Followed guidelines, still infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by berain666, Aug 19, 2010.

  1. berain666

    berain666 Private E-2

    Thank you for taking the time to read this.

    Approximately 2 months ago, while browsing Facebook, I came across a post from one of my friends describing a camping trip and offering a movie that I could watch to show me how it went. Stupidly, I clicked on the link, trusting my friend, only to find a window pop-up telling me that I need to update my java to view the video. I did so, and that is where all of the problems began...

    Shortly after that, my browser, Firefox, started trying to redirect me to various different pages, and telling me that they were bad pages (I had security set to high). Occasionally, my browser would even open by itself during something non-internet related, such as a game or Microsoft Word. A day or two after that, my Windows Defender told me it was unable to update, and kept trying to redirect me to the Windows Update page. Every time that I have tried to view the Windows Update page has been unsuccessful since then, telling me that the 'CONNECTION HAS BEEN RESET'. Since then, I have also had various attacks on other various email, game, and online accounts.

    Because of these problems, I downloaded a free version of AVG and disabled Windows Defender, which didn't seem able to do much. I have since then not had any problems with redirected pages, but continue to be unable to update Windows or even view the Windows Update page. I also constantly receive a message that says something like "This Windows program has stopped working" and it keeps giving me options to update windows to fix the problem(despite having disabled Windows Defender).

    I will try and include my DXDIAG to assist you with any info necessary. I have tried to follow the steps as they have been described in trying to fix this problem, and have since then determined that my Computer was infected with a KOOBFACE worm virus. I have deleted it, but I am still unable to update Windows. I will add the two remaining files I could not add as well.

    Thanks again for your time! :)
     

    Attached Files:

  2. berain666

    berain666 Private E-2

    Here are the two remaining files.

    Thanks again!

    :)
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why did you not run Combofix? In a moment I will instruct you to download and run it as per the instructions in the R&R. (Refer to it's sticky at the top of the malware forum and follow the instructions for your OS.)

    Use windows explorer to find and delete the below folders:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Now run Combofix at this point, please.


    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this, also attach the requested logs from TDSSKiller as well as the log from MBRCheck and combofix.

    Give a description of how your machine is running now! :) And if you still are unable to update windows consider the following:
     
  5. berain666

    berain666 Private E-2

    Thank you for your response, I will try those things as soon as I am able.

    Thanks again!
     
  6. berain666

    berain666 Private E-2

    The problem has been fixed! I will attach the log files I was able to find though in order to potentially help others with this annoying problem. I was unable to find the thread to get one of the logs for one of those programs but the rest are attached.

    Thank you so much!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I know that TDSSKiller addresses your problem, but I would still like to see the log from combofix. :)
     
  8. berain666

    berain666 Private E-2

    I would love to show you, but for whatever reason, I am unable to find the thread that tells me how to find the log for combofix. I also looked for it on my own to no avail. Could you possibly post a link to it? It would be appreciated.
     
  9. berain666

    berain666 Private E-2

    I think i found it! I hope this helps!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Only a little bit left to do now.

    Have a look in msconfig, is this machine set to start up normally?

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Firefox::
    FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\duvvzztr.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    
    DirLook::
    C:\Users\Owner\AppData\Local\76561197998316679
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and address my question regarding msconfig.
     
  11. berain666

    berain666 Private E-2

    Well, I tried doing the above mentioned, but it appears that after updating it itself, combofix tries run, then gets stuck on the 'attempting to create a restore point' screen. I even left it there for several hours to be certain, but I have tried many times with no luck. I believe i did as directed, I created the notepad and copy/pasted just as you mentioned, including all of the text as follows:

    KILLALL::

    Firefox::
    FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\duvvzztr.default\
    FF - prefs.js: browser.search.selectedEngine - Ask.com

    DirLook::
    C:\Users\Owner\AppData\Local\76561197998316679

    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    but it continues to get stuck on the attempting to create restore point screen. It shows the load screen with the percentage of files backed up, it fills up to 100 percent, then just hangs indefinitely. I assure you I have disabled AVG and Windows Defender, so nothing should be interfering. And to answer your question, yes, I have set up msconfig to start normally as mentioned in the original guide to fix my machine. It is still set that way.

    I have even searched on the internet for a useful guide to using combofix, as I was unable to find the thread you mentioned, and I was unable to determine the reason for it hanging.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use windows explorer to find this folder:

    C:\Users\Owner\AppData\Local\76561197998316679 <--- Do not click on any of it's contents, I just want to see what's inside it. Let me know.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running now.
     
  13. berain666

    berain666 Private E-2

    Here is a list of what is inside the requested location:
    C:\Users\Owner\AppData\Local\76561197998316679
    Folder-28020
    subfolder-cache
    subfolder-persistent
    subfolder-temp

    The regedit was executed successfully, the success message was given.
    The new Mglogs.zip is attached. I am still unable to run the cfscript.txt
    with combofix. I know very little about what you are having me do, I am trusting that it pertains to the permanent removal of the viruses that were initially giving me trouble. I don't currently seem to be having any trouble with anything at this time. Thanks again for your help, and if you need me to do anything else, let me know!
     
  14. berain666

    berain666 Private E-2

    oops I hope it works this time
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me or show me with a screenshot the contents of those folders, please.

    And you didn't attach the Mglogs.zip :(
     
  16. berain666

    berain666 Private E-2

    Hmm.. yes... it would not let me attach the mglogs either of those two times for whatever reason, something about it being in a previous post, so hopefully it works this time..

    I don't believe I have any software installed that takes screenshots of my desktop, so here are the names of the files listed under the persistent
    directory:

    50F446BADC59250D5222F7A59CF478888CDB6946
    6018B115E4F8FEFEFFB9E05CF59BF82310D1CD8A
    D9FA8096F855C00D13E9CDB97AD0ED0EFBB32DA0

    they are about 700-731 bytes each with no extension listed... they just show up as (file)
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have the built in "Paint" application which you could have used, but no worries ;)

    Just rename the folder I was questioning to C:\Users\Owner\AppData\Local\76561197998316679.old (include the .old extension!) see how the PC behaves for a few days and if all is well then please delete it.

    Let's just do this now because I am not seeing anything else to be done either.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    After clicking Fix exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. berain666

    berain666 Private E-2

    Ok, did all that stuff, thanks again! You have been most helpful!
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds