Can only run in safe mode - have malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by eagleowl, Aug 24, 2010.

  1. eagleowl

    eagleowl Private E-2

    Hi

    I would be grateful for your help please.

    AMD Athlon 3800 64 x 2 dual 2.0GHz 960Mb RAM
    Win XP Home Service pack 3
    AVG9 free & Zonealarm

    Few days ago pop up for Antimalware Doctor; scanned with SAS & MBAM but had to stop process to delete one of the files found. PC clear after that.

    However, next day Google redirects even when not using Google search. Discovered proxy in Firefox and fixed. (Options, advanced, network, connection)

    Ran SAS last night; nothing found. Was going to run MBAM but too tired so decided to leave till morning. Today can only start in safe mode. Tried to change it in msconfig but no deal. Ran SAS & MBAM - nothing found but I know the file "newsecureapp70700" is there but doesn't show up. It's showing in startup in msconfig.

    Can't run Combo fix because I can't disable AVG9 in safe mode. Believe me I tried and can't uninstall it either.

    I'm running Spybot S & D as a desperate measure.

    Please can someone help? Using another PC to post this.
    Regards

    Carol
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need to see the log from it regardless. Also the log from MBAM.
    Just run it anyway, and then also run MGTools.exe

    Attach those 4 requested logs. :)
     
  3. eagleowl

    eagleowl Private E-2

    Is it ok to run Combo fix with AVG still on my pc? Thought it might be dangerous
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just go ahead and run it.
     
  5. eagleowl

    eagleowl Private E-2

    Ran Combo fix in safe mode. It found root activity after a couple of stages and I had to ok a restart. When Combo fix finished my pc started in normal mode. I then ran MGtools. Logs attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing much left to do. Combofix addressed your main issue!

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    jpapmy
    
    File::
    c:\windows\system32\drivers\qmme.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running.
     
  7. eagleowl

    eagleowl Private E-2

    Thanks you for your patience and I'm sorry to be a pain but I can't turn off nor uninstall AVG9. I thought I had stopped it before but Combo fix said otherwise. Zonealarm is no problem. Can you offer any suggestions please?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes! Follow the instructions in my last post and then attach updated logs as requested. ;) Ignore the fact that avg is not ddisabled.
     
  9. eagleowl

    eagleowl Private E-2

    Did as instructed. Logs attached.


    Carol
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this file?

    • C:\SAS_30930675.COM
    If you do not know then just delete it.

    Delete the below listed file also.
    • C:\Windows\lsrslt.ini

    Run Ccleaner.

    Did the files delete successfully?
     
  11. eagleowl

    eagleowl Private E-2

    Don't know what that SAS file was but deleted that and lsrslt.ini successfully.
    Everything appears to be fine now. I'm really careful about where I go and what I click on but I think I know how I got infected - playing an online game where the ads were too close to the game margins. Not purposely I'm sure ;). Won't be going there again.


    Is AVG9 adequate protection or should I try something else? It's certainly better than Panda that I had previously.

    Thank you so much for your help. It's greatly appreciated.

    Best wishes

    Carol
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome for the help. Now avg should be fine, I use Avast! myself and am very happy with it, but each to their own as they say. :) Safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. eagleowl

    eagleowl Private E-2

    I don't know what the SAS file is so have deleted it successfully along with lsrslt.ini. Ran CCleaner. Everything appears to be ok now. Thanks so much for your help.

    I'm thinking of replacing AVG9 maybe with AntiVir Personal. What do you think? It has antispyware included.

    Is IE8 still more secure than Firefox? I read that on this site today. If so I'll update to IE8 and change Activex settings as per instructions here.

    Thank you again for your help.

    Best wishes

    Carol
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)

    The choice is yours ;) Sounds good to me. I used to use and like avg when it was the 7.5 version, my opinion of it changed the more it updated.
    I can't really comment on that, firefox is a much more versatile browser, so more damage can be done through insecure plug-in's etc... I prefer firefox myself. You should use what you like most and feel more secure using.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds