Extremely frustrating Malware/Virus - please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by gm303, Apr 4, 2009.

  1. gm303

    gm303 Private E-2

    Hi...I'm going to attempt to give you as much info/background about this infection in addition to what logs I could manage to attach. In short, the virus/malware is preventing me from accessing ComboFix's website, and when I managed to download ComboFix from another website the infected computer does not allow me to run it (I get a small progress bar that loads then goes away, the program doesn't initialize). Also, I'm not able to install SUPERAntiSpyware as the setup is not allowed to finalize and complete. Both programs have also been tried to be installed/run in Safe Mode to no avail, and I tried renaming ComboFix but still had the same result.

    More background: Wednesday morning during a random Ctrl+Alt+Del, in the task manager I saw Adobe Acrobat Reader (which I didn't recall using/opening) using a ridiculous amount of memory usage, something close to 228,509k. I closed the process and didn't think much of it, but later on in the day Firefox froze, and soon after I found that programs were crashing randomly (Napster, Outlook Express, AIM, Firefox). A little while after that I noticed Google links were being redirected (here is an example of the redirect link when I Google AVG for instance)
    h t t p://www .google. com/url?sa=t&source=web&ct=res&cd=1&url=http%3A%2F%2Ffree.avg.com%2F&ei=pgPUSfn cHOnslQfrvpzkDA&usg=AFQjCNGC_5wf_ZlpTvTBmerEaNG3uLMPgA&sig2=yxjT-32L0qC1BJTcRL4-rA

    After a reboot I noticed upon loading windows that after my desktop loads the desktop flashes blank for a quick moment before the icons come back (didn't happen before). Additionally, programs like PeerGuardian and my anti-virus & firewall (ZoneAlarm) do not load, but CAN be started manually. Also, when trying to go to Run>Regedit Explorer restarts and Regedit fails to start.

    When I first ran MalwareBytes Anti-Malware it found 12 items (Wednesday), the first 7 being Adware.minibug and the remaining 5 being Trojan.Agent and Trojan.Vundo ( 4 files and 1 Registry Key):
    tdssinit.dll and tdssservers.dat were in the System32 folder (both labeled as Trojan.Agent) and BM2e666998.xml and BM2e666998.xml were in C:\Windows, plus HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (all 3 labeled as Trojan.Vundo).

    After selecting to remove the files through MalwareBytes I selected yes to restart, but after closing all programs Windows "hung" with just an empty desktop on the screen for several minutes, totally unresponsive. After a hard reboot I found the same problems as before, so I booted into safe mode and ran another MalwareBytes scan which this time found nothing. Additionally a ZoneAlarm scan said it found 2 infections but froze before I could view them; subsequent scans show no viruses/infections found. The virus also keeps me from properly installing other Anti-Virus software and a few other anti-malware programs such as ComboFix and SuperAntiSpyware as mentioned above.

    I was able to install and run MGTools (logs attached) as well as a MalwareBytes log from a few minutes ago which at this point shows nothing found.

    At this point I'm back at square one, with the same redirecting, occasional crashing of Firefox (and immediate crashing of Napster and AIM, highly frustrating). The only thing I've done otherwise is uninstalled Adobe Acrobat.

    Any help would be very appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, please reset msconfig to normal startup.

    Second, please clean out these folders:
    C:\WINDOWS\TEMP\
    C:\Documents and Settings\HP_Administrator\Local Settings\temp\

    I need to see the previous log for MBAM to see what was removed.

    Then please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds