Internet security 2012 virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by elitehak, Jun 28, 2011.

  1. elitehak

    elitehak Private E-2

    Hello,

    I have the virus redirecting my browser with all the security scams pop ups that I should register and download, and pay, that a threat has been detected, etc

    I tried following the instructions (read me first) and downloaded ATF cleaner. When i try to run it, a window appears askign with what program I want to run it with?? This is secondary effect of the malware/virus I have.

    I was able to deactivate all the pop ups, etc. by going into task manager but I am unable to run anything. I tried other programs like Outlook, i get the same window. It seems this virus de-activates the .exe files?

    Not sure how to progress from here. Should i be doign this in safe mode maybe?
    I have windows XP.
    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the below file to your Desktop. Once saved on your Desktop, Right click on it and select Install

    EXEfix

    Then see if you can run EXE files. If you can then move right back into running the READ & RUN ME FIRST.
     
  3. elitehak

    elitehak Private E-2

    Hello,

    Thanks. I have followed now all the steps in the read me file, etc.
    Problems seem to have disappeared, but I would still appreciate someone looking at my logs and providign feedback.

    4 logs are attached: superantispyware, MB, RR and MG. I was not able to do combo fix as I was not able to download the application (got a blank page)

    Thanks in advance

    View attachment SUPERAntiSpyware Scan Log - 06-28-2011 - 22-27-56.log

    View attachment rrlog.txt

    View attachment MGlogs.zip

    View attachment mbam-log-2011-06-28 (23-08-33).txt


    Hopefully everythign is ok.
    after this I will do the restore, and should I also set back msconfig to :selective start up?

    Thanks
    Eli
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I will tell you when to toggle System Restore.

    And you should never be in selective startup unless you are doing Temporary debugging and then it is only temporary. See the READ & RUN ME step 4 again.

    What are the below for?
    O4 - HKLM\..\Run: [SQ916D] C:\Program Files\SQ916D\916D.exe
    O4 - HKCU\..\Run: [InsaniquariumDeluxeSetup.exe] C:\DOWNLO~1\INSANI~1.EXE /r
    O4 - HKCU\..\Run: [Chutes.exe] C:\DOWNLO~1\CHUTES~1.EXE /r


    Are you having any problems where icons seem to be missing, or programs are missing from your Start menu, or files seem to be missing from your hard disk ( like things in Program Files )?

    Did you knowingly install Zynga Toolbar? If not then uninstall it.
    Did you knowingly install facemoods? If not then uninstall it and this program is not recommended!!!

    Uninstall Conduit Engine

    Also I recommend that you uninstall Ad-Aware. It is not that useful anymore. SUPERAntiSpyware and Malwarebytes are much better tools to have.

    Also uninstall Java(TM) 6 Update 21 and update to the current version See: Updating Sun Java


    Now delete the below files. Let me know if you have a problem finding and deleting these:
    C:\Documents and Settings\jasmin-remelie\Local Settings\Application Data\s4s3uq2wq1302a4035f3d1q82hm24dxldgkd72
    C:\Documents and Settings\All Users\Application Data\s4s3uq2wq1302a4035f3d1q82hm24dxldgkd72
    C:\aaw7boot.log
    C:\AVG6DB_F.DAT
    C:\avgun.log


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: {EA551C00-2AE5-11d3-8592-00A0C98E9EA4} - - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 29, 2011
  5. elitehak

    elitehak Private E-2

    Hi again,

    Here is the info/updates:

    1) What are the below for?
    a) O4 - HKLM\..\Run: [SQ916D] C:\Program Files\SQ916D\916D.exe --->>>>> NO CLUE
    b) O4 - HKCU\..\Run: [InsaniquariumDeluxeSetup.exe] C:\DOWNLO~1\INSANI~1.EXE /r --->>> OLD GAME THAT I HAD
    c) O4 - HKCU\..\Run: [Chutes.exe] C:\DOWNLO~1\CHUTES~1.EXE /r ----->OLD GAME THAT I HAD

    Let me know what to do with these?

    2) I unistalled Zynga, facemoods, conduit engine, adaware, and Sun Java, and re-installed newest version of Java

    3) i deleted the 5 files mentioned below
    4) fixed the 2 files with analyze.exe from HJT
    5) ran the getlogs.bat file (see attached)


    let me know how it looks. As well, let me know the next steps in terms of system restore, and msconfig.
    Thank you in advance

    View attachment MGlogs.zip
     
  6. elitehak

    elitehak Private E-2

    Sorry, just noticed something odd that I wanted to mention.

    In my tray (start up icons) I have the windows security alert disabled. It asks me to click on it and make sure automatic updates are set to on. If i do this, and try to select "on", it then says "unable, go to control panel, systems, updates, and set it to on". But when I go to control panel, systems, updates tab, the selection for automatic updates is on?

    Thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will remove them.

    facemoods to not get completely removed according to your last MGlogs.zip so we will manually remove leftovers.

    As stated already, you should not use MSconfig.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.3.61.0\facemoods.dll
    O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.3.61.0\facemoodsTlbr.dll
    O4 - HKLM\..\Run: [SQ916D] C:\Program Files\SQ916D\916D.exe
    O4 - HKCU\..\Run: [InsaniquariumDeluxeSetup.exe] C:\DOWNLO~1\INSANI~1.EXE /r
    O4 - HKCU\..\Run: [Chutes.exe] C:\DOWNLO~1\CHUTES~1.EXE /r

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you mean. There is no Start up icon named Windows Security Alert disabled ? Do you mean something under Control Panel? Please clarify.

    Do the below folders exist?
    c:\documents and settings\all users\start menu\personalsec
    c:\program files\common files\personalsecuninstall
     
  9. elitehak

    elitehak Private E-2

    Hello,

    Here are the results/information:

    1) I ran analyze.exe, and was only able to locate and fix 01, 02, and the first 04. The 04-insaniquarium and 04 slides were not listed.


    2) ran the log, see attachment
    View attachment MGlogs.zip


    I am not getting any more redirects from the browser, etc. seems to be running well.

    3) icon in the tray issue

    In my start up tray (right lower corner of the desktop, where the time is, etc.) I have an icon that looks like a red shield with a small white x on it. When I hover the mouse on top, this text box appears: windows security alert
    If I click it, a window opens called: windows security center opens
    There is 3 sections in the window: firewall : ON automatic updates: OFF Virus protection: ON It looks like the legit windows security center screen.

    Under the AUTOMATIC UPDATES section, there is a button that says: turn on automatic updates. If i press it, it says: "sorry, could not change your automatic update settings. To try and change these settings yourself, go to systems in control panel. On the automatic updates tabselect automatic (recommended), then click ok"

    Then if I do go to control panel/systems, automatic update tab, the selection to put the automatic updates is already activated and for every day at 3:00 AM ???

    Hope this is clearer.

    I will await your feedback, thanks in advance
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is more clear. I though you were talking about click the Start button, but you were just referring to the system tray icon. This is really more of a Windows problem that should be worked in the Software Forum, but I will give you a couple things to try which may correct this inconsistency. In fact have you tried going to Microsoft's Site to do check updates. It may even fail when you have an inconsistency like this. Check it out right now.

    ......... Okay I was going to post some canned fixes that I have related to Windows Update issues, but then I found the below link which seems to be the same problem you have. So I suggest you check out this link which gives a couple of procedures to try and resolve this:

    http://www.1stbyte.com/2011/06/18/windows-security-center-says-automatic-updates-are-turned-off/
     
  11. elitehak

    elitehak Private E-2

    Hi again
    Reporting back.

    1- tray icon of windows update: the link worked very well, all is fine now.
    2- computer runs like brand new !


    Last question, can i now do the system restore :)
    Thanks

    Eli
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent news. You're welcome.
    Included in the below instructions. Follow them in order.
     
  13. elitehak

    elitehak Private E-2

    Hi again,

    Just wanted to say thanks.
    Everything is working like a charm.

    I have to say that this site is amazing. Instructions are clear (like the read me first) and the support is really great ! Considering all the malware, etc. out there, and all versions of operating systems, etc. this site does an amazing job ! People just need to make sure to follow all the steps, in the right order and keep tabs.

    Other sites are sometimes to technical, missing instructions, etc. including Microsoft's !

    I have used this site a few times, it is great and will make sure to publicize it !

    Eli
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Thanks for the feedback. :)

    But I forgot to post the final instructions.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds