computer infected, help

Discussion in 'Malware Help (A Specialist Will Reply)' started by edanboro, Dec 27, 2012.

  1. edanboro

    edanboro Private E-2

    hi,
    i cant use my computer, only on safe mode,
    did everything on the sticky (except MGtools, didnt work)
    the logs are attached.
    thanks!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you elaborate on that please?

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. edanboro

    edanboro Private E-2

    i attached the OTL logs, and pictuer of the error at MGtool
    thanks
     

    Attached Files:

  4. edanboro

    edanboro Private E-2

    the name of the virus is comrepl.exe if this helps..
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rerun Hitman and have it delete Suspicious files. Also, under the heading "Repairs" have it fix this:



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : Rapid (C:\Users\WIN-7\AppData\Local\Temp\Rapid.Exe) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : Mozilla Firefox (C:\Users\WIN-7\AppData\Local\Temp\Mozilla Firefox Corporation.exe) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : pwemklicukstqwdkklq (C:\Users\WIN-7\AppData\Roaming\pwemklicukstqwdkklq.exe) -> FOUND
    • [RUN][ROGUE ST] HKCU\[...]\Run : 879328 ("C:\Users\WIN-7\AppData\Roaming\879328") -> FOUND
    • [RUN][ROGUE ST] HKCU\[...]\Run : 7247yfu4i3u4hi3hbj8 ("C:\Users\WIN-7\AppData\Roaming\879328") -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Run : kingdoms (C:\Users\WIN-7\AppData\Roaming\kingdoms.exe) -> FOUND
    • [RUN][SUSP PATH] HKLM\[...]\Run : MUZBQUE0M0Y0RUEyMEM5QT (C:\Users\WIN-7\sceff_.exe) -> FOUND
    • [RUN][ROGUE ST] HKLM\[...]\Run : 879328 ("C:\Users\WIN-7\AppData\Roaming\879328") -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Run : Rapid (C:\Users\WIN-7\AppData\Local\Temp\Rapid.Exe) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Run : Mozilla Firefox (C:\Users\WIN-7\AppData\Local\Temp\Mozilla Firefox Corporation.exe) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Run : pwemklicukstqwdkklq (C:\Users\WIN-7\AppData\Roaming\pwemklicukstqwdkklq.exe) -> FOUND
    • [RUN][ROGUE ST] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Run : 879328 ("C:\Users\WIN-7\AppData\Roaming\879328") -> FOUND
    • [RUN][ROGUE ST] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Run : 7247yfu4i3u4hi3hbj8 ("C:\Users\WIN-7\AppData\Roaming\879328") -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Run : kingdoms (C:\Users\WIN-7\AppData\Roaming\kingdoms.exe) -> FOUND
    • [RUN][SUSP PATH] HKCU\[...]\Policies\Explorer\\Run : kingdoms (C:\Users\WIN-7\AppData\Roaming\kingdoms.exe) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Policies\Explorer\\Run : kingdoms (C:\Users\WIN-7\AppData\Roaming\kingdoms.exe) -> FOUND
    • [SHELL][SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\WIN-7\sceff_.exe) -> FOUND
    • [SHELL][SUSP PATH] HKUS\S-1-5-21-3997148575-4277534644-2900686109-1000[...]\Windows : Load (C:\Users\WIN-7\sceff_.exe) -> FOUND
    • [HJPOL] HKCU\[...]\System : DisableTaskMgr (1) -> FOUND
    • [HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Reboot the machine.



    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    O4 - HKLM..\Run: [879328] C:\Users\WIN-7\AppData\Roaming\879328 (Microsoft Corporation)
    O4 - HKLM..\Run: [MUZBQUE0M0Y0RUEyMEM5QT] C:\Users\WIN-7\sceff_.exe ()
    O4 - HKCU..\Run: [7247yfu4i3u4hi3hbj8] C:\Users\WIN-7\AppData\Roaming\879328 (Microsoft Corporation)
    O4 - HKCU..\Run: [879328] C:\Users\WIN-7\AppData\Roaming\879328 (Microsoft Corporation)
    O4 - HKCU..\Run: [comrepl] C:\Windows\System32\com\oS8EKkFaMnLf\comrepl.exe ()
    O4 - HKCU..\Run: [kingdoms] C:\Users\WIN-7\AppData\Roaming\kingdoms.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [Mozilla Firefox] C:\Users\WIN-7\AppData\Local\Temp\Mozilla Firefox Corporation.exe ()
    O4 - HKCU..\Run: [pwemklicukstqwdkklq] C:\Users\WIN-7\AppData\Roaming\pwemklicukstqwdkklq.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [Rapid] C:\Users\WIN-7\AppData\Local\Temp\Rapid.Exe (New)
    F3 - HKCU WinNT: Load - (C:\Users\WIN-7\sceff_.exe) - C:\Users\WIN-7\sceff_.exe ()
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: kingdoms = C:\Users\WIN-7\AppData\Roaming\kingdoms.exe (Microsoft Corporation)
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    2012/12/27 06:56:55 | 001,169,224 | ---- | C] (Microsoft Corporation) -- C:\Users\WIN-7\AppData\Roaming\kingdoms.exe
    [2012/12/27 06:56:50 | 000,164,864 | ---- | C] (New) -- C:\Users\WIN-7\AppData\Roaming\sncjjh.exe
    [2012/12/27 04:13:43 | 001,368,064 | ---- | C] (Facebook) -- C:\Users\WIN-7\AppData\Roaming\jdqqyj.exe
    [2012/12/27 03:41:27 | 000,208,384 | RHS- | C] (New) -- C:\setup.exe
    [2012/12/27 03:41:19 | 000,000,000 | -HSD | C] -- C:\ProgramData\sessionmanage
    [2012/12/27 03:03:13 | 000,032,072 | RHS- | C] (Microsoft Corporation) -- C:\Users\WIN-7\AppData\Roaming\879328
    [2012/12/27 02:42:24 | 000,752,128 | ---- | C] (New) -- C:\Users\WIN-7\AppData\Roaming\ivkkgn.exe
    [2012/12/27 02:41:31 | 001,169,224 | ---- | C] (Microsoft Corporation) -- C:\Users\WIN-7\AppData\Roaming\pwemklicukstqwdkklq.exe
    [2012/12/27 00:07:53 | 000,000,000 | -HSD | C] -- C:\ProgramData\System32
    [2012/12/26 23:46:04 | 001,169,224 | ---- | C] (Microsoft Corporation) -- C:\Users\WIN-7\AppData\Roaming\donkey.exe
    [2012/12/26 23:45:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Local Settings
    [2012/04/26 19:33:58 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpeD884.dll
    [2012/02/02 13:31:05 | 000,055,632 | ---- | C] (Microsoft Corporation) -- C:\Users\WIN-7\AppData\Roaming\great.exe
    C:\Users\WIN-7\AppData\Roaming\55
    C:\Users\WIN-7\AppData\Roaming\TwZsf.vbs
    [2012/12/27 08:54:47 | 000,222,720 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\55.exe
    [2012/12/27 07:49:50 | 000,314,368 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\jnwcqq.exe
    [2012/12/27 06:56:55 | 000,000,000 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\kingdomscharacter.dat
    [2012/12/27 06:56:52 | 000,164,864 | ---- | M] (New) -- C:\Users\WIN-7\AppData\Roaming\sncjjh.exe
    [2012/12/27 04:57:25 | 000,000,909 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\system.bat
    [2012/12/27 04:13:48 | 001,368,064 | ---- | M] (Facebook) -- C:\Users\WIN-7\AppData\Roaming\jdqqyj.exe
    [2012/12/27 04:09:44 | 000,780,288 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\oiawml.exe
    [2012/12/27 04:08:24 | 000,000,032 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\kkk
    [2012/12/27 04:05:14 | 000,780,288 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\xojcac.exe
    [2012/12/27 03:39:21 | 000,186,880 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\clunkh.exe
    [2012/12/27 02:42:27 | 000,752,128 | ---- | M] (New) -- C:\Users\WIN-7\AppData\Roaming\ivkkgn.exe
    [2012/12/27 02:22:06 | 000,015,972 | ---- | M] () -- C:\Users\WIN-7\AppData\Roaming\miner11.exe
    [2012/12/26 23:46:00 | 000,469,504 | RHS- | M] () -- C:\Users\WIN-7\sceff_.exe
    [2012/11/27 08:06:03 | 000,000,000 | ---D | M] -- C:\Users\WIN-7\AppData\Roaming\Fohyin
    [2012/11/27 20:44:07 | 000,000,000 | ---D | M] -- C:\Users\WIN-7\AppData\Roaming\Foso
    [2012/11/27 08:06:03 | 000,000,000 | ---D | M] -- C:\Users\WIN-7\AppData\Roaming\Liim
    [2012/12/27 00:07:49 | 000,000,000 | -HSD | M] -- C:\Users\WIN-7\AppData\Roaming\msnmsgr
    [2012/11/27 09:45:04 | 000,000,000 | ---D | M] -- C:\Users\WIN-7\AppData\Roaming\Niqa
    [2012/11/28 00:40:51 | 000,000,000 | ---D | M] -- C:\Users\WIN-7\AppData\Roaming\Xaag
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.
    • Rerun RogueKiller - just a scan- and attach new log.
    • Same for OTL.
    • Now also see if you can run MGTools.exe, and attach MGlogs.zip if so.
    • Let me know how things are running also.
     
  6. edanboro

    edanboro Private E-2

    the computer is much better now!
    now i can use it without safe mode, althoght there is one bug, internet explorer stuck all the time, cant use.
    thanks a lot!
    logs attatched
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Delete these files.
    • C:\Users\WIN-7\AppData\Roaming\55
    • C:\Users\WIN-7\AppData\Roaming\TwZsf.vbs


    Reboot, navigate back to where those files were. Are they STILL gone?

    How are things running now?
     
  8. edanboro

    edanboro Private E-2

    ok did it, they gone after reboot,
    didnt notice a change
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Elaborate please.
     
  10. edanboro

    edanboro Private E-2

    when i open explorer and navigating to another page, most of the time the page dont come up and if it does, it dont responding after a sec, when i trying to close it, but it doesnt closed, so i close it throght tast manager
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try using the FIXit Tool on this page, scroll down a little. Any better?
     
  12. edanboro

    edanboro Private E-2

    its dont work:
    "sorry,We encountered a problem in downloading one component of more....."
    [code 80070578]
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can post about the internet explorer problems in the software forum. I have done all that I can with regards to malware removal. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. edanboro

    edanboro Private E-2

    thank you very much!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Happy New Year to you!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds