4 diff threats kept popping up on browser...

Discussion in 'Malware Help (A Specialist Will Reply)' started by seablue2u, Mar 16, 2013.

  1. seablue2u

    seablue2u Private E-2

    I'm not sure exactly what caused it. I went threw all your great recovery instructions, and don't seem to have a problem now--no pop ups now. MB and TDS seemed to make the difference. Have been a MB fan a long time, and now love the others, as well. Thanks for all you do.

    Here are my logs, just to make sure you guys think it looks okay.
    Thanks,
    seablue
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not attach the requested log from Hitman Pro. Did you run it? Based on your logs you are still infected.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. seablue2u

    seablue2u Private E-2

    Sorry, just ran it. Also ran the other program, and have it saved on the flash drive. will wait to hear from you.
    sea
     

    Attached Files:

  4. seablue2u

    seablue2u Private E-2

    HEre's the second log of HM, from the purchased version. Don't know if that makes a difference.
    sea
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Continue on with the FRST instructions because you definitely still have a ZeroAccess infection.
     
  6. seablue2u

    seablue2u Private E-2

    I have a Dell Inspiron, and f8 isn't working for me--don't know why. Will f12 to boot section work the same way?
    sea
     
  7. seablue2u

    seablue2u Private E-2

    Latest HM. just in case you need it
     

    Attached Files:

  8. seablue2u

    seablue2u Private E-2

    If I go to System Recovery through the computer, rather than a reboot, it takes me to a system re install. Is that where we're heading? And is it okay to access it this way. F8 and F12 will not give me Advanced Boot Options.
    sea
     
  9. seablue2u

    seablue2u Private E-2

    Re: frst.txt file attachment

    Here's the frst.txt file. only got this running the program by itself. I need to know how to get to the System Recovery Option by some way other than f8.
    sea
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: frst.txt file attachment

    It's of no use to us. It has to be run from System Recovery.

    The only other way is with your Windows 7 Boot DVD. Do you have it? Most people do not. Let's try a different way of fixing it.


    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then right click on it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.
     
  11. seablue2u

    seablue2u Private E-2

    Would you believe i had it in my hands last week during a cleaning spree (something that rarely happens here), and now I can't find it to save my life???

    Anyway, Dell is sending me another set of them. Is that the same as the Win7 boot dvd? I made a back up recovery disk set just this evening, but wonder if it's infected as well? The machine is working good again, but i keep running all the spyware/malware programs--sometimes catching something, sometimes not. Just downloaded the beta of MalwareBytes Root Remover...says i'm clean, but I know not.

    I'm trying to back up some files (pics of 2 grandkids, and tax papers), and wonder if saving them is also saving the zeroaccess?

    Should we go ahead before i get all the pics/papers saved? Don't want to lose them if I don't have absolutely have to.

    Have downloaded CombiFix and will run it, if you think I can do so without losing the pics/papers. Will have to wait til tomorrow though to do anything else, as i'm just about cross eyed from messing with this all day and night now.
    thanks for helping me,
    sea
     
  12. seablue2u

    seablue2u Private E-2

    COmbofix wants me to disable AVG. Should I do that?
     
  13. seablue2u

    seablue2u Private E-2

    on hubby's laptop as combofix ate my local area connection on the desktop. Time Warner spent the last hour telling me my network interface card was bad. arghhhhhhhhhhhhhhhhh, i can't get to the combo file txt to give you now.
     
  14. seablue2u

    seablue2u Private E-2

    back on now, but had to restore to the sixth of March. going to bed, and hope i don't dream of any computer stuff at all. will work on this tomorrow
     
  15. seablue2u

    seablue2u Private E-2

    Re: Combofix log....4 diff threats kept popping up

    Forgot to attach the combofix log.
     

    Attached Files:

    • log.txt
      File size:
      69.6 KB
      Views:
      9
  16. seablue2u

    seablue2u Private E-2

    beginning to wish i'd never run combofix. it's been intermittent on and off ever since then. :(
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!!!! The Zero Access infection you have ate it. ;) When Combofix ran and removed the malware, this can break some services and registry entries related to your network interface. The fixes are typically quite easy. Your ISP has no idea what they were doing.

    You should have attached the log here with a different computer so that we could have continued. Doing as system restore could likely have undone everything we fixed and could have the effect you are describing with slowing down your PC.

    I'm going to need some new logs to better determine your status now after having performed a System Restore.

    Please rerun Roguekiller and attach a new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  18. seablue2u

    seablue2u Private E-2

    Before i do anything else, i have to tell you i've installed McAfee Total Protection, not the free one.
     
  19. seablue2u

    seablue2u Private E-2

    You should have told me this BEFORE i ran combofix. you only said it might turn some things off, but often rebooting again would correct this.

    I'll run RK, and the mgeek tools.
     
  20. seablue2u

    seablue2u Private E-2

    Re: New RK logs... 4 diff threats kept popping up on browser...

    The first has everything, the second has what was left after i deleted what it found.
     

    Attached Files:

  21. seablue2u

    seablue2u Private E-2

    Re: .bat file???

    don't know what or where this is. do i need to download the mgeek programs again. i did have to dl RK again. the only thing left on my machine after restore was TdssKiller
     
  22. seablue2u

    seablue2u Private E-2

    Re: getting a new set of system restore disks from Dell...

    I am getting a new set of system restore disks from Dell in a couple of days. McAfee is still blocking Zero Access infections. Will tell you when the disks arrive.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: getting a new set of system restore disks from Dell...

    Was not a good idea and per our instructions in the READ & RUN ME, you should only be doing what we ask you to do and absolutely nothing else because it make removal more difficult and could cause many other additional problems.


    Again this is not what was requested. You should not be deleting things on your own. These were normal system settings.

    System Restore would not delete the C:\MGtools folder. It should still be there.

    Of no use to us. You need a Windows 7 Boot DVD. Not reinstall disks unless you want to totally restore your PC to the way it was out of the box and lose all your personal data/files...etc. Also did your PC originally come with Vista on it? Your MBR shows as Vista. Did you upgrade to Win 7 later?
     
  24. seablue2u

    seablue2u Private E-2

    Re:Win7, never Vista

    Win7, never Vista. I received the system disks today, btw. Where does it show as Vista?

    why was McAfee not a good idea? I needed something to help quickly. I know you are all busy and can't do things quickly here, as you are helping many.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Win7, never Vista

    Sorry for the delay. Real work, real life and tax season :( have gotten in the way.

    As stated earlier, unless you obtained Win 7 Boot DVD, they are of no use to use. System Restore disks are normally just disks to reinstall back to the way the PC was shipped and you probably already have a factory restore partitin for doing this. .... Well that is unless the infection you have broke it.

    RogueKiller recognizes your MBR as a Vista MBR.

    Multiple reason:
    • We asked you not to do anything unless requested in the READ & RUN ME. As it typically only serves to get in our way and adds to confusion when unknown/unexpected files start showing up.
    • You already had AVG installed and should not have multiple antivirus packages installed.
    • McAfee will not fix your problems. Have you seen that it has fixed anything?
    I need to see a new log from MGtools to determine what is currently running on your PC.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  26. seablue2u

    seablue2u Private E-2

    all is taken care of now. thanks for your time.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds