Infection help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Elgin_McQueen, Jun 3, 2010.

  1. Elgin_McQueen

    Elgin_McQueen Private E-2

    Am unsure what details are needed so here goes.

    Am running Windows Vista SP2 32bit.

    Have recently had problems with Google Chrome, when clicking on results from google searches or opening pages using the scroll wheel button it tends to redirect to other pages, there appears to be no attempt to download anything or to attack my computer but who knows?

    Have also started having a problem with my computer when starting up, ocassionally it will load up incorrectly, graphic settings have altered, my desktop and some desktop files will not appear and it may need restarted several times before a correct boot-up takes place. This started around the same time that my computer would freeze as a burn started when burning items to disk, burning to disk can be overcome by putting the comp into safe mode however.

    Using the instructions here i've attached the logs requested. Except the MGTOOLS one as I couldn't get it to run at all.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You probably will need to uninstall AVG in order to get MGTools to run. See this:

    Please go here and download and run the AVG Removal Tool.

    If the MGTools folder has been created, then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  3. Elgin_McQueen

    Elgin_McQueen Private E-2

    That worked, cheers. MGTools log attached to this post.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware other than what was removed by SAS and MBAM. Could you tell me what these are:
    C:\ProgramData\188FmQ8
    C:\ProgramData\a65er40Yy680
    C:\ProgramData\jrNYi6G

    I see you have run TDDSKiller in the past, so I would like to see a new log from running it:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.
     
  5. Elgin_McQueen

    Elgin_McQueen Private E-2

    Apparently they are system files created on the 16th, 18th and 17th of April this year respectively. There is another one at C:\ProgramData\U860 also created on the 16th.

    Here's the TDSS log.

    Browser-wise I don't seem to be getting the redirects anymore. When opening multiple tabs in chrome typically at least half of them would redirect but have just tried it out now and they all opened correctly.
     

    Attached Files:

    Last edited: Jun 3, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log was clean. Can you right click those files and check the properties. See if they are signed? Also tell me what issues you are still having.
     
  7. Elgin_McQueen

    Elgin_McQueen Private E-2

    I assume that would come under the details tab. No info there except file size, type of file and date modified for all 4 files.

    Browser redirect seems to be fixed. Tested in Chrome, FF and IE8 and there were no problems whatsoever. The computer has obviously restarted a few times whilst running all these programs, disabling UAC etcetera and appears to have come back up running fine each time. From what I can see at the moment, things appear to be back to normal. :)
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, I would go ahead and delete those files. Good to know things are running well, so If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  9. Elgin_McQueen

    Elgin_McQueen Private E-2

    Done and dusted. Cheers for the help. Impressed at how you responded. :D
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds