Help please? Nasty malaware/virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by lmarklar, Sep 21, 2009.

  1. lmarklar

    lmarklar Private E-2

    Let me start from the beginning... I was on the internet using I.E. 8, I was searching for information on books by Jim Butcher, I followed a google link, while it loaded I went to get something to drink. When I came back the computer was rebooting, it had installed malaware complete with the pop-ups about virus's ect ect. Sucks, but not a huge deal, I can get those off.

    I ran symantic and it found and quarantined some files, deleted others, I did a manual search and came up with a braviax.exe, I disabled this in the startup menu. I installed malwarebytes anti-malaware, rebooted into safe mode, attempted to run the software, it opens its screen, then closes without running, click on it again, and you no longer have permissions to run this program, re-install, same deal, open once then kick you off. Now my Symantic virus definitions/e-mail protection/outlook protection, have been corrupted. There are no more pop ups, I cant run any type of antispyware or virus programs. The internet misdirection program is still there, and it did not hijack my DNS.. no idea how this one is works. I attempted to run ComboFix and it pops up the dos screen then goes away without doing anything.
     
  2. lmarklar

    lmarklar Private E-2

    update, well I have continued to try different methods of running antispyware/virus scanners ect. I have managed to get SUPERAnitSpyware to run, I had to do it from a safe mode, it found 4 infections, then rebooted the machine. Upon reboot, I got an error before even logging on, NT AUTHORITY/SYSTEM has authorized a shutdown due to windows/system32/services.exe being terminated unexpectedly, gives a code of 1073741482. I rebooted the machine back into safe mode, I re-installed malwarebytes, but no luck still. So I deleted the old copy of ComboFix, put another copy onto the desktop and ran again, this time it detected a rootkit, rebooted the machine, I allowed it to boot to normal mode, it came up, after login ComboFix ran, rebooted machine again, generated its log, now I am running Malwarebytes and it has, so far, been running ok, I will continue to follow the rest of the cleanup procedures and then post my logs once I have completed all of them.
     
  3. lmarklar

    lmarklar Private E-2

    Ok, so here we go.

    I managed to get everything to run, took most of the day... but it all ran. I somehow could not find the original ComboFix log... So I ran it again to generate a new log (this log is after I have run all the other programs). I am sorry that somehow I managed to misplace the first log. but any help in finishing out this clean up is appreciated.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. Please tell me what issues you are still having.
     
  5. lmarklar

    lmarklar Private E-2

    thanks, I have not had any issues, but I have not been using that computer until someone smarter than me checked the logs to make sure I hadn't missed something ;)

    Great forum, great advice, and great how to articles. I just followed the "Do this first stupid" section and have apparently gotten that computer cleaned back up. Thanks for having this resource here guys!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds