DCOM Server Process Terminates/Google Links Hi-Jacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by Legend1392, Jan 25, 2010.

  1. Legend1392

    Legend1392 Private E-2

    Hello, I've been coming to majorgeeks.com for some time now, and have found the information you have here at your site very useful. The past year or two I've been using the programs you recommend to keep spyware, malware, and viruses out of my computer, and so far everything has been running great.

    Until recently. In the past two, maybe three weeks at most, I've been having google search links redirect me to websites advertising different products, and also trying to sell me anti-virus programs (most likely fake programs).

    I ran your cleaning procedure, and the problem never really got any better.

    Now the past week I've been having the DCOM Server Process shut down, and try and restart my computer in a one minute countdown, but I've changed the service now to take no action when shutting off.

    In one of the many scans I've done with Malwarebytes' I found the following harmful files:

    Trojan.BHO
    Trojan.FakeAlert
    Worm.AutoRun
    Trojan.Proxy
    Trojan.Agent

    I found these after my Dad did a system restore to about a month ago thinking that might solve the problem. It did not.

    I've run the entire cleaning procedure, and I've also done a disk check because I read somewhere on this site in a previous post it might solve the DCOM Server Process error.

    I know that this could possibly be a software issue, but I highly doubt it is, because google is redirecting me to advertising links, leading me to believe this has to be some sort of malware, spyware, or virus.

    So far nothing has worked, so I'm posting here hoping that someone can help me. I've searched all over the internet looking for answers, and there seem to be none to this problem. This is my last resort, the only thing left to do after this is reformat my harddrive, so I would very much appreciate any help one of the experts on this site can offer.

    Thankyou,

    Legend1392

    P.S. If any more information is required, just let me know and I will post it.
     
  2. Legend1392

    Legend1392 Private E-2

    SUPERAntipSpyware Log and Malwarebytes' Log
     

    Attached Files:

  3. Legend1392

    Legend1392 Private E-2

    MGTools Log, and RootRepeal Log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    If TDSSkiller found anything, be sure to reboot afterwards. Are you still having problems?
     
  5. Legend1392

    Legend1392 Private E-2

    At the moment, everything seems to be working perfect. Google links are taking me to the appropriate website, and not redirecting me. I haven't had any pop ups, and I've changed the DCOM Server Process back to its default setting of rebooting the computer when it shuts down, and so far it has not shut down.

    I've attached the TDSSKiller log you've requested. Thankyou so much for your help! I can't thankyou enough! :-D
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have more infections to fix. Some of these have been on your PC for a long time.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKUS\S-1-5-20\..\Run: [penayoheve] Rundll32.exe "C:\WINDOWS\system32\pedewovo.dll",s (User '?')
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    O20 - AppInit_DLLs: C:\WINDOWS\system32\hubobazi.dll c:\windows\system32\lavejipu.dll
    O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Legend1392

    Legend1392 Private E-2

    Thankyou so much for the help, I had no idea I was infected with so much malware. I followed all of the instructions you gave me, and I've attached the logs to this post. So far everything seems to be working great. :)

    Is there any more malware or dangerous software on my computer that I can remove?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Do you know what the below two files are?
    Code:
    "C:\"
    3451197.exe   Oct  5 2009         804  "3451197.exe"
    3888819.exe   Oct  5 2009         804  "3888819.exe"
    If you don't know then just delete them. Your logs are clean otherwise.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds