Internet problems(need help fast)

Discussion in 'Malware Help (A Specialist Will Reply)' started by -DaVe-, Jun 24, 2008.

  1. -DaVe-

    -DaVe- Private E-2

    hi guys
    i have been experiencing a lot of problems with many sites, most of the websites i normally use i am unable to open them in my internet explorer or firefox, all these problems started occuring about 3 days ago, everything was running perfectly fine before that. then a friend of mine told me to take a hijackthis log and post it on this site, i hope u guys will be able to help
    thnx in advance
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. -DaVe-

    -DaVe- Private E-2

    thnx a lot chaslang, i followed all the steps in that thread and now i think all the malwares are removed from my pc and i am able to surf the way i used to, i just have one question
    could i remove all the softwares i installed in the process to remove all the malwares?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the infection you had, you really should complete the procedure and attach ALL of the requested logs. There is a strong possibility that you are still infected even if you are not seeing signs of it.
     
  5. -DaVe-

    -DaVe- Private E-2

    i attached all the logs from my scan, am i still infected?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To answer that question, you need to attach the last and most important log from MGtools. The log will be where stated..... C:\MGlogs.zip
     
  7. -DaVe-

    -DaVe- Private E-2

    opps forgot to attach those logs, but there are 5 logs there, and the maximum files i could attach are 3, which ones should i add?
    sorry if i am being pain in the ***
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only the one the instructions in the READ ME asked for and that is the same one I asked for in my last message. And that is C:\MGlogs.zip The instructions did not tell you to look inside of the C:\MGtools folder for anything.
     
  9. -DaVe-

    -DaVe- Private E-2

    oh alright, attached the zip folder, hope everything would be fine in my computer
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The worst is over but we have a little more to do. :)


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {EB1E1C3F-8FCB-4B97-B1A3-010EAFFDC591} - C:\WINDOWS\system32\ddcBSmME.dll (file missing)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O20 - Winlogon Notify: jkkLBSMd - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now delete the below file:
    C:\WINDOWS\BMb3ab802f.txt

    Now look for the below folder which is on your Desktop. It is named with an illegal character in the name so I'm not sure what it will look like to you but you should be able to find it. If you did not create this yourself (and I doubt you did) then delete the folder:
    Code:
    "C:\Documents and Settings\Owner\Desktop\"
    ÿ             Mar 27 2008              "ÿ"
    
    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. -DaVe-

    -DaVe- Private E-2

    thnx a lot bro for all the help, my computer is running perfectly fine and i did all the steps u asked me to do except one where u told me to delete a folder thats on my desktop, i created that folder my self which is invisible thats why u think it named with a illegal character, i have some important stuff in that folder thats y i didn't delete it, do i have to remove that folder?
    oh and i did receive the success message when i ran fixme.reg file
    the zip folder is attached:)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you do not but you see the danger in doing this and have an illegal file name. And did you also notice that I could see it which means it is not really invisible. ;) What program/tool did you use to do this? Or did you just use the trick to erase the folder name and enter an illegal character using the ALT key. For example, like this: http://www.iambetterthanu.com/2007/10/09/create-an-invisible-folder/




    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
    Last edited: Jun 29, 2008
  13. -DaVe-

    -DaVe- Private E-2

    ye i did use that trick to make the folder invisible, but i guess its not anymore since u caught it:cry, lol
    did the final steps but u left out one thing, should i uninstall the spybot search & destroy and ccleaner too?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I did not leave it out. I guess you did not really read all of this How to Protect yourself from malware! ;)
     
  15. -DaVe-

    -DaVe- Private E-2

    ye u didn't leave it out, i read that thread after i had replied here
    anyways thnx a ton man for all ur help, really appriciated
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds