Computer infected with Klone.AP & other stuff. Please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by stefanos11, Nov 6, 2009.

  1. stefanos11

    stefanos11 Private E-2

    Hi, one of my computers at work is infected with all sorts of stuff and it's rarely used, until now. I started using it and found malware. I completed all the steps but one. When I tried to run RootRepeal it would freeze "initializing...please wait". So i skipped it. Another thing about the computer is that it wouldn't connect to the internet. It says it's connected but when i try to open firefox or internet explorer it would say "page not found", couldn't even install updates. The internet used to work on this computer. I've been downloading everything from another computer and transfering with usb key. And sometimes it wouldn't let me access files on the usb key(only through windows explorer). I would double click on my computer, then E:USB and a pop -up window would come up and ask me what program to use to open it. Anyhow, after completing all the steps it's running a bit sluggish now. I tried for three days to connect to the internet and nothing. I also pinged it to the router and it came back successful. Any help would be greatly appreciated.
    I've attached the SAS, MB & MGTools logs.
    Thank you.
     

    Attached Files:

  2. stefanos11

    stefanos11 Private E-2

    Here are the combofix logs. There are two because I couldn't install the "microsoft recovery console" during combofix, so I waited untill it was finished, then I installed it and ran it again, but didn't scan the second time.
    Good Luck, and thank you again!
     

    Attached Files:

  3. stefanos11

    stefanos11 Private E-2

    I forgot to mention something, when instructed to show hidden & system files, I checked the box and clicked apply and ok. But it didn't seem to work, so i opened folder options again and it was unchecked. Everytime i would check the box and click apply the icons on the desktop would flash a little, then i would click ok, and the icons would flash again but no hidden files. I repeated it many times but couldn't get the hidden files to show up. And now that I completed all the steps, the hidden files are shown. Should I scan again? Thanks, and sorry for all the seperate replies.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than what has already been removed, your logs are basically clean. Your connection problems are most likely a settings issue on your end. Make sure you are not blocking your browser with your firewall. Also do you use a Proxy Server to connect to the internet? If not, then you need to change your browser settings so that it is not trying to use a proxy. If you do use a Proxy, then you need to make sure the proper values are entered.

    You PC is sluggish (probably down right slow) due to the below
    You cannot run Windows XP with so little memory. At a minimum, you need 4 times this ( i.e. 1 GB but preferably 2 GB ).


    You should do the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    After clicking Fix, exit HJT.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. stefanos11

    stefanos11 Private E-2

    I don't use a proxy server. Even when I disable the firewall I can't connect. I've completed the last step, thank you. But still don't know what to do with internet. Any advice? Thanks for your help.
     
  6. stefanos11

    stefanos11 Private E-2

    I reinstalled windows(repair) and it's dowloading all the updates right now. Got my internet back! I guess i'll have to uninstall combofix now. Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but my point was to make sure you settings were not changed to use one, but since you have things working it does not matter anymore.

    Now you need to complete all my final steps previously given.
     
  8. stefanos11

    stefanos11 Private E-2

    Understood. Thank you again, I've learned a lot from you guys since i've discovered this site, it's great, thank you again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds