help with malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by charon2112, Jul 19, 2010.

  1. charon2112

    charon2112 Private E-2

    Hello, I have some kind of malware that works when I reboot. I see a command line window flash quickly, and then 3 or 4 chrome windows will open, all pointing to some 'linkbucks' site. I did all of the 'read & run me first' steps (at least all of the ones I could run with 64-bit windows 7). Below are the logs.

    Thanks very much for any help. :)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the log from running C:\MGTools.exe --> C:\MGLogs.zip
     
  3. charon2112

    charon2112 Private E-2

    MGTools wouldn't run. It said it was incompatible with a 64 bit OS.
     
  4. charon2112

    charon2112 Private E-2

    sorry, it seems to have worked. I got an error message about time.exe being incompatible.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any AV program installed on this system?
     
  6. charon2112

    charon2112 Private E-2

    I use MSE. I know, it's a Microsoft product...but I like it. And Maximum PC gave it a very good rating.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is not showing in your Add/remove programs list. What issues are you still having, as I am not seeing any malware in your logs.
     
  8. charon2112

    charon2112 Private E-2

    I see it when I go to 'add/remove programs'. My problem is the same as my first post, on boot up, I see a quick flash of a command line window, and then 3 or 4 browser pages pop up with obvious crap pages, like porn or 'make $$ quick'. It's annoying, but I'm more afraid of what the virus may be doing that I don't know about.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download Counterspy which should work on your system. Attach the log after you run it.

    I am going to suggest that you uninstall Chrome, since we are not seeing any specific malware in your logs.
     
  10. charon2112

    charon2112 Private E-2

    Thanks a lot for helping me with all this Tim. I really appreciate it. I ran Counterspy, and it found and quarantined a trojan. But I can't seem to get access to the logs. They're at "C:\Documents and Settings\All Users\Application Data\Sunbelt\AntiMalware\Logs", but my PC won't allow me to access the 'application data' folder. I am the administrator on the PC so I'm not sure what that's all about. Could that be part of the trojan?
     
  11. charon2112

    charon2112 Private E-2

    I saw the file location for the command line window that flashes when I reboot. It looks like the file location for it is "C\Windows\SysWOW64\cmd.exe". Is that the virus? Should I attempt to delete that?

    Sorry for the double posting, I would have just edited my previous post, but I don't see an 'edit post' button anywhere.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The command prompt window is likely due you having the below running in your startup list and you do not have AVG installed.

    O4 - HKLM\..\Run: [AvgScan] C:\Windows\system32\AvgScan.bat

    Delete this startup and see if the problem goes away.

    And DO NOT touch C\Windows\SysWOW64\cmd.exe as it is required by Windows. It is the command shell.
     
  13. charon2112

    charon2112 Private E-2

    Thank you...I don't see that file in explorer though. And I do have 'show hidden files' enabled. Could it be hidden in another way?

     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    What issues do you still have?
     
  15. charon2112

    charon2112 Private E-2

    That line is no longer there. I actually deleted it using the CCleaner startup tool. I rebooted and didn't get the popups, so maybe that worked?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds good to me.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  17. charon2112

    charon2112 Private E-2

    Done and done...
    Thanks Tim and Chaslang for all your help... I really appreciate it. :)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds