Total XP virus, would be so thankful for any help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nina C., Apr 2, 2010.

  1. Nina C.

    Nina C. Private E-2

    Hi All -

    I'm currently doing battle with some variant of the Total XP virus. I ran all the steps in the READ & RUN ME FIRST post, except for Malwarebytes because it closes that program 3 seconds after I open it. I'm no longer getting the total XP popups, or (knock on wood) having the NT authority system shutdowns, but I am still having my google search results redirected.

    I am trying to upload the MGlogs.zip but it just hangs at 37% loaded and goes no further.

    Any help you can give me in fighting this virus would be so so appreciated! This is the worst virus I've ever had to fight.

    Thank you!
    Nina
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please check the size in bytes and tell me what it shows.

    Also try attaching it again. Make sure you are trying to attach the MGlogs.zip file and not MGtools.exe

    If still having a problem, try shutting down Ad-Aware and TrendMicro just while you upload and attach the file.
     
  3. Nina C.

    Nina C. Private E-2

    Thanks for the response. I am so thankful to have someone helping me.

    It's 126kb

    I tried attaching it again, tried renaming it, tried unzipping and rezipping, tried shutting down ad-aware and trendmicro. All no dice. I can upload some of the individual files, but not all.

    Can you not help me without this file?

    I still can't run Malwarebytes.

    Thanks!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a typcial normal size file.

    Not properly/completely.

    See if you can attach it to an email and send it to chaslang at majorgeeks.com

    Tell me once you have sent the email.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, which browser were you using to attach the MGlogs.zip file? If FireFox, did you try Internet Explorer or vice versa?
     
  6. Nina C.

    Nina C. Private E-2

    Ahh - thank you, it seems that it is working through IE. I did send you the email first though, so hopefully you will have it either way.

    Thank you!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you using Chrome to try and send it before? If so, in the future I suggest you use IE anytime you have problems like this.
     
  8. Nina C.

    Nina C. Private E-2

    Yes I was using Chrome and Firefox. I'll use IE for the rest of this process.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since your TrendMicro software includes and antispyware component, I suggest that you uninstall the inadequate Ad-Aware to avoid wasting resources on it and to avoid potential conflicts.

    Uninstall the below old version of software:
    Spybot - Search & Destroy 1.5.2.20

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\Program Files\Time Stand Still\MSDXM6.OCX (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Nina C.

    Nina C. Private E-2

    Hi -
    I've followed your instructions, and here are the log files.

    I don't see the search redirect happening at the moment, but I still can't launch malwarebytes.

    Thanks!
    N.
     

    Attached Files:

  11. Nina C.

    Nina C. Private E-2

    Just wanted to add that I am still experiencing the google search results redirects, albeit intermittently. This darn virus!!! Thank you!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With which browser or browsers?
    • Test all of them but make sure that the other browsers are closed while tesing any particular one.
    • Also does it happen in safe boot mode?
    • Are you sure it is a redirect? I only ask due to the fact that you said it was intermittent.
    If still having a problem, do to the below and retest.



    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  13. Nina C.

    Nina C. Private E-2

    Thank you again for your reply.

    With which browser or browsers?
    Test all of them but make sure that the other browsers are closed while tesing any particular one. It is happening in both Chrome and IE. Firefox immediately crashes any time I try to do a google search.
    Also does it happen in safe boot mode? I can't get on the internet in safe boot mode.
    Are you sure it is a redirect? I only ask due to the fact that you said it was intermittent yes. It takes me to a random new website, usually with a lot of flashing ads. I hit the back button on my browser, and then reclick the search result and it takes me to the right place.

    I completed the first two steps as you instructed me to, but it seems the virus is blocking me from the Kaspersky site - no images are showing up, nothing is clickable. I can see that the Kaspersky site is working just fine on another computer in the house - we are out of blank CDs and I don't want to infect my flashdrives, so as soon as I can find a store open today I will do the third step. (Unless you know a way to email an executable file.)

    Thank you again for all of your help. I'll write again when I've been able to complete the third step.
     
  14. Nina C.

    Nina C. Private E-2

    Following my last post, I was able to email the TDSSkiller.exe to myself, but it doesn't look like it found anything. It ran very quickly - As soon as I open it, it shows the results (screenshot attached) with a prompt line "press any key to continue" which closes the window.

    Thank you!
     

    Attached Files:

  15. Nina C.

    Nina C. Private E-2

    Just to give you an example of the google search redirects, I googled the restaurant Rao's, was redirected to this page http://www.alltheindustrials.com/search-results.aspx?keywords=tables
    when I went back and clicked the link again, I was taken to the Rao's homepage.

    It's not a consistent page that I'm taken to, but they're all similar in look and feel.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm beginning to wonder if you had one of the forms of infections that get into router hardware.

    If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.


    Let me know if that helps.
     
  17. Nina C.

    Nina C. Private E-2

    Hi -
    Just wanted to pop back in to give you an update.
    After I last posted, the virus got stronger again. It was stopping me from running any programs, endless popups, causing total system shutdowns, causing web browsers to shut down, and blocking me from the internet. I just kept persisting in running the tools you had given me. I finally was able to download a update for combofix which deleted three registry keys, and then I could finally run Malwarebytes, which was able to zap the virus.

    I am knocking on wood that it is finally gone - haven't seen any google redirects in last 24 hours or pop-ups and I've been able to run and update my antivirus program.

    Thanks again for your help with this.

    Best,
    Nina
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach these logs from ComboFix and Malwarebytes so we can see what was removed.

    There are new forms a TDSS rootkit infections going around that can cause redirection issues but your previous logs did not show signs of this infection.
     
  19. Nina C.

    Nina C. Private E-2

    Here are the logs from when I finally was able to kill the virus. TDSS never found anything wrong.

    Thanks!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you did not have a TDSS infection. ;) In fact what was removed was a rogue antivirus infection and these are new files that were not in your previous logs which is probably the reason you last said
    However you are not completely clean yet. Let's finish things off.

    First go to the C:\MGtools folder and locate the FixFA.bat file and double click on it to run it. It runs very quickly an you may just notice a quick flash of a black command prompt window.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. Nina C.

    Nina C. Private E-2

    Thanks for the response!

    Here are my logs.

    Everything seems to be working just fine now. Haven't add any problems all day today or yesterday.

    Thanks again for all your help,
    Nina
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds