Continued Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by deby0021, Oct 11, 2010.

  1. deby0021

    deby0021 Private E-2

    Thank you for your help.

    I have run the programs according to the READ ME First post and attached the necessary files.

    Upon starting Internet Explorer, after a minute or two a new browser window opens with an advertisement. I am also having network connection issues. At times, wireless configuration shows no connection but I can access internet for a time. Then I have no access.
     

    Attached Files:

  2. deby0021

    deby0021 Private E-2

    Final log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any Anti-virus software on this system?

    I see you ran TDSSKiller on the 9th, please run it again and attach that log.

    While you are doing that:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    c:\documents and settings\Administrator\Start Menu\Programs\Startup\olezo.exe
    C:\Documents and Settings\All Users\Application Data\05cgy0.dat
    C:\Documents and Settings\valued customer\Templates\8s32
    C:\WINDOWS\Ghotofiwupuc.dat
    C:\WINDOWS\Mteyutil.bin

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * TDSSKiller log
    * C:\MGlogs.zip
     
  4. deby0021

    deby0021 Private E-2

    I have AdWatch Live for virus protection. Upgrade?

    Files attached.

    Thank you for your quick response.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run TDDSKiller before or after the MGLogs?
    If you ran it after, did you reboot between TDDSKiller and running MGLOgs? It is still indicating an MBR infection.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  6. deby0021

    deby0021 Private E-2

    I did run MG logs after TDDS.
     

    Attached Files:

  7. deby0021

    deby0021 Private E-2

    think rebooted, not 100%. Repeat?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can fix this without going into the Recovery console.

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now if you wish to continue and fix the malware - please do the following:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..
    Now repeat it for physical drive 1.

    Now please re-run MBRCheck.exe and attach that log also.
     
  9. deby0021

    deby0021 Private E-2

    Thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nope, that didnt do it. Do you have your xp cd?

    You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    The re-run MBRCheck and attach the log.
     
  11. deby0021

    deby0021 Private E-2

    Do not have CD, will have to track one down.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As long as it is the same version of your...ie: Home or Pro. ;)
     
  13. deby0021

    deby0021 Private E-2

    My computer has recovery on the hard drive and did not come with disk. Setup windows recovery console. Selected at startup. I get a blue screen " A problem has been detected.." yada yada
    -Check for viruses, remove newly installed hard drives, check hard drive config. Run chkdsk /f

    *** STOP: 0x0000007b (0xF7CAF524, 0xC0000034, 0x00000000, 0x00000000)


    Is this a valid way to setup the recovery console?

    Should I track down the disk (XP Media Center)?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, if you can find someone to borrow it from. That would be the best way to go.
     
  15. deby0021

    deby0021 Private E-2

    I asked a co-worker who does IT as well about getting a copy of Media Center. He told me to try another MBR utility that he uses. I did that, ran MBCheck, and the report looks clean. I am attaching it with the rest of the recent programs runs according to the READ ME post.

    What do you think?
     

    Attached Files:

  16. deby0021

    deby0021 Private E-2

    other logs
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would love to know what tool you used to fix the MBR infection. Some of our tools ( such as MBRCheck ) are not addressing these newer infections.

    Tell me what issues you still have, if any.
     
  18. deby0021

    deby0021 Private E-2

    Things so far are running well. The computer ended up doing a full recovery but saved all my data. Don't know if that was because of the MBR program or something dumb I did. I haven't updated anything until I got the all clear from you on the reports.

    The program was MBR Wizard. I downloaded it from here: http://mbrwizard.com/download.php
    At my buddy's suggestion, I used the 2.0 version since I am on an older OS.

    If I have any continuing issues, I will let you know. Thank you for all the help. Is there a donation area?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do let me know if you have any other issues. And thank you for that link. I will test it out very soon!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds