Help needed!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by grove93, May 17, 2011.

  1. grove93

    grove93 Private E-2

    I dunno how my computer has become infected but it all started while I was surfing the web.....it kept accessing random sites and that was when I knew something was up with my pc. I`ve read the READ FIRST post and `ve downloaded SUPEAntiSPyware..After installing it I performed a scan( i`ve attached the log) and quarantined the threats that have been found....After rebooting my PC my internet wasn't working, so I clicked the option REPAIR THE BROKEN CONNECTION from superantispyware.....To my amazement, my internet still didn't work so i resorted to removing the threats from quarantine......Can anyone help me?:)
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    So do you have an internet connection again since dequarantining items found by SAS? :confused If not you will have to use another computer to download tools needed.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Then continue with the below:

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. grove93

    grove93 Private E-2

    I'm just scanning my computer with malwarebytes(tdsskiller didn't found anyhing i`ll post the log later)and it has found some infected files...... I would gladly put those files in qurantine but how do I know that they are critical in windows functioning??? Because if they are and I deleted them or put them in quarantine then my computer could become worse than it already is??
     
  4. grove93

    grove93 Private E-2

    srry for bumping i coudn't edit my post....so i`ve done a scan with mba and quarantined all the items and again the internet didn't work.....had no other choice but to dequarantine them....what can i do as i can't remove the malware w/o damaging my ie connection??

    ps. i put the log from tdsss and mba
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue on with the rest of the Read and Run Me first procedures ;)
     
  6. grove93

    grove93 Private E-2

    Well, i ran combofix , which scanned and deleted the infected files....All is well, but after that the internet didn't work again so I used system restore.......Could please tell me how to repair my internet connection after the removal of the malware because there I see no point in scanning and cleaning the files with diff programs and then having to dequarantine them??

    ps.. here`s the log from combofix
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You see no point in running scans, however I need to see results from the scans in order to help you. If I send you off to the networking forum to further discuss your connection issues they may see that you are not finished up here and request that you do before they continue to help you. ;)

    Another example, had you not included the log I just asked you to attach I may not have seen how to repair your connection but now I think I do.

    I still however need to see the C:\MGlogs.zip from running C:\MGTools.exe
     
  8. grove93

    grove93 Private E-2

    Here is the log from mgtools....thanks a lot for using your free time to help us solve our problems:D

    off topic: are there any sites from where you can learn more about registers, keylogs and similar stuff so that you can understand them better?? :)
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    From now on you need to follow my instructions, do not go and run system restore again! It is creating more work :)

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:61111
    F3 - REG:win.ini: load=C:\DOCUME~1\Eu\LOCALS~1\Temp\csrss.exe
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKLM\..\Run: [conhost] C:\Documents and Settings\Eu\Application Data\Microsoft\conhost.exe

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Eu\Application Data\dwm.exe
    C:\Documents and Settings\Eu\Application Data\Microsoft\conhost.exe
    C:\DOCUME~1\Eu\LOCALS~1\Temp\csrss.exe
    C:\Documents and Settings\Eu\Application Data\7DDA.689
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Microsoft Firewall 2.9"=-
    "conhost"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Do you recognize these DNS servers as belonging to your ISP? It is a Romanian domain...

    • O17 - HKLM\System\CCS\Services\Tcpip\..\{68BFBF3D-5B3E-4C2C-B5A3-8EA5278A996A}: NameServer = 82.76.253.125 81.196.170.20

    You did not download and install Ccleaner as per the instructions so please do so now and run it as specified.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  10. grove93

    grove93 Private E-2

    i did the steps you requested me to take and again the internet didn't work so i resorted to system restoring even though you advised me against it......here are the logs from combofix and mgtools...Isn't there a solution to replace the corrupted files so that the internet will work?

    ps. actually i`ve installed and run CCleaner but after i`ve used system restore so maybe that's why it ddin't appear installed.....
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm sorry but you cannot continue to use system restore! There is a proxy server we need to fix and you still did not answer my question about the 017 line. When you are ready we can begin a fix again, but you must NOT use SR as it undoes all my progress. You may think we are not making progress but we could do if you give it a chance.
     
  12. grove93

    grove93 Private E-2


    i know that i have a proxy srv that keeps redirecting me...and the reason i use the system restore is because i can't think of any way of making my internet work again after the scans.......well i am from ROMANIA an registered to that ISP so i guess that nothing is wrong with O17........
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, thanks for answering about the 017 line.

    Try this then:

    Proxy Server - Changing Settings


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "conhost"=-
    File::
    C:\Documents and Settings\Eu\Application Data\Microsoft\conhost.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  14. grove93

    grove93 Private E-2

    i have done what u said and now my internet seems to work fine, just not on IE (i am currently on FF)..And my AV hasn't detected anything this time so I guess that there's no more malware on the comp...thanks a lot

    here are the logs from combofix and mgtools....Also, could you tell me how to fix IE (would installing the newest version fix the problems?)
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:52202 <--- Fix this if you did not set the proxy yourself.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKCU\..\Run: [Microsoft Firewall 2.9] C:\Documents and Settings\Eu\Application Data\WMPRWISE.EXE

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Eu\Application Data\WMPRWISE.EXE
    Folder::
    C:\Documents and Settings\Eu\Recent(2)
    C:\Documents and Settings\Eu\Recent(3)
    C:\Documents and Settings\Eu\Application Data\7DDA.689
    C:\cmdcons(2)
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Microsoft Firewall 2.9"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  16. grove93

    grove93 Private E-2

    I have done what you requested and now my IE and FF both work well , but my IM (yahoo messenger) doesn't work at all.....APart from this everything works fine
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Documents and Settings\Eu\Application Data\7DDA.689
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  18. grove93

    grove93 Private E-2

    i took those steps succesfully, but yahoo messenger won't work...Oddly enough my skype works perfectly which prompted me to think that maybe YM was corrupted....so i reinstalled it but still no luck

    On another note my AV keeps finding viruses in :C\system volume information\_restore.... I'm guessing that they are parts of viruses left from the previous system restores, so it must be safe to quarantine them,right?
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will only be able to remove the infections in your restore points by toggling system restore. And frankly, I have always found YM to be buggy.

    Your logs are clean. If you want, post in the software forum for help with YM.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  20. grove93

    grove93 Private E-2

    Thank you for taking your time to help me get rid of the malware ...As for the YM i have adressed my problems at the Networking section of this forum
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. I will look at your thread in networking, and if necessary, move it to software since few members post in the networking forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds