I think it's Malware, not for sure.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mysterymaiden, Feb 14, 2011.

  1. Mysterymaiden

    Mysterymaiden Private E-2

    I was recently attacked by Avira Anti-virus.
    I did a Malwarebytes scan immediately, and it only found two things. I then did a virus scan using my Avast! scanner, and it found nothing.

    I have used Combofix before to help with a virus, and it worked well. Combofix stopped all the pop ups and such, and I no longer see the icon on my desktop.

    My problem is, my anti-virus has been disabled and will not come back up. When logging on to my account, it either takes more than five minutes for the screen to change or it just stops and freezes entirely.
    I tried looking in my registry and my programs but have found nothing in relation to Avira.
    A friend then suggested doing a system restore, and all it did was bring back my MSN messenger to where when I log on, it pops up. With time.
    I have also installed Revo Uninstaller to get rid of any traces. Nothing.

    Is this just malware, or is this still apart of the virus?
    Any tips on how to stop this issue is greatly appreciated.

    Also: At the begging of the Combox fix scan, it said: "file or system "C:/WINDOWS/regedit.exe" is infected, and attempting to disinfect it." It would do some type of restore, and then continue on with the scan.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Then the infected file will need to be replaced which we will get to.

    Ensure that you have followed the below procedures and attach the requested logs.

    READ & RUN ME FIRST. Malware Removal Guide
     
    Last edited by a moderator: Feb 15, 2011
  3. Mysterymaiden

    Mysterymaiden Private E-2

    Sorry for the late reply. Scanning everything took some time!
    Ok. I was able to get the logs, but I wasn't able to find them to upload them.

    So, I shall have to copy and paste. Sorry.



    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~






    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



     

    Attached Files:

    Last edited by a moderator: Feb 15, 2011
  4. Mysterymaiden

    Mysterymaiden Private E-2

    And here's Root Repeal.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~





    I did notice my computer is working a whole lot faster, but it still seems to lag a bit in the start up process.
     

    Attached Files:

    Last edited by a moderator: Feb 15, 2011
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. Mysterymaiden

    Mysterymaiden Private E-2

    Hopefully this works!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still need to attach the log from running C:\MGTools.exe --> C:\MGLogs.zip.
     
  8. Mysterymaiden

    Mysterymaiden Private E-2

    I'm sorry, but I do not understand. Are you asking me to convert the logs in to MGLogs.zip?
    Or maybe I'm forgetting something......?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Once you have downloaded MGTool.exe to your C: drive, then double click the exe file ( Right click if using Vista and run as admininstrator), this will give you a command prompt. Let it run until it tells you it is finished. It will automatically create the log located at C:\MGLog.zip. Just attach the zip log.
     
  10. Mysterymaiden

    Mysterymaiden Private E-2

    I didn't get any type of prompts or any popups like the help link for the MGtool said. As soon as I clicked Run, it started to scan.

    I do see a zip folder with that title. It has alot of stuff in it. I'm guessing this is what you're talking about?
    (If I come off painfully retarded right now, my apologies. I'm on two hours worth of sleep. Combined with that, and I'm completely clueless on this type of stuff I'm a bit......wonky. Bear with me)
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh don't worry. All the logs are attached and I shall review them once I have made a cup of tea! Shall post a fix shortly :)
     
  12. Mysterymaiden

    Mysterymaiden Private E-2

    Merci, I seriously appreciate it.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\Compaq_Owner.YOUR-45C550F850\desktop\MGtools.exe <--- delete this. Not the location we asked for it to be downloaded to.
    C:\Documents and Settings\Compaq_Owner.YOUR-45C550F850\desktop\MGtools (1).exe <--- delete this

    Uninstall the below outdated Java
    • Java 2 Runtime Environment, SE v1.4.2_03
    • Java(TM) 6 Update 15

    Foxreal YouTube FLV Downloader Pro version: 1.0.1.1 <--- Uninstall this and use something like downloadhelper instead.

    You also have many SUPERantispyware files on your desktop which should be in their own folder when SAS was installed. I do not know why they are scattered all over the desktop.

    What are you using for antivirus? Norton/Symantec?

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\ServicePackFiles\i386\proquota.exe | c:\windows\system32\proquota.exe
    C:\WINDOWS\ServicePackFiles\i386\regedit.exe | c:\windows\regedit.exe
    DirLook::
    c:\documents and settings\Lora's dungeon\Local Settings\Application Data\{EBCB52A3-2438-4793-9BD4-A626E77B75F5}
    File::
    C:\WINDOWS\system32\svchost.exe.exp.log
    C:\WINDOWS\system32\atmfd(5).dll
    C:\WINDOWS\system32\urlmon(4).dll
    C:\WINDOWS\system32\wininet(4).dll
    c:\documents and settings\Lora's dungeon\Local Settings\Application Data\Xbapulivihan.bin
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now! :)
     
  14. Mysterymaiden

    Mysterymaiden Private E-2

    Ok. When I tried right clicking on the screen on MBRCheck.exe, nothing would show, then the screen disappeared.

    I will give you the logs after I reboot.
     
  15. Mysterymaiden

    Mysterymaiden Private E-2

    I use Avast! But I uninstalled it yesterday, thinking that maybe the virus had gotten to it, and I was planning on reinstalling. I didn't really like Norton too much, because it bogged down my system.

    My computer is working really swift and crisp right now! :)
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\regedit.exe
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
     
  17. Mysterymaiden

    Mysterymaiden Private E-2

    What exactly am I looking for when I click the browse button on the site?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Click browse and then navigate to this file to upload

    Combofix is still reporting it as infected after I replaced it, I just want another opinion! So let's see what Jotti says. Or... if not Jotti, this website:

    Please go to virustotal and upload the following files for analysis, and let me know the results.

     
  19. Mysterymaiden

    Mysterymaiden Private E-2

    Just so I know I'm doing this right, I'm supposed to scan through all these folders and their sub folders?
    Or I'm not at the right destination? Lol.
    I clicked windows at the C drive, did a search, and this is what popped up.

    http://tinypic.com/r/2vv6m86/7


    (by the way, I'm using windows XP)
     
    Last edited: Feb 16, 2011
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run Combo and get us a new log.
     
  21. Mysterymaiden

    Mysterymaiden Private E-2

    Here it is...
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log indicated that it did restore a clean copy of regedit. What issues are you still having, if any?
     
  23. Mysterymaiden

    Mysterymaiden Private E-2

    Everything seems to be in working order.
    My computer is working very swiftly, and precisely.

    Am I done with everything?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  25. Mysterymaiden

    Mysterymaiden Private E-2

    Ok, done.

    Thanks so much for your help guys!
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds