Help with Malware Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Xyllus, Mar 30, 2011.

  1. Xyllus

    Xyllus Private E-2

    Hey guys,

    I seem to only have one problem: When using Internet Explorer it randomly, but often redirects me to random spam sites (sometimes even just Yellowbook.com) when I click a link.
    This seems to be happening more often when I just click a link from a google search. It also occurs when I try to use Chrome.

    I am pretty confident it started yesterday, when I was in a hurry to watch a soccer game and installed Sopcast AND forgot to uncheck the 'Install Ask toolbar' thing. I have now uninstalled the toolbar and sopcast itself, but to no avail. I also have run the tests you wanted me to, except for RootRepeal (I have a 64 bit system) and MgTools doesn't work, when starting it on the desktop it gives me: C:/ is inaccessible.

    Thank you guys!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    But you attached the log from MGtools??? Did you mean ComboFix did not run since you did not attach that log?



    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. Xyllus

    Xyllus Private E-2

    Yeah of course, my bad.

    And I ran it: nothing was found.

    Thank you so much for the quick reply!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\RunOnce: [*ntfswinmgr.exe] "C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ntfswinmgr.exe"
    O4 - Startup: ntfswinmgr.exe

    After clicking Fix, exit HJT.




    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\Ben\Start Menu\Programs\Startup\ntfswinmgr.exe
    C:\Users\Ben\Local Settings\TEMP\18d009f6
    C:\Users\Ben\Local Settings\TEMP\bc18d009
    C:\Users\Ben\Local Settings\TEMP\divCDAA.tmp
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    "*ntfswinmgr.exe"=-
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now uninstall the below old versions of software:
    Java(TM) 6 Update 15

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 31, 2011
  5. Xyllus

    Xyllus Private E-2

    I'm still getting the redirecting, but it seems less frequently than before!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The infection renamed itself inbetween your first logs and the fix I gave you. Thus the fix was no longer correct. What you have now is different names and if I post another fix, the same thing will likely occur.

    What I need you to do is to run the C:\MGtools\GetLogs.bat program again and then attach the new MGlogs.zip file. And then you MUST NOT shutdown or reboot your PC so we can avoid allowing the infection to rename itself on the fly. You must wait until I give you a fix and you run it which will then cause a reboot.
     
  7. Xyllus

    Xyllus Private E-2

    Alright, won't reboot.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\RunOnce: [*cacheeditxml.exe] "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\cacheeditxml.exe"
    O4 - HKCU\..\RunOnce: [*cacheeditxml.exe] "C:\Windows\SysWOW64\config\systemprofile\AppData\Local\cacheeditxml.exe"

    After clicking Fix, exit HJT.



    • Now right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Files
    C:\Windows\SysWOW64\config\systemprofile\AppData\Local\cacheeditxml.exe
    C:\Users\Ben\Local Settings\TEMP\18d009f6
    C:\Users\Ben\Local Settings\TEMP\bc18d009
    :Reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "*cacheeditxml.exe"=-
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Xyllus

    Xyllus Private E-2

    I didn't reboot, but I did put it to sleep and unfortunately, hibernation mode.
    I tried the instructions again but it didn't work. After that, I tried to understand the logs myself but it didn't work so I have to attach the mgtool log file again, sorry.

    Thanks!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you cannot allow this either and also it would be adviseable not to run anything else after attaching the logs. It now changed to:

    O4 - HKLM\..\RunOnce: [*auditauthadsl.exe] "C:\Windows\SysWOW64\auditauthadsl.exe"

    My fix below will on contain one line in the HijackThis fix for the above since that is all that showed in your log. But that could have changed by now. So look for any 04 - type lines ( whether 04 - HKLM or 04 - HKCU ) that have the [* randomname ] in them and fix those lines.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\RunOnce: [*auditauthadsl.exe] "C:\Windows\SysWOW64\auditauthadsl.exe"

    After clicking Fix, exit HJT.



    Now Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\SysWOW64\auditauthadsl.exe
    C:\Users\Ben\Local Settings\TEMP\18d009f6
    C:\Users\Ben\Local Settings\TEMP\~DFB2D6C5485DEFCB85.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF138A65652CFDF9F2.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF3CB6723A166AA22F.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF9078B3A4041E4073.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF94200A635870560E.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFAC877AFB7CCED45A.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFB4D1ED8FEADEB3E4.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFBF7A46C30EB73CB6.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFD3D8EA5F96CEDE46.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFD8E31603895E36E7.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFE41F2938C5A7B30A.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFED5CED79A2BB3D0A.TMP
     
    :Reg
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Google Update"=-
    "SpybotSD TeaTimer"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. Xyllus

    Xyllus Private E-2

    Some trying out seems like it has fixed the problem!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Xyllus

    Xyllus Private E-2

    Seems like the same problem popped up...

    I don't know I did wrong?

    Thanks.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have already run the final cleanup to remove MGtools, redownload MGtools.exe and run it again. Attach a new MGlogs.zip file.

    If you did not run the final cleanup, just do the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Now run this new scan >>> GMER - running with a random name and attach the log from GMER
     
  15. Xyllus

    Xyllus Private E-2

    Alright then.
     

    Attached Files:

  16. Xyllus

    Xyllus Private E-2

    Sorry; had to restart the computer.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\RunOnce: [*pagecryptaudio.exe] "C:\ProgramData\pagecryptaudio.exe"
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\ProgramData\pagecryptaudio.exe
    C:\Users\Ben\AppData\Local\{334287BA-4BC8-4C45-958E-03ACBE9DE3C3}
    C:\Users\Ben\AppData\Local\{39AEBD1B-9DC2-4219-AEAB-E153E160B866}
    C:\Users\Ben\AppData\Local\{46236C79-AAE0-4EB1-8226-2FEAA4580E6D}
    C:\Users\Ben\AppData\Local\{5E38F573-29F2-451E-A200-7606461384A3}
    C:\Users\Ben\AppData\Local\{7139E418-15CA-43B7-AB83-15E639802334}
    C:\Users\Ben\AppData\Local\{D90CD825-51B4-49B8-8DF1-37C56CE8A320}
    C:\Windows\X÷#                                                            
    C:\Users\Ben\Local Settings\TEMP\18d009f6
    C:\Users\Ben\Local Settings\TEMP\A9R6CE7.tmp
    C:\Users\Ben\Local Settings\TEMP\bc18d009
    C:\Users\Ben\Local Settings\TEMP\pwldqpow.sys
    C:\Users\Ben\Local Settings\TEMP\{9A9B1473-A3BF-763F-BB5C-06B2E2216216}
    C:\Users\Ben\Local Settings\TEMP\~DF20762BF00F3C5FCB.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF6BDE2059AA24479A.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF8DD63657E0F37489.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF9E56BAE87F2ED55E.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFD525F0E48B805A1C.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFEA2D4F9951EBF843.TMP
    C:\Users\Ben\Local Settings\TEMP\~DFEF1B9C2B6F7DC182.TMP
    :Reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. Xyllus

    Xyllus Private E-2

    Still same issue.

    I never reboot, but it's just hard to prevent the pc going to sleep/hibernate, since I take it with me everytime.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to stop "taking it with you" and will have to disable hibernate/sleep mode. It is constantly changing your problem making the logs you post out of date and incorrect. At this rate, you may be better off reinstalling or restoring from a backup since the file names and registry keys keep changing before you run the fix that we create based on your previous posts.

    Please follow the instructions in the below and attach the log from OTS.

    Scanning with OldTimer OTS

    After attaching this log, you must not allow your PC to be shutdown, goto sleep, or to hibernate. If you do, we cannot help you.
     
  20. Xyllus

    Xyllus Private E-2

    My apologies; I did not realize putting it the sleep was also attributing to the problem. From now on, this computer will not see anything but daylight.
     

    Attached Files:

    • OTS.Txt
      File size:
      289.7 KB
      Views:
      3
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to get ComboFix to run and we will have to take some more drastic steps since McAfee is likely getting in our way.

    Uninstall your McAfee Software and then run the below too:

    McAfee Removal Tool

    Also uninstall DAEMON Tools Lite

    Then please redownload a new copy of combofix.exe save it to your desktop and and try to run it. Attach the combofix.txt log if it runs. Whether ComboFix runs or not, continue on with the below.


    Now download and save the below to your PC (save into your C:\MGtools folder). Then double click on it to run it.

    MGLister.bat

    It should take a couple minutes or less to run. You will see a black command prompt window while it is running and it should close when it is finished. Now continue on to the below.




    Now right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\ProgramData\catcabedit.exe
    C:\Users\Ben\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\catcabedit.exe
    C:\Users\Ben\Local Settings\TEMP\Low
    C:\Users\Ben\Local Settings\TEMP\~DF4BC8C398A9D71BEB.TMP
    C:\Users\Ben\Local Settings\TEMP\~DF4E52B55EB571EB73.TMP
    :Reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    :Commands
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
     
  22. Xyllus

    Xyllus Private E-2

    Thank you!

    I did uninstall both programs, but both the McAfee Removal Tool and Daemon tools wanted me to restart, which I denied.

    Combofix still does not run; gives the same error message (C;/ inaccessible)

    and MGLister.bat worked fine, but ran extremely fast, e.g. I barely had time to even see the Dos Command come up before it disappeared again.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    O4 - HKUS\S-1-5-18\..\Run: [catcabedit.exe] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\catcabedit.exe" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [catcabedit.exe] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\catcabedit.exe" (User 'Default user')

    After clicking Fix, exit HJT.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now delete the below file
    C:\Windows\srvcatcab.exe

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  24. Xyllus

    Xyllus Private E-2

    Adding those lines to the registry did work; it seems to be running MUCH smoother now! Haven't been directed yet.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so let's see how it looks after the below.



    Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\srvcatcab.exe
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\catcabedit.exe
    C:\Users\Ben\AppData\Local\{C766EE86-DE90-49EF-8C1C-D1F06CD4E615}
    C:\Users\Ben\AppData\Local\{27FC6CF0-C831-4DFD-98FF-9B6C297C467E}
    C:\Users\Ben\AppData\Local\{65DE282F-644C-4A35-A293-4AD9BEB9979F}
    C:\Users\Ben\AppData\Local\{312413CC-C4B7-4D0A-A234-C18CECB96185}
    C:\Users\Ben\AppData\Local\{E1476F64-092A-4FCA-9E22-DBCB35F202DB}
    C:\Users\Ben\AppData\Local\{F7F0DE65-F5BE-4BF6-91A6-9A2239487CA2}
    C:\Users\Ben\AppData\Local\{072D1831-FEB5-4450-A1B2-999798356F69}
    C:\Users\Ben\AppData\Local\{8AFCB84A-069A-4444-B779-DA334008760F}
    C:\Users\Ben\AppData\Local\{2E4B8277-7E9D-425E-909D-3F3C258C77A1}
    C:\Users\Ben\AppData\Local\{1832BB3F-8597-4376-B505-B85DE322A902}
    C:\Users\Ben\AppData\Local\{43723186-0175-4D40-8C91-A9831D2863E9}
    C:\Users\Ben\AppData\Local\{7A9B71D5-D82B-4845-825C-C3EC4D87C1E5}
    C:\Users\Ben\AppData\Local\{77936E03-69AB-44AB-953F-E371957E9F37}
    C:\Users\Ben\AppData\Local\{E9F37D55-A157-444F-8DCB-550F901C0E0D}
    C:\Users\Ben\AppData\Local\{BA00136A-8D96-45A2-BA4C-CA14F7A8E112}
    C:\Users\Ben\AppData\Local\{A79DD1EC-0D0C-452E-98D0-D6FA9F1E74A9}
    C:\Users\Ben\AppData\Local\{3DBCEF61-0A4F-4581-A009-EBEF3A010E6E}
    C:\Users\Ben\AppData\Local\{285C8FE4-75BE-40CB-8082-9AAB2E1944AE}
    C:\Users\Ben\AppData\Local\{AA90E48B-282B-4C2B-8BDA-795A59FBBC72}
     
    :Reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    :Commands
    [purity]
     
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now if the above did not automatically reboot your PC, reboot it now and then after reboot, continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  26. Xyllus

    Xyllus Private E-2

    Seems to be working great!
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then reinstall McAfee. Give it another day, and if all is still good you can do the below again. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. Xyllus

    Xyllus Private E-2

    Alright, awesome!

    Thank you so much, keep up the good work!

    Do you guys take donations or anything?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds