Infection Cleared But Damage Still Present

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gmoney Cricket, Jul 1, 2010.

  1. Gmoney Cricket

    Gmoney Cricket Private E-2

    I had some type of Trojan virus attack my PC that resulted in fake anti-virus (AV) program pop-ups and all sorts of IE window openings. I ran Malwarebytes and detected 14 infected files. These have all been removed, but I am having connectivity issues with many programs now. I got Firefox to work by re-installing it from an external file. However, other programs that require connectivity are not functioning. I tried to repair the connection, but it says that the DNS is not accessible. The only way I got Firefox to work was to go in and change the proxy to automatic detection. It seems there is a problem there. In any case, I would like to solve this issue for the entire computer. Any advice?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Gmoney Cricket

    Gmoney Cricket Private E-2

    I have Firefox up and running now, but IE is totally corrupted and looks like it may need to be reinstalled. However, all other programs are suffering from a connectivity issue. This would include WOW, iTunes, etc..... Any suggestion as to how I can remedy this?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Gmoney Cricket

    Gmoney Cricket Private E-2

    Sorry it has taken me so long to get back to this. I completed the READ & RUN ME FIRST steps, and have attached all of the logs here. In an additional posting, I included the log from the MalwareBytes scan I ran immediately after the infection. I would appreciate any advice you could offer.

    Thanks!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is this:
    C:\SECREC? If it is a folder you created, then you need to take ComboFix out of it and put it directly on your desktop, not run it from here:
    Running from: c:\secrec\ComboFix.exe

    I am not seeing much in the way of malware, so let's do this:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now make sure you have nothing set as proxy servers:
    Change Proxy Settings.

    Now use windows explorer to find and delete:
    c:\documents and settings\aok\Local Settings\Application Data\pdsgtuxdj

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds