Went through "read and run me first," and still having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Matt_iac, Feb 4, 2010.

  1. Matt_iac

    Matt_iac Private E-2

    Hello,

    My problems started a couple weeks ago, when my computer started running very slow, and showing signs of malware. Using the tools from major geeks most of this seems to be taken care of, except for a " visa advanced verification" pop-up, which surfaces everytime an online purchase is attempted. As of now, that is the only noticeable problem with my computer (other than it seeming to run slow.)

    I went through each step of the "read and run me" process successfully, except for running root repeal. I received an error message when I tried to run this. I turned off my antivirus and firewall before doing this, so something else must be preventing it from working.

    Any help is greatly appreciated, thanks!

    -Matt
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have a Master Boot Record infection.

    Please run the below tool from Prevx

    Prevx 3.0 use the button that says Download Prevx 3.0

    After running the Prevx scan, reboot and then continue with the below.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Matt_iac

    Matt_iac Private E-2

    Thank you for the reply. I went through the steps you mentioned, and attached the logs. After rebooting my computer when the Prevx scan was finished, it attempted to scan again. It couldn't complete, saying "error: V911 cleanup not licensed..." I'm guessing that is normal, but wanted to mention it.

    Also, my computer seems to be running normally. I havn't had the visa verification popup yet, although it usually only occurs after purchasing something online (which I havn't done.) Thank you very much for the help.

    -Matt
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, PrevX did not work for you like it has for other people. So either you downloaded to wrong (not free) version or they have changed their policy on removing this infection for free. If that is the case, you will need you Windows Bootcd to boot to the Recovery Console to run fixmbr. Do you have your CD?
     
  5. Matt_iac

    Matt_iac Private E-2

    Yes, I believe I have the right CD. "Operating system product recovery CD-ROM" is what it is labeled.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure that is the correct CD. You will have to try booting with it to see if you can boot to the Recovery Console to follow the below instructions.


    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.


    If you were able to boot to the Recovery Console to run fixmbr, then now repeat the instructions in my last fix from the point of run Avenger thru to the end and attaching new logs.
     
  7. Matt_iac

    Matt_iac Private E-2

    I'm pretty sure it's the right disc. I was able to get to the recovery console by typing "R", after the welcome to setup screen appeared. In the recovery console I was asked "which windows installation would you like to log onto?" I tried to type "fixmbr" as instructed, but it would only let me type a single letter. What could be preventing me from typing a full command? At the top of the screen it said to type "exit" to quit the recovery and start windows, making it clear to me that I should have been able to type more. Any ideas?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to select the Windows installation first ( see the instructions ) before you get to a command prompt where you type fixmbr.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just incase you still don't understand. Normally most people only have one Windows installation installed and thus you would just enter 1 in response to the prompt of "Which Windows ..........."

    Then it will ask you for the Administrator password.
    Then you should get the C:\Windows> prompt

    At this prompt, you would then enter the fixmbr command.
     
  10. Matt_iac

    Matt_iac Private E-2

    Thanks for the simple instructions, I feel like an idiot for not figuring it out the first time.. Anyway, I ran the fixmbr prompt successfully. Here are the updated logs. Thanks again
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Main reasons for a slow PC are the below which shows insufficient memory to properly run Windows XP.
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 101.59 MB
    You need at least twice this (which is 1GB ) but 4 times this ( 2GB ) is much better.



    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Uninstall the below old versions of software:
    Java(TM) 6 Update 17
    Spybot - Search & Destroy 1.4

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\a132m\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. Matt_iac

    Matt_iac Private E-2

    I ran through everything you suggested, and my computer seems much more stable than it was before. I also ordered some extra RAM to hopefully alleviate my complaints about my pc being slow.

    When running TDS killer it didn't seem to find anything, as it never asked me to type in "delete." Everything else seemed to work as expected. Here are the updated logs. Thanks again.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds