Completed READ ME FIRST, problem with background adverts with no browser running

Discussion in 'Malware Help (A Specialist Will Reply)' started by johnson501, Jul 8, 2010.

  1. johnson501

    johnson501 Private E-2

    Initially i had a problem with my sound card.. i looked for a driver and found Creative Diognostics.. this gave me the option to test my card, i tested but nothing, then i set the card back to default and it started working.. it was then i noticed adverts playing from somewhere.. found out that this is running from a corupt IEXPLORE.EXE..(even runs when no browser is open) in task manager when you end task on it the advert immediately stops.. but it reappears soon after, other symptons i have is the occasional popup in IE even though i'm not even using IE.
    any help would be very appreciated.
     
  2. johnson501

    johnson501 Private E-2

    My apologies for not adding these
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\woody\Local Settings\Application Data\rxiurlvwm
    C:\WINDOWS\Temp\100.dat
     
  4. johnson501

    johnson501 Private E-2

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 4c00ddc7732c58a1d68ef0527b90539d

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>

    I've included my combofix scans 1st one i did in order with the others but left my windows firewall running and the 2nd was earlier today without the firewall... i read in another post it may be harder to clear as i have a dell?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Do you have the OS installation disc? Or are you stuck with just the DELL System Restore partition?
     
  6. johnson501

    johnson501 Private E-2

    I have a Dell disc called drivers and utilities, it does mention changing boot sequence on it..

    thanks
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you don't have an installation disc for your OS. You have two choices. One is to hit control + F11 or 12 to get you into the restore partition ( you need to look for the exact F key as you boot up) and do a restore to factory settings or two, go ahead with our fix and risk not being able to access that restore partition in the future. If you boot to the restore partition, you will lose everything you have put on the computer since then. Which means you will need to have all your program discs to reinstall. That is why I asked if you have backed up your personal data and files. However, not doing either will make your system vulnerable to further infections.

    If you want, this is the fix to run:

    Now - please do the following:

    • Click Start, Run then copy and paste the below into the Run box and click OK.

    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0

    • Now reboot your PC and after reboot continue with the below instructions.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. johnson501

    johnson501 Private E-2

    thanks it does seem to have done the trick, i did run MGtools but had a lot of the same errors as below... it did state that a log had been created on the C drive but i couldn't find it.. did a search for it and still no luck, i'll try this again in the meantime

    C:\WINDOWS\system32cmd.exe
    C:\DOCUME~1\woody\LOCALS~1\Temp\. A Temporary file needed for initialization could not be created or could not be written to. Make sure that the directory path exists, and disk space is available. Choose 'close' to terminate the application




    thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe. Your log should be located at:
    C:\MGLogs.zip
     
  10. johnson501

    johnson501 Private E-2

    I did another scan with all virus protection off and it worked ok.. posted log below.. still no adverts and no adverse affects to date

    thanks
    if the log isn't any good i'll download again but one question what did you mean by download to root??
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Root folder is typically your C: drive.

    Your logs look good, but you need to run CCLeaner and then make sure these two folders are cleaned out:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\woody\Local Settings\temp\

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  12. johnson501

    johnson501 Private E-2

    All completed and all is working fine, many thanks to you

    Do you know how this virus infected so many? will it be stopped by current virus protection?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. As to this virus, it is spreading rather rapidly so I am hoping that the AV companies will begin to find a way to protect against this in the near future. The problem is that it is hiding in the MBR files. That makes it more difficult to remove.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds