Help to remove malware... Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by archeon, Jul 26, 2010.

  1. archeon

    archeon Private E-2

    To all: Thank you in advance for any and all help.

    I am knew to using forums and requesting online help, so please let me know if i am approaching this wrong.
    I am working on a friends Dell Inspiron E1505 laptop. He asked me to help him figure out why he couldnt get on the net, and kept getting pop-ups and redirect to porn sites.
    I was able to get the system back on line by removing the NIC device driver in device manager, and then doing a refresh.
    None of the Anti-virus softwarewill install correctly, and Mcafee that was already installed would not even start. I have tryed to install House Call, Sophos root-kit revealer, AVG Free, MalwareBytes, Spyware Doctor, etc. with no luck.
    In the beggining i couldnt even get task manager to open, but i have been able to resolve that issue.
    I am pretty sure it is something that is loading at boot-up. I have tryed using mscinfig to disable pretty much everything, and the system still wont let me install/run any virus/malware software, or browse to a anti-virus/malware removale web site without being redirected. I have cleaned up the host and lmhost files, the temp and temp enternet directories for all profiles.

    I would like to post a Hijackthis log if that is o.k. and see if someone can point me in the right direction.

    Please let me know if i am in the wrong forum and what i should do next.

    Thank you

    Archeon
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. archeon

    archeon Private E-2

    First, thank you for the reply and you help.
    I followed the instructions as far as installing SUPRAntispyware and running a scan. When the scan was complete it had found 1500+ issues. I had it remove the problems, and rebooted as instructed. The system hung part way through the shutdown process. When i got it started again, i tried to browse to Mcaffe and Kaperski sites and was redirected. I tried to retrieve the scan log and there was none. I am now rescanning using the quick scan (i have to hit the hay soon) and it is finding some of the same infections. I will continue with your directions when i get home from work on Tuesday. I will do my best to include all the requested logs if at all possible.

    Thanks again

    Archeon:major
     
  4. archeon

    archeon Private E-2

    I was able to complete a quick scan with SUPERAntivirus and saved the log file.
    I then tried to run Malwarebytes. It will load and remain on the screen for about 5 seconds, and then without warning it closes. Do you have any workarounds for this?
     
  5. archeon

    archeon Private E-2

    Well here are the logs as they are. I am still having issues. I still cant get Malwarebytes Anti-Malware to stay open long enough to do a scan. When i ran ComboFix i was instructed to reboot because a rootkit was found. After rebooting the scan continued, and it seemed like it finished normally.
    The system seems to running a little slower now, and takes longer after log-in before i can do anything. I tried to install AVG Free, and was asked if i was using proxy settings, when i could not resolve the proxy issue the install terminated. To the best of my knowledge this system is not using ant proxy settings. I am trying to clean the system from a new account i setup with admin rights.

    See the attached log files.

    Thanks.
     

    Attached Files:

  6. archeon

    archeon Private E-2

    Here is the last file.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Other than these two folders:
    c:\documents and settings\marek\Local Settings\Application Data\mmhxeheyb
    C:\Documents and Settings\All Users\Application Data\SMMGYXCXGAV

    (Just use windows explorer to find and delete them), I am not seeing any malware in your system. I suspect you are having system issues as opposed to malware issues.

    Have you been able to run the scans in safe mode on your regular user account?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds