Help me! Vicious time-wasting malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by paradisedweller, Apr 27, 2009.

  1. paradisedweller

    paradisedweller Private E-2

    Usually I can nip these pains in the bud but this one really caught me off guard.

    Whatever it is it downloaded fake anti-virus programs onto my computer yesterday. I can't tell you much because I was dumb and forgot to keep a record of the stuff I deleted but there was something called frmwrk.exe reported running on sysinternals and a program called altcompare on my add/remove programs list.

    Today it replaced my wallpaper with some stupid virus warning and started re-directing my browser (firefox and chrome) to a fake malware warning. It also created a new user (I have Windows XP) but I don't remember what the user was called, I deleted it without checking. It also seems to have disabled task manager. I have Avira Antivirus but it looks like that's been screwed with, so I decided to try Hijack This

    If it's of any use I will be forever grateful to the person who can solve the problem. I work from home and I have to clear this up before I can finish working on my project so I'm pretty annoyed at the waste of time.

    Here's the HT logfile:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:49:15, on 27-04-2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal



    Again, forever indebted: I can't do much but I'm a photographer so if you live in the Greater Toronto Area I can offer you some free photography. If not I will write a very appreciative response and that will have to do.

    Cheers,

    Michelle





    ADMIN EDIT: Please read and follow the following READ & RUN ME FIRST. Malware Removal Guide and HOW TO: Attach Items To Your Post, many thanks.
     
    Last edited by a moderator: Apr 27, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. paradisedweller

    paradisedweller Private E-2

    Sorry about the post, I didn't realize I wasn't supposed to do that until *after* I submitted and went on to read your post - I felt a little dumb, I gotta admit.

    So the read&run procedure cleared up the majority of the nusiance but I still get redirected when I'm on firefox to spam sites - a bit of a nuisiance because I'm doing research and when I open stuff in tabs I have to check each one to make sure I'm on the page I want before I lose the link.

    I share a network with a second computer and while I can access the second computer's shared files (it has no symptoms of a virus) it can't access my shared files. Again more of a nuisiance than anything but could be something worse behind it.

    Also, I'm a bit worried by a message when I restart. In the blue windows startup screen, right before it shows the users (I'm on XP home, 32 bit) there's a message that says "lsdelete file not found, skipping autocheck" or something along those lines.

    Lastly my antivirus program which is Avira's free version right now has to be started manually and I can't seem to change that back to auto start. I know didn't change any settings, so my computer is vulnerable for the first minute between the time I log on and the time I can get to Avira's start screen. I keep my computer on 90% of the time but it's still worrisome if a virus managed to manipulate my antivirus program.

    I've attached the logs from the malware programs I ran, and I will be glad to add anything else. Take your time getting back to me, I fixed the majority of the headache and I appreciate that.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the log from running MGTools.exe --> C:\MGLogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds