several viruses invected ?

Discussion in 'Malware Help (A Specialist Will Reply)' started by trazzer, Jun 30, 2013.

  1. trazzer

    trazzer Private E-2

    Hi ther, i dont know if iam right but i think mine computer is invected by iexplorer and RtkNGUI64.exe viruse. I do have legaal windows 7 but i hade to reboot with a upgrade cd w7 (polish version was bored from guy next door) so thats why it looks maybe littel strange. I noticed in task manager few times that ieplorer was runing on 5 aplications, and i hade all windows closed. I also noticed strange behive of several proces in task manger. taskhost.exe wer 3 of them runing at same time and 2 dident have a location path, same proceses without path wer csrss and 2 of them runing same time. also without a location path svchost,winlogon.exe, wininit.exe and some more. I have totaal of 3 computers invected same, cus of sharing same network with ather peopel. her are myn logs, hope u can help me and pls if u have any quastion iam waiting. I cant finde any wher the tdskiller files!

    thank u for ur time , greetings Trazzer
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs.

    Delete these if they show:

    • C:\ProgramData\Babylon
    • C:\ProgramData\BrowserDefender
    • C:\Program Files (x86)\Wajam

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. trazzer

    trazzer Private E-2

    Hi and thank u for helping me. I did run hitmanpro again only couldend delet those files like u told me. When i pres to delet them nathing was happening. her are bouth logs. thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome!

    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Program Files (x86)\Wajam
    C:\ProgramData\Babylon
    C:\Users\marcin234\AppData\Roaming\Babylon
    
    :reg
    [-HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}]
    [-HKLM\SOFTWARE\Classes\Prod.cap]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}]
    [-HKLM\SOFTWARE\Wow6432Node\Babylon]
    [-HKLM\SOFTWARE\Wow6432Node\babylontoolbar]
    [-HKLM\SOFTWARE\Wow6432Node\DataMngr]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\DataMngr]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\DataMngr_Toolbar]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\delta LTD]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Internet Explorer\Main\bProtector Start Page]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Internet Explorer\SearchScopes\bProtectorDefaultScope] 
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document into a text file and attach it here in your next post.



    now rerun Hitman again and let me know what issues remain. :)
     
  5. trazzer

    trazzer Private E-2

    Hi ther,
    oke did as u told me, only did somthing rong i think cus dident see any thing after in the green window after reboot. Iam sending u the log from hitman and ot. thank u

    can i ask u, i have two more computers invected like this, they were all conected same network cus iam a musician and use them to stream or make music. can u help me as wel with them. it one desktop and one laptop. Thank u again for ur time.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There are still two items to fix with Hitman. :)

    Let me know how you get on.
     
  7. trazzer

    trazzer Private E-2

    Oke, first thing to morrow i will do it when I come back from work. To day wasent home on time. Thank u and I will post the logs after. Have a great day.
     
  8. trazzer

    trazzer Private E-2

    Hi ther,
    He dont let me delet it. nathing hapends when i pres delet.
     

    Attached Files:

  9. trazzer

    trazzer Private E-2

    by the way i cant either unistalate norton idenity safe
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then try using Revo Uninstaller.


    Hitman will not let you delete? Then let's do it another way. :)


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Rescan with Hitman again (scan only) and attach new log
     
  11. trazzer

    trazzer Private E-2

    Hi ther,
    I hade succes message about adding to the regestry. Sending u the hitman log.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Code:
    :reg
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Internet Explorer\Main\bProtector Start Page]
    [-HKU\S-1-5-21-385320426-4037490643-2327970191-1000\Software\Microsoft\Internet Explorer\SearchScopes\bProtectorDefaultScope]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document into a text file and attach it here in your next post.


    Now rescan with Hitman again please and attach log.
     
  13. trazzer

    trazzer Private E-2

    oke did what u askd me ;) ot and hit logs, have a nice day. I think it dident work. those last are hard seems.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you try to fix what Hitman detects, what message do you get?
     
  15. trazzer

    trazzer Private E-2

    i pres on delet and dont get any massage. nathinh hapends i can pres and pres. did log again her it is
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )
     
  17. trazzer

    trazzer Private E-2

    I will do it right a way to day. Sy was a way in rl. I post the logs when it finishd.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK no problem. :) I will be here.
     
  19. trazzer

    trazzer Private E-2

    Hi ther, sy for de;ate but rl went busy. Her u have the log for the scan, thank u and wait for ather instructions.
     

    Attached Files:

    • JRT.txt
      File size:
      4.1 KB
      Views:
      1
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me how computer is behaving now. :)
     
  21. trazzer

    trazzer Private E-2

    Awsome. Real great. Starting up fast and no strange lags or ghost process activ. Thank u very much. I have still a laptop asus with same problems as dell was. Can I use the tools same way or just start a new topic. Problem was bouth computers were at the time conectid tot a home network with ather ppeople's computers. Now I have own conection. I use computers to stream life music as wel as to make prodoctions. Again thank u, u rock!! All ready posted thanks to majorgeeks site and u at myn facebook site.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. You can start a new thread for the new computer. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. trazzer

    trazzer Private E-2

    Oke to night I will do it. Thanks
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. ;)
     
  25. trazzer

    trazzer Private E-2

    oke i have done everything what was on the page. :-D
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent! :)
     
  27. trazzer

    trazzer Private E-2

    thank u:-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds