Assistance Needed Please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kajjajja, Nov 9, 2008.

  1. Kajjajja

    Kajjajja Private E-2

    Hey guys,

    I've had an issue for about 2-3 months now, and it's pesky. Just to let you know, I have gone through all the steps and procedures listed in the Welcome Center part of the forums. I've performed all the House Cleaning & Setup, enabled viewing of hidden files, system files and file extensions, as well as gone through the procedures based on my OS.

    I have used and followed the procedures listed for the following programs: SUPERAnti Spyware, Spybot Search and Destroy, Malwarebytes Anit-Malware, combofix.exe and MGTools.exe. I should have logs for all of them as well. I will do my best to find them and post them as instructed in the guidelines.

    Now, the symptoms are that Internet Explorer prompts me for a split second to try and make it my default browser and disappears. It does this continuously even while using other programs.

    I don't know what to call this virus or malware, so if anyone can help me I would greatly appreciate it. I also understand that help is done by volunteers who are willing to assist others with their computer issues. Thank you in advance for your hard work.
     

    Attached Files:

  2. Kajjajja

    Kajjajja Private E-2

    This is the only other log I could find. I had nothing show up in Spybot and couldn't find a log to upload.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Just to let you know we are currently reviewing your logs and will get back to you with a set of instructions as soon as we possibly can....thanks for your patience.

    Kes13! :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi


    You use Firefox and any time you use Internet Explorer it will prompt to make it the default browser...you just needs to open IE and check the NO box. :)



    1) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    File::
    c:\windows\system32\b1tbgrTn.exe
    c:\windows\system32\W8GhNGkH.exe
    c:\documents and settings\Owner\Application Data\wklnhst.dat
    
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    3) Please go to Add and Remove programs and uninstall the following software:

    • Java 2 Runtime Environment, SE v1.4.2
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7

    Now reboot your machine, and install the following most current version of Java:

    Java Runtime 6

    4) Run Ccleaner!

    5) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    Kestrel13! :)
     
  5. Kajjajja

    Kajjajja Private E-2

    Thank you for your help! I will have to get back to you and let you know if it worked. These are the logs that I have for you.

    Thanks again!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please disable all anti-virus and anti-spyware applications before we do the following:

    2) Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    So please attach the C:\avenger.txt log after doing the above.

    Thanks
    Kes13!
     
  7. Kajjajja

    Kajjajja Private E-2

    There you go! By the way, the problem seems to be solved. Thanks for your help!
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download a fresh copy of ComboFix and run it again. Attach the new log once complete.

    Finally, run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. Kajjajja

    Kajjajja Private E-2

    Hey there. Just ran Combofix (the one you told me to download) and ran the Getlogs file.

    Here are the results. Thank you.
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please attach the new log from ComboFix.
     
  11. Kajjajja

    Kajjajja Private E-2

    Here you go. Thanks for your patience.
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Pre-Instructions:
    1. First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.
    2. Print out these instructions or save them to a text file so that you can operate with All Browser Windows CLOSED.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 2:
    Next, we need to run Avenger just like you did before.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Step 3:
    Next, I would like you to go to the following website and upload the below file. Post the results if anything is found.

    http://virusscan.jotti.org/


    Step 4:
    Finally, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\Avenger.txt
    • C:\MGlogs.zip
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  13. Kajjajja

    Kajjajja Private E-2

    I can't upload the MGTool.zip because it says I've uploaded the file already to this thread.

    Also, this is what http://virusscan.jotti.org/ said:

    File: ShowWnd.exe
    Status:
    OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database)
    MD5: b8e7353996d0757e2b8f47be702074be
    Packers detected:

    This is the only information I found. No log was present.
    -
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) Please use Windows Explorer to find and delete the following folder:

    If the deletion fails let us know!

    2) Please run the C:\MGtools\GetLogs.bat file to make a new log and attach when you next reply..the MGlogs.zip will be found at C:\MGlogs.zip

    Thanks
    kes13!
     
  15. Kajjajja

    Kajjajja Private E-2

    Here you go! The folder did delete without any problems. Thank you!
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  17. Kajjajja

    Kajjajja Private E-2

    Thank you so much Kestrel13! and bjgarrick. Your help was and is much appreciated. Happy Thanksgiving to you both and happy holidays! Wishing the two of you and the rest of Major Geeks a safe and wonderful year!

    Many thanks.

    James
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi James:wave

    Your very welcome, Happy Thanksgiving to you too :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds