Completed read and run me, logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Andria041381, Nov 26, 2009.

  1. Andria041381

    Andria041381 Private E-2

    My computer became infected somehow this week and I'm not sure how. One morning Internet Explorer had 52 pages opened and my firewall had been disabled, so I knew something was wrong. I ran and updated AVG. It found and cleaned a few things. However, within a day I realized that there was still a problem. Upon clicking a webpage link after doing a search on google or yahoo, I would be directed to an incorrect website.

    I've completed the Read and Run Me procedures and have attached my logs. Everything went smoothly. However, I didn't receive the "scanning complete" message after running MGTools. I waitied patiently for several hours, but the last message I received was "Zipping hijackthis.log adding: hijackthis.log (188 bytes security deflated 67%

    Please let me know if my logs look clean, or if I need to do anything else to finish fixing my pc.

    Thanks in advance.
     

    Attached Files:

  2. Andria041381

    Andria041381 Private E-2

    attached mglogs.zip
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The cleaning procedure took care of most of your problems. We just have a little more to do.

    Uninstall the below old versions of software:
    Ad-Aware SE Personal
    Spybot - Search & Destroy 1.5.2.20

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Andria041381

    Andria041381 Private E-2

    Thanks for your reply. I completed the tasks that you asked and attached my new logs.

    Unfortunately, I'm still getting redirected to incorrect/weird websites when following a link in google/yahoo. Any other advice is greatly appreciated.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.


    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Also please run an online scan with Kaspersky Online Scanner as instructed in the viewable process shown here. Attach the log.


    Are you still having redirect problems? If so, is it occurring with all browsers? Does it occur in safe boot mode.
     
  6. Andria041381

    Andria041381 Private E-2

    Sorry for my delayed reply. I followed your instructions and ran ATF Cleaner and Kapersky. Kapersky found several infected files/viruses. I've attached the log. I am still getting redirected to sites like luckybreaks, apartmentfinder.net, cabelas.com, searchfindsite, etc when searching using google and yahoo in normal mode and it also happens in safe mode. I use Internet Explorer browser. Should I download another browser like firefox/opera to test if it happens using another browser? Thanks for all your help so far. Please let me know how I should proceed.
     

    Attached Files:

    • kas.txt
      File size:
      1.5 KB
      Views:
      3
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is a false detection by Kapersky. They need to do their homework a little better.;)
    Code:
    C:\MGtools.exe Infected: Trojan-Dropper.Win32.Agent.bikj
    MGtools is not a threat of any kind ;)

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. Andria041381

    Andria041381 Private E-2

    The problem now seems to be resolved. I'm no longer getting redirected and the pc is running faster now. I've attached the logs you requested. Are there a few last steps I need to complete?

    On a different note, I've been receiving a message stating "Windows Virtual Memory too low" for quite some time. Would installing additional memory speed up my computer and resolve the virtual memory error?

    Thanks.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean. Yes you do need to install at least 4 times the amount of memory you now have installed. Your logs show the below
    You cannot properly run Windows XP and the other applications you have installed with so little memory. At a minimum, you need 1 GB ( this is 4 x 256 MB) but 2 GB ( this is 8 x 256 MB ) would be a better idea.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds