Another classic Malware attack...

Discussion in 'Malware Help (A Specialist Will Reply)' started by miguelitos, Apr 24, 2012.

  1. miguelitos

    miguelitos Private E-2

    Howdy,

    Tried the lot, now here's a hijack this...


    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 7:03:58 PM, on 4/15/2012
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal


    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.


    And the Combofix


    ComboFix 12-04-12.03 - Windows XP 04/13/2012 1:13.1.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.498 [GMT -7:00]
    Running from: G:\ComboFix.exe
    AV: AVG Anti-Virus *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
    FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

    Edit by chaslang: Inline ComboFix log removed. Logs need to be attachments.


    Thanks in advance. You guys are awesome!
     
    Last edited by a moderator: Apr 24, 2012
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Please see the instructions again. You need to ATTACH all of the logs we requested which were:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix - Note you ran ComboFix from G:\ComboFix.exe It must be on your Desktop
    • RootRepeal
    • MGtools - which is the C:\MGlogs.zip file and nothing else. This should not have been run before ComboFix. And also note that you must not be using MSconfig to control startups! You must put your PC into Normal Startup mode before running MGtools.
    We did not ask for a HijackThis log and you must attach logs.
    (See: HOW TO: Attach Items To Your Post ) ( Or View: How to Attach Items to Your Posts)

    Also you need to tell us what problems you are having?
     
    Last edited: Apr 24, 2012
  3. miguelitos

    miguelitos Private E-2

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only attached one (Combofix) of the requested logs. Please read my instructions again and attach the logs I asked for.

    Also as stated in the instructions, you MUST run MGtools.exe from the C: drive not from the G drive like you did. And ComboFix.exe MUST be put on your Desktop for possible future use. It should not be on the G drive either.
     
  5. miguelitos

    miguelitos Private E-2

  6. miguelitos

    miguelitos Private E-2

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let me repeat this again. You must run MSConfig and select Normal Startup as I stated previously and as stated in the READ & RUN ME. Do this right now. Do not continue until you do this. Reboot your PC after changing this setting.


    No please answer the below questions:
    1. How many antivirus programs do you have installed? I see signs of Avira, AVG, Comodo, Kaspersky, Norton, and perhaps others. Which ones are currently installed? Do not install anymore.
    2. Is your only problem that you cannot uninstall programs?
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.

    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    1. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • The above file will open in the notepad.
      • Under TCP/IP Primary Install section find the following: Characteristics = 0xA0
      • Edit 0xA0 and replace it with 0x80 (replace A with 8)
      • Under File menu click Save and close the notepad.
    2. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install a popup window opens.
      • Select Protocol from the list and then click Add.
      • A new window opens, click Have Disk....
      • In the browse... box type c:\windows\inf
      • Click OK.
      • Select Internet Protocol (TCP/IP), and then click OK.
      • On the Local Area Connection Properties screen select Internet Protocol (TCP/IP) and click Uninstall, and then click Yes.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    3. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • A file opens in the notepad. Under TCP/IP Primary Install section find the following: Characteristics = 0x80
      • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
      • Under File menu click Save and close the notepad.
    4. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install
      • A popup window opens. Select Protocol.
      • A new popup window opens. Select Internet Protocol (TCP/IP), and then click OK.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    5. After restart please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    6. Then attach the below logs:
      • the avenger.txt log
      • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds