Hijacks, Crapware, & Trojans- 2 many 2 list

Discussion in 'Malware Help (A Specialist Will Reply)' started by Throws_pc_out_window, Dec 15, 2009.

  1. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    I have this big long list of symptoms and have been kicked out of the forums twice already (*sighs* IE 7 crashes. Haven't been banned or anything). For some reason it's only on this page and TechSupportGuy, and BleepingComputer (I was wondering if maybe you guys were havin' problems on your end) forums so I got smart and typed this into Notepad and Copy/Paste'd it in - lol!

    Here goes....yesterday my wife commented that she was being spammed really bad so I guess that is where this started with a spam e-mail. Next I tried to download a legit demo for photoshop (I am an up-and-coming artist) and I think I was hijacked because when I ran the installer my pc screeched (like if you stuck a hot poker up R2-D2's rear end - :-D) and then BSoD. I had to kill the power and reboot which resulted in 3 more BSoD's before I was finally able to get it to do a system restore (last know good configuration).

    When I tried to get back on the 'net I was highjacked to this page that sorta' resembles the My Computer page for Windoze 98 and it started (didn't get an option to choose whether or not I wanted to do the scan, it just auto-initiated one) scanning my harddrive while SCREAMING at me that my pc is infected and to purchase their software to fix it. This happens a lot and everytime my pc gets a little bit slower (drive-by downloads maybe?). Have ran MBAM and it came up with 4 cases of Malware.Packer, TROJAN.BHO, Highjack.Homepage, SuperAntispyware came up with a bunch of cookies (220) and Rogue.Agent/Gen-Nullo[DLL], Adware.CouponBar while Norton 360 tagged Bloudhound.PDF.18, Trojan.Brisv.A!inf, and a generic Trojan Horse (no name given) along with 6 blocked intrusion attempts, and 3 blocked spyware programs.

    I have also noticed in the process listing for Task Manager there are 9 instances of svchost.exe that is really creaming my memory usage with one running over 60,000 K when I try to get on the 'net, and my page file hovers at 1.21GB when I'm disconnected (jumps to over 2 GB when I open IE 7). At first I could kill this process and everything would work GREAT for about three minutes then I would have to kill it again.

    I have followed all steps in the sticky to the best of my ability except downloading Combofix. It went to a white page and said it was unable to download at this time. Can someone please help because we use this pc for a home-based business and there is a lot of sensitive data on it. Thanks in advance and Happy Holidays to you & yours!
     
    Last edited by a moderator: Dec 17, 2009
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So then could I please see some logs from running each of the programs requested? Those being:


    • SUPERantispyware
    • Malware Bytes
    • Root Repeal
    • MGTools

    Thanks
    Kes13!
     
  3. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    My apologies and thank you for your help. I ad so much trouble getting my message up and I was afraid toreply to it until asked. A few things have changed. I am unable to use System Restore, either to restore or create, and my system crashes at random to a BoSD that states: QL-NOT-LESS-OR-EQUAL STOP:
    0x0000000A (0x00000000, 0x0000001C, 0x00000000, 0X80538102).

    and when I reboot I get a message which states tat drive D/ is corrupt, and although sometimes it will not boot, I boot from drive C/. I also upgraded from IE 7 to IE 8.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I had just started to look through your logs when I noticed that you are in the queue to receive help at The TechGuy Forums

    You now need to decide where it is you wish to resolve your issues. Here... or TechGuy. Whichever forum you opt to work with, you must leave a note in your thread at the other forum explaining that you do not wish to waste resources by cross posting.

    Thanks for your understanding and co-opertaion.
    Kes13!
     
  5. Throws_pc_out_window

    Throws_pc_out_window Private E-2

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to add/remove programs and uninstall the following old java:

    • Java(TM) 6 Update 5

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT

    3. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4.
    • Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.


    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger and TDSSKiller.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    Done. I have rebooted system 3 times and am still recieving CHKDSK scans on drive D): but it runs so fast I can't see the results to write them down. Noticed a pick me up with everything else, though (boot up, internet page load times, etc.) although it seems to have added 3 extra processes causing it to jump from 42 to 45 and thee is some MINOR lag (but way better than it was. Thanks, dude!). I did lose one of the svchost.exe process for a total of 8 and the 60,000K instance dropped to around 30,000K. My system Idle Process though is still stuck at 28K (this is supossed to fluctuate correct?). Have had no BSoD's yet so here's hoping. I have attached the logs as requested including an extra one to show which files I was able to delete. Thanks for your support and Merry Christmas.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try the beta version of ComboFix which is named KittyFix.exe

    Download ComboFix from http://download.bleepingcomputer.com/sUBs/Beta/KittyFix.exe and save it to your Desktop.

    Note: This is a beta version of combofix and might be unstable but tests done so far have proved it works well

    Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer.
    • Now Exit/Close/Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Close any open browsers and any other programs you might have running.
    • Double click on kittyfix.exe & follow the prompts.
      • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this
    • When finished, it will produce a report for you. Please attach the "C:\ComboFix.txt" to your next message.
    Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
     
  9. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    Done. KittyFix said that it detected a rootkit, then rebooted my machine. I also recieved a pop up shortly before my last post when I tried to sign into myloweslife . com. It was requesting the answers to my security questions, security code on the back of my card, and the PIN. I wasn't stupid enough to enter this and have been changing passwords ever since. I wonder if maybe it's hiding on the D:) drive since that one doesn't reinstall when I wipe the hard drive. Could this be why I am getting CHKDSK messages on boot up? Also, my process list dropped to 38 in task manager, but the sys idle process still seems locked at 28K.
     

    Attached Files:

  10. Throws_pc_out_window

    Throws_pc_out_window Private E-2

     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We will need to boot to the Recovery Console ( you installed it while you installed ComboFix) to remove this infection.

    1. Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command and boot back to normal mode, continue with the below.

    2. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    3. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    Done. Everything is running relly good now. Haven't had a blue screen since I ran Avenger and TDSSKiller. The only hiccups are that CHKDSK message for drive D:/ on boot up (That scans REALLY FAST. Less than 30 seconds.) and the system idle process still seems to be locked at 28K. Internet page loads are pretty much instantaneous now, as well as program start-ups.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you give us the exact word for word error message that appears?

    Also a note regarding System Idle Process:

    The system idle process is not a process, more a counter which is displayed in WinTasks used for measuring how much idle time the CPU is having at any particular time. This counter will display how much CPU Resources, as a percentage are 'idle' and available for use. So if you aren't doing much, your System Idle Process will be high :)
     
  14. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    I booted five times to get this: Checking file system on D: / The type of file system is NFTS / One of your disks needs to be checked for consistency. The rest goes by like Superman on speed -:-D. I also have some errors from event viewer concerning this and one from the security section which I am getting over and over again. I also have a message which appears when you open the START menu which says some of the programs cannot be shown because there is not enough room. Please choose smaller icons (done), or unpin some menu items (also done). Things are starting to slow down again. My page file has jumped back to 1.61 GB with just two open tabs (deviantart . com and yahoo . com). Thank you Kestrel13! for your patience and helping me out with this!
     

    Attached Files:

  15. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    It has also started beeping (like when you log into safe mode) when I am on the net. It just started now...
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you mean by that statement? What do you have on the D:\ drive? It is sounding like you are having a hard drive failure. (Kes is at work for the next few day....so please just answer those guestions.
     
  17. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    I have 2 partitions C: (OS) and D: (Data). If I reinstall Windoze from the partition it only deletes the data in C: (according to E-machines anyway.). I figured that since drive D: was safe, I would set up shortcuts in my documents to jump to drive D: and store everything there. I keep my music, artwork, pictures, and work files on it. Sorta like a 70 GB My Documents:-D. I was just wondering if whatever was screwing with me didn't also copy itself to that partition (sorry if it's a stupid question...I'm really just guessing).
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As I said, I am just jumping in while Kes is busy. So I haven't looked at all your older attached logs. But when you run both MBAM and SAS, you are checking the box to scan all drives, including the D: partition?

    If you have, and nothing was found, then I would start to consider the possibility of a Hard Drive failure ( the clicking or beeping sounds may be the indication of that.)
     
  19. Throws_pc_out_window

    Throws_pc_out_window Private E-2

    yeah, i did that. Hmmmmmm. How would you go about testing that? Seems like a buddy did something like that on an old Seagate drive. But MBAM and SASS were missing a few things that combofix picked up, like the rootkit for example. That's what led me to wonder. And jump in all you want to...sounds like I need ALL the help I can get - lol
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The problem with the D drive is not malware and formatting and reinstalling the C drive will not fix the D drive. Also running malware scans on the D drive will not find or fix anything since it is not malware. And even chkdsk will not fix the problem. You need to backup files on the D drive and then delete the partition, format, and copy your files back. However, this is not topic for the malware forum, you would have to discuss this more in depth in software if you need help.

    Final steps below! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. Throws_pc_out_window

    Throws_pc_out_window Private E-2

     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use this instead -

    "%userprofile%\Desktop\kittyfix" /uninstall

    * Notes: The space between the kittyfix" and the /uninstall, it must be there.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds