Help remove malware from my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by raj2ad, Jun 18, 2012.

  1. raj2ad

    raj2ad Private E-2

    For about two months now, my PC is infected with a horrible malware. Even after trying handful of solutions suggested elsewhere, I haven't been able to fix the problem. I hope someone here might be able to help me.

    The main problem that I have is the annoying google redirecting. In addition to this problem, upon PC startup I used to have three to four pop-up windows' messages saying ****.dll not found.

    I followed steps outlined on this site under fixing google redirecting issues. Then I installed and ran the four malware removal programs suggested on this site. The pop-windows don't show up anymore, which is good. But the google redirecting still occurs.
    I have attached the log files from these scans. I also have 6 more log files from RKreport that were obtained by fixing hosts/registries/links. I can attach those in my next post if they are needed. Any help is greatly appreciated.


    Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which browser is redirecting?

    Uninstall the below outdated softw
    are:
    • Java(TM) 6 Update 29

    Delete these files.
    • C:\Users\SARASW~1\AppData\Local\Temp\dhegr.dll
    • C:\Users\SARASW~1\AppData\Local\Temp\rtero.dll

    I want you to runa fresh version of TDSSKiller so refer to the below for how to do so. Download the new copy and let it overwrite the previous.

    TDSSkiller - How to run


    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6



    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. raj2ad

    raj2ad Private E-2

    Thank you for the reply, Kestrel13!

    The google redirecting problem is with my Firefox browser. I checked with IE and currently that does not seem to redirect.

    I followed all the steps you suggested and have attached logs from TDSkiller and frst. I could not find .dll files in my TEMP folder, most likely because I deleted them when I did a RogueKiller scan as described in my first post earlier (attached RK_log_7).

    After doing the above, firefox still showed google redirecting.

    Could there be something that I am missing?

    Thank you for your time.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We are going to be uninstalling your old version of FireFox and installing a fresh version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox with Revo Uninstaller and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.


    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    How are things running now?
     
  5. raj2ad

    raj2ad Private E-2

    Thank you!
    I followed the steps. No more google redirection yet. I appreciate all your help, Kestrel13!

    Thanks.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome, Raj! Safe surfing! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. raj2ad

    raj2ad Private E-2

    Thanks Kestrel13!
    I am following steps to protect my PC from future malware threats using tips from this forum.

    I really appreciate you taking out time to help me. Thank you.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It was a pleasure to get you sorted Raj. :) Take care.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds