Antispyware Virus -

Discussion in 'Malware Help (A Specialist Will Reply)' started by randyh43, Aug 27, 2010.

  1. randyh43

    randyh43 Private E-2

    Dear Majorgeeks,

    Need your help with a virus.....
    I ran through the Read and run me first.....The computer seems to be stable upon reboot however wehn I reboot I keep getting a run .dll error Error loading C:\windows\kbiptap.dll
    Attached please find my SASlog.txt, Malwarebytes log, Root Repeal log and MGtools log. I was unable to run Combofix - while it was running it kept rebooting the computer.
    The virus I had or have is Antispyware Doctor virus.

    ** When I ran Superantivirus and Malwarbytes I'm certain both programs found infected files because I saw them and I clicked next and it moved them to the quarantine and deleted them etc. however it seems that both programs did not create a log file with todays date which is when I ran them.

    Thanks,
    R.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are more than 4 months out of date with your copy of MGtools. You should not be saving old copies of it or ComboFix. Please do the below.
    1. Uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. Go to add/remove programs and uninstall HijackThis.
    3. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    Now uninstall the below:
    Ask Toolbar
    AVG Anti-Spyware 7.5 << this was discontinued a long time ago
    Java(TM) 6 Update 4

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now download MGtools and save to your Desktop and run it per the instructions in the READ & RUN ME. Attach the new MGlogs.zip file.
     
  3. randyh43

    randyh43 Private E-2

    Thanks for your quick reply. I followed all of your steps. All went well except I could not find the program Ask Toolbar to remove it. All the rest went ok.

    Attached is the new MGlogs.zip file. awaiting your instructions.
    Thanks again, :)
    R.
     

    Attached Files:

  4. randyh43

    randyh43 Private E-2

    Dear Majorgeeks,

    Some events today: -
    1.Discovered my computer clock was off by one month. This was the reason why we were getting logs with dates in July instead of June. Corrected this.
    2.While entering Internet Explorer browser it began to redirect me to ad sites ( this did not happen before.) My home page comes up but followed by one or two ad windows. The rest of the computer seems stable even after rebooting a couple of times.
    Thx,
    R.
     
  5. randyh43

    randyh43 Private E-2

    I meant to say July instead of August in my last post....
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKCU\..\Run: [Ywacijegozuxecug] rundll32.exe "C:\WINDOWS\kbiptap.dll",Startup
    O4 - HKCU\..\Run: [newsecureapp70700.exe] C:\Documents and Settings\Randy Hernandez\Application Data\85FF56E47A00EC6EF964680063DA73BD\newsecureapp70700.exe

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 28, 2010
  7. randyh43

    randyh43 Private E-2

    Hi Guys -

    I followed your instructions below. I had no problem running analyse.exe.
    When I dragged the CFscript.txt file on top of Combo Fix it opened the program. It began to run combofix. It said " Attempting to create a restore point" then it waited about 5 minutes then it said scanning your computer this may take 10 minutes or more depending on your computer etc. then about 3 minutes after this the computer rebooted on its own. I do not see where Combofix created a combofix.txt log. It's not on my C: which probably means the program didn't run correctly.
    I accidentally ran the MGtools getlogs.bat program before running CC cleaner. I hope this did not cause too much trouble. I ran CC cleaner last.
    Attached is the MGlogs file. I don't have a combofix file to send you. Should we run combofix again? I did not get the DLL error when ComboFix automatically rebooted my computer. Hopefully it still killed the processes you had listed.

    The computer seems stable but only you guys would know if the demons are gone!

    Thanks for your help! R. :)
     

    Attached Files:

  8. randyh43

    randyh43 Private E-2

    I forgot to mention in my last post that I disabled Mcafee before running Combofix.
    R.
     
  9. randyh43

    randyh43 Private E-2

    Dear Majorgeeks -

    Some events from today Sunday - August 29th.

    Computer seems stable however Internet Explorer is still creating one or two ad windows on start up that take me to news sites. I believe you had identified these exe files that were supposed to be deleted by ComboFix but I have not been able to run combofix correctly. It keeps rebooting the computer in the middle of the process.

    Thanks, R.
     
  10. randyh43

    randyh43 Private E-2

    Sunday August 29th - more events.....

    My wife got into Facebook usinig Explorer and it seems to spawn another AntiSpyware type message saying the computer was infected if you wanted to download some AV software etc etc. - Explorer seems to still be infected.
    R.
     
  11. randyh43

    randyh43 Private E-2

    Dear Chaslang,

    Attached is another log file for Super Antispyware. I re-ran the program and found that it picked up a lot of ad tracking cookies all which pop up when using Explorer.
    Hope you can help soon. Sorry for the multiple posts on this thread but I thought it was important you knew what was happening with the computer as it happens.

    Thank you,
    R.
     

    Attached Files:

  12. randyh43

    randyh43 Private E-2

    Dear Chaslang,

    Please disregard my last SuperAnti virus attachment. It was from Friday not today. Attached is today's log with the adware cookie problem I'm still having. Again sorry for the multiple posts.
    Thanks,
    R.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay since ComboFix will not run properly, let's do this a different way.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. randyh43

    randyh43 Private E-2

    Dear Chaslang,

    I followed your latest instructions. I was able to add the below lines to the registry-I received the successful message. Mcafee blocked Avenger like it was a Trojan virus so I had to disable Mcafee to run Avenger correctly. It worked the second time I tried. Attached are the logs for Avenger and MGTools.
    On two ocassions today the computer gave me a system32 error in a small dialogue box which caused the computer to freeze. The mouse was working but when I double clicked on programs nothing would open. I couldn't even reboot without putting my finger in the off on button.
    Internet Explorer still seems to be redirecting me to other websites when for example I follow a link I found doing a search on something. It takes me to un-related sites. I still think there may be issues.
    Thanks,
    R.
     

    Attached Files:

  15. randyh43

    randyh43 Private E-2

    Dear Chaslang,

    Attached are two new log files for Super Antivirus and Malwarebytes.
    Both reported infected files. The Super Antivirus seems to be catching all adware cookies. The Malwarebytes says it caught a trojan virus called trojan.zapchast.
    Should I have not run these again?

    Thanks,
    R.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are some infections out there that are known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    After resetting your router to factory defaults and reconfiguring your network, are you still having redirects?
     
  17. randyh43

    randyh43 Private E-2

    Dear Chaslang,

    I assume my modem is the same as a router so I reset it like you instructed to make sure the virus hadn't infected it. I was able to reset it with no problems but it did not do anything with regards to the redirects. The redirects only happen in Internet Explorer. Explorer will bring me to my home page then it may or may not immediately open another window that goes to websites called consumerproducts.com or news at some channel .com etc.
    There is no doubt that Explorer is still infected with something. When I google for example "guitar" and get the results and I click on a link that I know to be a safe website, like for gibson.com or fender.com - explorer will redirect me to some other unknown site like the ones I mention in this paragraph. On the other hand when I do those same google searches in Flock or Safari the searches come back with links that work fine. I hope you can find what is going on with Explorer just for the sake of getting rid of whatever virus code is still in my computer. The computer is otherwise stable however I'm afraid to leave it as is knowing that over time whatever virus is left may "re-awaken".

    Thanks,
    R.
     
  18. randyh43

    randyh43 Private E-2

    Re: Antispyware Virus - Still having serious issues

    Hi -
    Although my computer is not showing overt signs of the virus it has or had, there are still problems going on that are making it freeze... The browsers are working very slowly. I have received various RUNDLL32.EXE errors in small windows. When I click ok to report the problem it sends it off and then the computer freezes up not allowing you to open programs from the desk top or to ctrl,alt, del. to get to task manager. It won't shutdown or restart either. It locks up and only turns off by pressing the off button. When I was able to finally go to task manager I noticed the system had a large of amount of processes going on. Some which I'm not certain were legitimate or not.
    Not sure where to go from here...... worried this will persist and continue to render my computer not usable...Is there anything we can do? :(
    Thanks,
    R.
     
  19. randyh43

    randyh43 Private E-2

    Tuesday - August 31st. Computer is still having issues. While in Flock received Generic Host Process For Win32 Services error related to some file called svchost.exe - Subsequently froze all browsers. I beginning to think the modem may have the virus.
    Explorer is still redirecting to strange website like Top10offers.com, bettycrocker.com etc.
    I hope you guys can still help in some way.
    Thanks,
    R.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note that frequent posting bumps your thread and can delay getting an answer. See: Don't Bump! It Only Hurts You!!!



    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Also let's make sure some old malware I saw in your old combofix log was removed in the past.


    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. randyh43

    randyh43 Private E-2

    Dear Chaslang,

    I ran through your latest instructions.... attached are the two files you requested. Let me know if you still see problems.
    I'll send you more comments tonight as I observe the computers behavior.
    As of the time right before I began your latest instructions, Explorer was still redirecting to weird websites - so was Safari.

    Thank you,
    R.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still need to attach the log from running TDSSKiller.
     
  23. randyh43

    randyh43 Private E-2

    Sorry my friends....

    Attached is the TDSKiller log I forgot to previously send.

    Thanks for the help!

    R.
     

    Attached Files:

  24. randyh43

    randyh43 Private E-2

    Other side issues that have persisted that I wanted to inform you about are -
    1. I cannot seem to be able to do a Windows update. This didn't happen before. I can't tell whether its the link that my operating system has to go to Microsofts website for updates that is invalid or if its remanents of the virus. It also doesn't work when I got to Microsofts webpage to try to the update from there. I have service Pack 2 for XP. Should I be concerned about installing Service pack 3?
    2. I have a DELL wireless keyboard that has volume controls which completely stopped working after this virus started. The keyboard types but the top controls don't work. I unplugged and replugged the USB connections and reset the keyboard and wireless base - but still have not been able to get the volume control on the keyboard to work again.
    Thank you,
    R.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I suggest you post in the software forum for additional assistance with those issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  26. randyh43

    randyh43 Private E-2

    Thank you to everyone at Major Geeks for the help with my virus problem. The computer is working normal again without the redirects and I was able to get windows to update. I'll follow your last steps....

    All the best,
    R.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds