3 things that are meant to be unchecked for superantispyware. It's currently at C:\windows after going alphabetically. i checked the windows folder it has 23,000 files in it. After 45 minuets my scan is at 3,000 files. I really hope something is going wrong here, but if not, I should be back with a log in what, a month or two?

    EDIT: I also neglected to mention that it's found 0 threats, and I recently had/have antivirussystempro Trojan on my computer. I've got all the traces of THAT trojan but now my cpu constantly runs at 100%.
     
  2. jham.utd

    jham.utd Private E-2

    I can't seem to edit my last post so i guess i'll take the bump delay, but never the less, i've come up with some logs and with very little interest in staying up to run the last two scans tonight, i'll save them for tomorrow. I ran 2 malware, and SUPERantispyware searches each because i had already it once before following the guide and saw no pain in running them again, other then time i guess. nevertheless, here they all are. i'll post back sometime tomorrow with the ones i'm missing.

    Also, an update on the state of my computer, it started out with antivirus system pro but i seem to have gotten rid of that (or at least the visable parts of it). the computer is now running at a reasonable cpu % but i'm still getting some random tabs open in firefox for things like sports bettings, dish network, and "kevins blog"

    On second thought, due to only being allowed to upload 4 documents, i excluded for now the latter super anti spyware log with no traces of any errors on it. if i need to i'll throw in the clean one tomorrow with the rest of the logs.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :) I am going to be guiding you thru the malware removal process, however I still need you to attach the C:\Mglogs.zip please.

    Thanks
    Kes13!
     
  4. jham.utd

    jham.utd Private E-2

    After i let it sit for the night i turned it back on and it ran at 100% cpu again so everything i do is very slow. when i run root repeal and hit scan, it restarts my computer, should i skip it and run mgtools or should i, and i hope i dont, run all the scans again.

    EDIT: it now restarted itself after opening my computer and freezing for 6 or so mins.
     
    Last edited: Dec 2, 2009
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. Skip root repeal for now and run MGTools. :) attach the zipped logs it creates.
     
  6. jham.utd

    jham.utd Private E-2

    My computer is running so slow doing any simple thing that takes less then a second normally is taking 5+ mins. Combofix.exe has fixed that problem once, i'm wondering if it would be worth it just to run it again so i'm able to move here. would that be a bad idea?
     
  7. jham.utd

    jham.utd Private E-2

    waited quite some time to be able to get to mgtools, i hit run but nothing happends

    there is a file in c:\MGtools, if i can recall, i ran it once but the system randomly restarted at some point during the scan.
     
  8. jham.utd

    jham.utd Private E-2

    mglog attached
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  10. jham.utd

    jham.utd Private E-2

    ill do that right now, in the mean time, if these mean anything i was able to get a more complete mglog by running combofix again. here both are

    EDIT: i have shownet running but i think it might've froze, the cpu running at 100% is crippling
     

    Attached Files:

    Last edited: Dec 5, 2009
  11. jham.utd

    jham.utd Private E-2

    no error messages, here are the logs. in order to get them i had to run combofix again, that log is attached as well.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\system32\dllcache\atapi.sys| C:\WINDOWS\system32\drivers\atapi.sys 
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  13. jham.utd

    jham.utd Private E-2

    possibly useless information, but every time i turn on my computer i have to close out of MOM.exe in order for my computer to not run at 100%

    logs coming up asap
     
  14. jham.utd

    jham.utd Private E-2

    logs
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter ( the quotes are required).
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.
     
  16. jham.utd

    jham.utd Private E-2

    Like an idiot, I ran the program off of my desktop so it looks as though a log wasn't created for that scan. Things were removed on that initial scan and if it means anything i scanned it again the way you asked and it came up with nothing, here's the log.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you think it could have been MDM.exe that you could have seen?

    We do not see it running in your process list but perhaps you stopped it yourself..? Which location was it running from do you know? You could reboot and not kill it and if it is running, get a log from MGtools while it is still running and attach the C:\mglogs.zip into your next reply.

    The first run of TDSSKiller did fix some items, however I am not seeing any problems now. Are you still having malware issues?
     
  18. jham.utd

    jham.utd Private E-2

    Yeah, i'm positive. It's a part of the catalyst control center, it's running fine now and i'm having no problems. i took a screen cap of the search results however it's been on my computer for a long long time, it doesnt worry me.

    I'm having no issues at all anymore
     
  19. jham.utd

    jham.utd Private E-2

    forgot to add my screen shot
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds