HELP!!!!!RootKit/Hacker on my computer(Highjackthis LOG)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sooyatnee, Aug 11, 2008.

  1. Sooyatnee

    Sooyatnee Private E-2

    I recently had the Ups virus ( blue screen yellow warning) with Buritos.exe and Braviax.exe/Karina.net/IRC.BOT/antivirus-2008 pro/antivirus-2008.

    It took me two day of reading but I finally got rid of it by getting rid of crappy software that wasn't protecting me and downloaded, NOD32, Spyware detector,Trojan remover and ATF Cleaner. I also cleared out system restore and delted registry key which seemed to fix the problem but now I have a

    Stealhed (rootkit) driver loading [Pe386] Backdoor. Rutock and I know its still there I cant get rid of it can come one please help me !!!! its ruined 2 cell phones an mp3 and a 300$camera in one day! I dont want to lose all of my files as well Here is my highjackthis log

    Logfile of HijackThis v1.99.1
    e
     
    Last edited by a moderator: Aug 11, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide

    Note:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Sooyatnee

    Sooyatnee Private E-2

    So I'm still working on it and I'm where Msconfig is set on Normal for start up mode, which has been done but I'm trying to find a HJT tutorial; I need know which one's are start up processes, I've seen it twice on your site but cant find it at all now!
    It was posted by Major Attitude. If you know where this is can you send me the link Please.
    Thank you
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't need a HJT tutorial....you need to follow the instructions and attach the requested logs:
    SuperAnti-spyware
    MalwareBytes
    ComboFix
    MGLogs.zip --> from running the MGTools.exe

     
  5. Sooyatnee

    Sooyatnee Private E-2

    Yes I am following the Read Me, and wasnt planning on posting a HTJ log,as I know you guys have us attach them. I'm going through each step as it says. So I'm stuck at a step
    I have had HJT for a while now and I understand you want me to delete and afterwards reinstall, which is fine. What I am trying to so is disable some of my start up processes without MSCONFIG, I used Ccleaner and then later read this in the READ ME file under Dealing with startup processes.

    How to deal with startup processes - do not use MSconfig

    * First you should uninstall any software that you do not use.
    * Second if you have processes still trying to load at startup even though you have uninstalled them. You can simple use HijackThis to easily remove the startup. That way you will not have to manually edit the registry.
    * Third for software you do not want to uninstall but you don't want it to load at startup, look in the program for an option not to load when Windows starts and disable it this way. If you cannot find an option like that you have two possible actions:
    o if you never want it to load at startup, use HJT to permanently remove the startup.
    o if you sometimes want it to load at startup, use a program like Startup CPL to enable or disable as you see fit. There are other tools for doing this too, like SpyBot - Search & Destroy and Autoruns and even Microsoft's Windows Defender if you have it installed (and by default Windows Defender is installed in Vista). See http://support.microsoft.com/kb/270035/ for using Windows Defender.
    * NOTE: DO NOT use Ccleaner to control startups since it just makes use of MSconfig which you do not want to use.
     
    Last edited: Aug 12, 2008
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We want you to set msconfig to normal startup so we can see all that is running!

    We also are not asking you to uninstall and later reinstall HJT ...it is built into the MGTools.

    Please run the scans and attach the logs.
     
  7. Sooyatnee

    Sooyatnee Private E-2

    Here are the folowing Logs for SAS,SB and MB.
     

    Attached Files:

  8. Sooyatnee

    Sooyatnee Private E-2

    I can't DL the console for combofix as I cant find my Windows XP cd, please let me know if this is okay.... here are the rest of the logs from MGtools.
    again Thank you as my paid for spyware protection was malware!:)
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have no idea what logs you attached --> SAS and SB. They were not the logs from running the programs.

    You also did not let MGTools run to completion....You now need to run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file. Wait for it to tell you it is finished before closing it out.
     
  10. Sooyatnee

    Sooyatnee Private E-2

    SAS- SuperAntiSpyware, SB- Spybot, MB-Malwarebytes.
    when I clicked on MgTools it extracted the batch files and registry files ect.
    but did not run at all, so I clicked on the batch files that were supposed to run and thought that they did, I also extracted the Zip file and it went through fine so where did I go wrong and why didnt it run like the manual said it would?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what happened...what error messages you got. Where did you download the MGTools.exe to? It should be on the root drive : C:\MGTools.exe

    ......??

    .....What program was that?

    If you follow the instructions, you should not have any problems...so you need to tell me exactly what you are doing.
     
  12. Sooyatnee

    Sooyatnee Private E-2

    No error message just didnt run when I clicked on it. but it extracted all the files mentioned in the instructions.
    the zip file I was talking about was from MGtools.zip (a winrar file)
    the paid for protection the was detected as malware is called spyware detector.
    I honestly have no idea what happened as I wait until I can give my full attention to reading and following the instructions but Mgtool just didnt run almost like I want even clicking on the icon or something I will uninstall and reinstall agian and see what happens.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should download MGTools.exe to this location:
    C:\MGTools.exe ---- there will be a superman type icon that when you click on it will produce a command prompt. Let it run, it will give you a window to accept the license for HJT ...agree to it. Wait until it tells you it is finished and to hit any key. The command prompt will disappear and you will find the C:\MGLogs.zip to attach to the next reply.
     
  14. Sooyatnee

    Sooyatnee Private E-2

    I havent contacted you b/c my computer died, it started freezing and redirecting me to different web pages, then shut down over and over taking about half an hour to restart in safe mode. I'm emailing you from another cmputer and as a reply to the last message there was no command prompt when I clicked on the icon. I dont know whats going now........any ideas??
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are able to start in safe mode....please try running SAS, MalwareBytes and ComboFix.....attach the resulting logs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds