Infected.. Not sure what all i have

Discussion in 'Malware Help (A Specialist Will Reply)' started by arronbullard, Mar 22, 2012.

  1. arronbullard

    arronbullard Private E-2

    My problems have been many. I have/had the google redirect. Think it may have been fixed, i did a file fix with microsoft and it made the redirect stop. It also made my mozilla connecct to the internet as it wasnt connecting, nor was my AIM which it also fixed i believe as they are connecting now. The odd part is IE was still connecting. And i tried the proxy but there was none. So im not sure if these are issues that may return or if they are fully fixed. I also keep getting recycle bin is corrupt. I have tried to run all the things like you guys request. But with the combo fix it gets stuck and i have to reboot after about 30 min into it. I have left it run for hours (over 4 i believe) and it wouldnt change. I will attach the logs. Thanks for your help in advance.
     

    Attached Files:

  2. arronbullard

    arronbullard Private E-2

    Sorry i also tried a system restore to a previous point and it wouldnt let me. Kept giving me errors.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to run MGtools as requested in the READ & RUN ME and then attach the C:\MGlogs.zip file it creates.
     
  4. arronbullard

    arronbullard Private E-2

    Sorry i knew i forgot to add one of them, but it wasnt on the desktop so i forgot it.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The MGtools log is very incomplete. Please shutdown any protection you have running and then run it again. This time make sure you wait until it finishes before attaching the log. Do not interrupt the command prompt window that opens. It will tell you when it finishes.
     
  6. arronbullard

    arronbullard Private E-2

    sorry. here is the new ran zip file.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto the below link and download the BFE.reg and MpsSvc.reg registry patches and save them to your Desktop.

    http://download.bleepingcomputer.com/win-services/vista/

    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the BFE.reg file saved to your Desktop and double click it. Allow it to be added to the registry. Repeat this for the MpsSvc.reg file.
    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
    O2 - BHO: (no name) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - (no file)
    O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
    O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
    After clicking Fix, exit HJT.

    Uninstall the below program:
    Ask Toolbar

    Now download The Avenger by Swandog46, and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. arronbullard

    arronbullard Private E-2

    When trying to uninstall the ask toolbar i got error 2738 could not access vbscript run time for custome action.

    I havnt got a chance to really use it more then that, but it appears to be running atleast quite a bit better.

    I still have the $recycle.bin file, but im not getting the corrupt error message i was getting for the recycle bin like before. But i have had it go away for couple days and then come back. So not sure if its truely gone.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A couple of your services are not running even though we applied a registry patch to fix them.

    Please click Start and in the Start Search box type type services.msc into the box. When you see the services.msc icon appear up above in the list, right click on it and select Run As Administrator. This will open up the Services form. Scroll down to theBase Filtering Engine service and double click on it. Start the service by clicking the Start button. Did it start? Set the Startup type to Automatic and then close the form for the Base Filtering Engine service.

    Now locate the Windows Firewall service and Start it and set the Startup type to Automatic, Did this Start?

    Now close the above services forms.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. arronbullard

    arronbullard Private E-2

    Neither one would start. The first one gave me error 5 no access denied. The firewall i got error 1068 the dependency service or group failed to start.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's see if we can get the permissions issue resolved.

    Now download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Repair Windows Firewall
      • Repair Internet Explorer
      • Repair Hosts File
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Windows Updates
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.
    Reboot after running Windows Repair.



    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click on resetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.


    Now see if you can start the BFE and Windows Firewall services. Even if you cannot, please do the below anyway.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  12. arronbullard

    arronbullard Private E-2

    ok both said they were started..
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, based on your logs, they are running properly now.

    Are you having any other malware problems?
     
  14. arronbullard

    arronbullard Private E-2

    Not that i know of.. I never did get combofix to run, was there a reason it wouldnt? Would that be a malware problem? Also i deleted/uninstalled the java i had on the computer and some of the and software i use for work dont work now, im just guessing but is that bc of the unistalling of java?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessarily. Sometimes it has problems running on certain PCs. If you are not having any other problems, I would not worry about it. If you are still having problems then we should look into it further. I will hold off giving you final instructions until I hear back that you are still not having any problems.

    Don't know since I don't know what software you are referring too and I would not know if it needs Java or not. Just reinstall Java and see what happens.
     
  16. arronbullard

    arronbullard Private E-2

    Dont currently have any problems that i can find.

    Thank you for all your help.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds