Codec-C virus on my laptop

Discussion in 'Malware Help (A Specialist Will Reply)' started by vvvccc, Apr 24, 2012.

  1. vvvccc

    vvvccc Private E-2

    Hello everyone,
    I accidentally downloaded codec-c on my computer because I wanted to watch a video on a website. I did not realize it is a bad virus. I have tried unistalling codec C through Revo Uninstaller but it did not work. The first time I got the virus, I did a full scan with MalwareBytes but that did not detect any virus.

    Background:
    I had Norton antivirus on my computer till a few days back, but I had just uninstalled it before getting the virus. After I got codec- c and was getting ads everywhere from Facebook to the Bank of America website, I tried to install my purchased version of Mcafee on my computer, but I could not do it.
    So I tried the uninstall again in the safe mode and it worked. So I now have McAfee on my computer. I have tried everything from running a full Mcafee scan in the safe mode to doing disk cleanup but the hyperlinks and ads are not going away. I am slightly scared as I read that this is a phishing virus . Moreover I am having the problem of stuff appearing and disappearing from my desktop and other issues like a really slow computer. Another thing which I have done in the interim is upgrade my computer from Vista to Windows 7, but that seems to have made matters worse, since I have lost the restore point of one month back where I can go back.My computer is very old and weak. It is Intel Core solo and is an Acer timeline model.

    I am attaching my logs in the next post.

    Really appreciate your help.
     
  2. vvvccc

    vvvccc Private E-2

    So my problem is that I cannot access the combofix download. I tried the cnet version of combofix but it says that my system is Windows 7 and it is an incompatible OS. I have already run MBAM and SuperAntispyWare and I am attaching the logs here. Should I go to the next step without trying combofix or wait till I can get it to run?

    I am also attaching the MBAM log from when I first ran it about 10 days back in case it is relevant.

    Thanks for the help.

    PS- combofix link http://www.bleepingcomputer.com/download/anti-virus/combofix is the one I am trying to access. I am not able to get to the download link at all. Is it just my laptop or is it affecting others too?
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The instructions want you to continue on if one step doesn't work. So just continue and get me the C:\MGLogs.zip.
     
  4. vvvccc

    vvvccc Private E-2

    Here are the rest of my files.

    Root repeal also did not run as it said my system is incompatible, but it created a crash report which I am attaching.

    Thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like the scans took care of the malware. However, we can clean up a few things:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now clean out this folder, esp. these files:
    Code:
    C:\Users\pragya\AppData\Local\Temp\"
    53Z0QMAC.TMP  22 Apr 2012              "53z0qmac.tmp"
    6QFL4KWX.TMP  22 Apr 2012              "6qfl4kwx.tmp"
    8D0FCD~1      24 Apr 2012              "8D0FCD23-D809-4E26-948A-C4BF83129A67"
    9ULT0CWD.TMP  22 Apr 2012              "9ult0cwd.tmp"
    BTN%CO~1      24 Apr 2012              "BTN%Copy%1"
    CRX_75~1      25 Apr 2012              "CRX_75DAF8CB7768"
    ctm1dd6.tmp   22 Apr 2012      329320  "ctm1DD6.tmp"
    ctm23d0.tmp   22 Apr 2012       62857  "ctm23D0.tmp"
    ctm6c24.tmp   22 Apr 2012      329320  "ctm6C24.tmp"
    ctm71c1.tmp   22 Apr 2012       62857  "ctm71C1.tmp"
    ctmbb5b.tmp   25 Apr 2012        3068  "ctmBB5B.tmp"
    DNKBQM0W.TMP  22 Apr 2012              "dnkbqm0w.tmp
    IS1598~1      25 Apr 2012              "is1598539481
    Tell me how things are running now.
     
  6. vvvccc

    vvvccc Private E-2

    I could not locate two of the files, specifically

    IS1598~1 25 Apr 2012 "is1598539481"
    ctm6c24.tmp 22 Apr 2012 329320 "ctm6C24.tmp"

    Also there were two files which I could not delete from the folder one said this file is open in chrome and the other said it is open in windows explorer but I could not delete them even after closing the said windows.

    etilqs_r3UYpThhLeKFcc0
    FXSAPIDebugLogFile.txt

    A third folder reappeared right now when I opened temp to view which files were left by the name of "ZGTemp" which had one file "files.mct"

    The hyperlinks are not present right now. But I will update you in day or two because like the other user, my hyperlinks and ads disappear and then reappear in some time.

    Many many thanks for helping me with this.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how things are running after a while. ;)
     
  8. vvvccc

    vvvccc Private E-2

    My computer is functioning alright so far. But I had an unauthorized transaction on my bank account today. How bad IS this virus?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to use a different computer and change your banking log in info.

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds