First timer/ possible infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by supalee337, Jun 11, 2009.

  1. supalee337

    supalee337 Private E-2

    Hello,

    I recently accidentally installed some program that had a virus or whatever attached to it. I first renamed hijack this and removed some stuff that I knew was bad. That allowed me to rename a few more of the anti-virus programs and run scans on them. I have run C-cleaner, super anti-spyware, malwarebytes, anti-malware, combofix, MGTools, and panda rootkit scan; in that order. I removed several trojans from super anti-spyware and some infections from malwarebytes. I dont know what combofix or MGtools did, but I got the blue screen and notification that I recovered from a serious error after MGTools. Panda came up with no rootkits detected. I disabled system restore and re-ran all scans but combofix and MGTools. All scans came up clean so I re-activated system restore. I have a feeling I am still infected because when I am surfing, I get the same popups/advertisements that I was before. I'm not sure where to go from here. My tech level is pretty low. Thank you for any and all help.

    Lee

    P.S. XP pro SP2 and FF3 or IE7 so I can do most any online scan.
     
  2. supalee337

    supalee337 Private E-2

    Yea, I'm infected. FF browser keeps crashing and still can't open up anti-virus programs normally.
     
  3. supalee337

    supalee337 Private E-2

    I see that I should have posted logs for my scans, so here they are. Sorry about that.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and a warm welcome. I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thankyou for your patience during this time.

    Kestrel13!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I apologise for the delay, I was away for a couple days.

    I have a fix for you below, however first of all, I would like for you to update Malware Bytes > rescan > fix all it finds > and attach the new log from running it.

    Next....

    You are not running any anti virus at the moment. You need to ensure you install some once I have given you the "all clean"


    1. We need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    C:\WINDOWS\system32\system32\drivers\MSIVXwsrsippqlmknmqyapltepktpbqxwbiqj.sys
    c:\windows\system32\drivers\MSIVXuvveoypxmiysaldveuliiwnorlmhkjit.sys 
    c:\windows\system32\drivers\MSIVXwsrsippqlmknmqyapltepktpbqxwbiqj.sys 
    c:\windows\system32\MSIVXcount 
    c:\windows\system32\MSIVXodulktetjxfaqbsndlojmtxmbnyjnuvy.dll 
    c:\windows\system32\MSIVXvwehijnwauhobogrqrsrtsmvrfxdypho.dll 
    C:\DOCUME~1\Supa\APPLIC~1\WAITDE~1\long keep software.exe
    C:\Program Files\Ipwindows\ipwins.exe
    C:\WINDOWS\system32\temp1600
    C:\WINDOWS\system32\temp1601
    c:\windows\sued.dat
    C:\Documents and Settings\All Users\Application Data\multitestonemapi\SETTINGS COPY.exe
    C:\WINDOWS\retadpu2000400.exe
    C:\DOCUME~1\Supa\APPLIC~1\WAITDE~1\long keep software.exe
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\avg8
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MSIVXserv.sys]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\User Once]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IpWins]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\one mapi scr heck]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\runner1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\User Once]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Alcmtr]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    3. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  6. supalee337

    supalee337 Private E-2

    Thank you so much for the help. The system hasn't showed any of the quirks that it was showing before. No FF crashes or ad popups in my surfing. Correct, I don't have any Anti-Virus Software installed. I was given some 'apparently bad' advice to never use that kind of software since a lot of it eats up your resources and possibly has viruses in itself. I was told to just be careful with what I opened and installed. I will be running MG's recommended AV software from now on when I am finally able to get this clean. Thanks again for the time.

    I see there is no paypal donation link anywhere on this site. I guess I will show my support by buying some gear or something. :cool
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    that's great to hear!

    Yes you were given bad advice there...

    Looking at your logs memory wise this is where you're at:

    Running anti virus does use up resources, however unless you're running really low on RAM you'll be just fine.
    Yep there's a nice selection here if you're interested. :)

    J!NX

    I will look at your logs after lunch, and get back to you with a response as soon as possible.

    Thanks
    Kes
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget to attach the log from running combofix :)
     
  9. supalee337

    supalee337 Private E-2

    My apologies. Here we go.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This machine is not in normal start up mode as per requested in the Read and Run me instructions.

    Use MSconfig to setup for Normal Startup Mode

    Please ensure that you put the computer into normal start up before getting me new Mglogs:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Thanks
    Kestrel13!
     
  11. supalee337

    supalee337 Private E-2

    Sorry about that. I always use msconfig to make sure I run as fast as possible.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is a bad idea. You shouldn't be using MSCONFIG at all to control start up's. I suggest that in future instead of resorting to using msconfig which is mainly for troubleshooting purposes that you use a start-up manager such as:

    Startup CPL

    Going thru your logs shortly and will respond ASAP :)
     
  13. supalee337

    supalee337 Private E-2

    I have had no other problems so far other than a few FF crashes. They may be unrelated and I just need a new install since I removed so much infection. I will wait for your word though. Thank you.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    2. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. supalee337

    supalee337 Private E-2

    When I click "scan" on HJT I do not see the results that you have quoted. I have attached the log from HJT. I did not fix anything, only ran the scan analysis.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. supalee337

    supalee337 Private E-2

    Ok, thank you.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. supalee337

    supalee337 Private E-2

    Thanks again! Problems have disappeared.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're welcome! safe surfing! :)
     
  21. supalee337

    supalee337 Private E-2

    One weird problem I am having is removing MGtools. I dont have a MGclean.bat file in my C:\MGtools folder. Is there another way to remove that program? I don't want to mess around with it too much since I don't know what all MGtools can do, heh. I guess I can just leave it installed...
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't be concerned about th MGclean.bat file... it is a newly added file in the most current version of MGTools that you didn't run. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds