Don't know what is happening

Discussion in 'Malware Help (A Specialist Will Reply)' started by blackprophet, Feb 8, 2010.

  1. blackprophet

    blackprophet Private E-2

    I think I have a problem with my hard drive but I think I have a spyware problem too. Windows wasnt loading and now that I got it loading it is super slow. Combofix is not working for me. I ran TDSKiller instead. Logs are attached.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happens when you try to run ComboFix?

    What are these:
    C:\33.js
    C:\44.js
    C:\66.js

    Please use windows explorer to find and delete:
    C:\Windows\temp\lpksetup-20100207-225933-0.log
    C:\Windows\temp\lpksetup-20100207-225958-0.log
    C:\Windows\temp\lpksetup-20100208-202520-0.log
    C:\Windows\temp\lpksetup-20100208-202656-0.log
    C:\Windows\temp\SEP7B49.tmp
    C:\Users\Lawnchair\AppData\Local\temp\02082025000011f0na1bd3no3a
    C:\Users\Lawnchair\AppData\Local\temp\{0B34EA0B-F555-425A-8AD6-E8DB95ADA6E8}
     
  3. blackprophet

    blackprophet Private E-2

    It just freezes and wont continue.

    I have no Idea. I didn't put them there.

    Done.
     
  4. blackprophet

    blackprophet Private E-2

    I was able to run combofix last night after i followed your previous instructions. I will add the log below.

    Also I have been getting random porn coming through my speakers (just the sound). I Don't have any porn on my computer.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    c:\windows\system32\emp66.exe

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. blackprophet

    blackprophet Private E-2

    Deleted it.

    Everything is working the same. My routine virus check ran and found a file. And when I investigated I found a bunch of folders in my IE5content folder that are filled with porn. I didn't put them there. Wish I had saved the file path cause I don't think I could get back there again.

    Log below.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run CCleaner to remove your temp internet files. Afterward, open IE and click on tools / and on the general tab, click on settings / view files and then choose them all and delete what is left.

    Then use windows explorer to find and delete:
    C:\33.js
    C:\44.js
    C:\66.js
    C:\77.js

    Now find this folder and delete anything that is in it:
    C:\Users\Lawnchair\AppData\Local\temp\LOW

    Now go to start / run / and in the run box, type:
    cleanmgr
    hit enter.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. blackprophet

    blackprophet Private E-2

    The random porn noise hasn't come back in a while. If I knew where that foolder was, I would check it, but alas I didn't save it.
    Seems like the computer is working all good now. The logs are attached below.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. blackprophet

    blackprophet Private E-2

    I have a question about this step. I am interested in buying the full version of SUPERAntiSpyware. But I also want to move to Comodo Antiviruse. Will these cause a conflict (because they are both active spware scanners)? If I wanted to buy SUPERAntiSpyware, what AV would you recommend? What AV is the best in your opinion?

    Thanks for all your help!
     
  11. blackprophet

    blackprophet Private E-2

    Damn! The random sounds are still happening. But this time they weren't porn, they were ads and music. that 99.js file keeps coming back as well.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you re-scan with the tools and attach new logs. You were either re-infected or I missed something.

    I don't suggest you purchase anything, but to answer your question, one is an anti-spyware and the other an anti-virus, so no conflict.
     
  13. blackprophet

    blackprophet Private E-2

    Here are the logs. As always RootRepeal doesnt work for me.

    I dont think its a reinfection, but thats just me (What do I know :p). The files you had me delete, most of them have had new versions come back. Also the compute has had the box come up as if it was trying toconnect to a new website. But no browsers are open. Thanks again.
     

    Attached Files:

  14. blackprophet

    blackprophet Private E-2

    Here is a copy and paste of the virus message I told you I got (I got it again while running the SUPERAntiSpyware scan. (I followed the link they gave this time and it doesn't seem to be there. It came up multiple times during the scan for different files.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    None of the files we removed were back. Plus your notification message is reporting a file in your temp internet files. Which means, along with the ComboFix log showing a new infection of a system file, you did get re-infected. You need to make sure you clean out your temp internet folders and keep your AV and AS programs up to date.

    Your logs are clean.
     
  16. blackprophet

    blackprophet Private E-2


    I'm sorry if I wasn't clear. You told me to remove those files. later I found a file called 88.js, 99.js and so on. Same with you told me to remove a file called emp66.exe. I just found files called emp77 and emp88. But they seem to be staying away now.

    I appreciate all your help. And I will be converting to Comodo after this post. Thanks again!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Just let me know if any of them do return. And do be careful about where you go and what you click on when you are surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds