help please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by alcroft420, Mar 11, 2008.

  1. alcroft420

    alcroft420 Private E-2

    Hey All,

    Hope you can help.

    I have some kind of win32 malware. I have gone through the Read & Run me first procedure from start to finish.

    Whilst running these procedures Spybot SD found various win32 issues and removed and quarantined 8 of the 9 but could not remove 1 of them.

    Alsl after these procedures Internet explorer dissapeared as well as paint, calculator and all my standard windows games. These are the only missing applications I have noticed missing so far.

    When opening internet explorer now I recieve a prompt asking me if I want to connect or work offline. As well as this internet explorer opens by itself with a spyware remover site?

    I have reset my homepage and restored default setting but these still happen.

    Now I have just noticed my background has changed to redbackground with a nuclear sign saying your privacy is in danger!!!

    Please help!


    I have attached logs for combofix and superantispyware!

    Thanks so much!
     

    Attached Files:

  2. Lev

    Lev MajorGeek

  3. alcroft420

    alcroft420 Private E-2

    Sorry about that,

    Have attached the requested mgtools.zip logs.

    Thanks so much for your help. The background is really worrying!
     

    Attached Files:

  4. alcroft420

    alcroft420 Private E-2

    Hey All,

    Has anyone had a look at my previous logs? My pc is still definitely infected.

    Any help would be appreciated!

    Thanks,
     
  5. alcroft420

    alcroft420 Private E-2

    Hey All,

    Sorry to be pestering. Just wanted to ask if I am doing anything wrong? Or if there are just no administrators available to help a present?

    Any advice oon my issue would be seiously appreciated!

    Thanks...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the stickies. Namely this one: Don't Bump! It Only Hurts You!!!


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - Winlogon Notify: winkrt32 - winkrt32.dll (file missing)
    O21 - SSODL: btrklfr - {B8C309BF-08FD-4D39-A896-8565541A975A} - C:\WINDOWS\btrklfr.dll (file missing)
    O21 - SSODL: apdqnxp - {7C55ECD7-84B5-47EC-8E6B-744DDB5F3331} - C:\WINDOWS\apdqnxp.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove some malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds