Is this a virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by sukatski, Dec 27, 2010.

  1. sukatski

    sukatski Private E-2

    When i turn on my pc i get :"Error loading C:\DOCUME~1\User\LOCALS~1\Temp\26440921.txt
    The specified module could not be found."
    how can i fix this? and is this a virus?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You could navigate to the temporary directory and delete the file, but it would be best for you to follow through with the below just to be safe.

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. sukatski

    sukatski Private E-2

    there even isnt a LOCALS~1\Temp\26440921.txt part.. it stops at User... or that folder is hidden?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, it is hidden. As I said, to be safe continue with my instructions that I previously posted.
     
  5. sukatski

    sukatski Private E-2

    btw.. i noticed that in every folder and desktop is hidden file thumbs.db dunno if this is related , so is it? and maybe i should try fixing mistakes with CCleaner?(on registry cleaner), plus i searched for that file when i turned off the hidding of files, still there isn't such file
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's normal. You obviously now have hidden files and folders set to show so that is why you are seeing those.
    You certainly could run the cleaner side of Ccleaner. (Not the registry section) and then see if the error continues. Or maybe you should simply follow the instructions that I posted earlier.
     
  7. sukatski

    sukatski Private E-2

    the error i get isnt malware? or the thumbs.db?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The thumbs.db is not malware. They are hidden files.
     
  9. sukatski

    sukatski Private E-2

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You mean when you try to run it. Well, just let it continue... do NOT mouse click or use the keyboard once it is running. It is very sensitive and doing so could cause the program to stall.

    Make a response again when you have logs to attach. :)
     
  11. sukatski

    sukatski Private E-2

    I waited but combofix.exe got the same error( i didnt even touch keyboard or moved a mouse ),and i used my own malware bytes 1,41 cause couldnt download the version u shared (somehow).Heres my logs.
    and does it change anything if scanned yesterday and gonna scan today ? or should i do it over from the start?
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes your version of Malware Bytes is out of date, so open up the program, locate the update tab > let it update and then re-scan > fix anything it may find, and attach the log regardless of the results.

    Now why am I not seeing a log from running MGTools.exe? Have you done so yet? If so then attach the C:\MGlogs.zip
     
  13. sukatski

    sukatski Private E-2

    oops.. i forgot .. i used all the programs in normal mode, should i redo them all in safe mode?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to do the scans in normal mode. I didn't ask for them to be run in safe mode. ;)
     
  15. sukatski

    sukatski Private E-2

    Ok, i turned on MGtools, it created some folders or files , but then nothing happened after.
    and when i turned on safe mode, i didnt got the error( the one i am blaming about)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes! Please attach the C:\MGlogs.zip
     
  17. sukatski

    sukatski Private E-2

    Sure
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And what about this?
     
  19. sukatski

    sukatski Private E-2

    oh , right.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This should do the job for you.

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Delete this folder:

    C:\Documents and Settings\User\AppData\LocalLow\MicroƱoft

    Uninstall the below software:
    • RegCure

    What is inside of this folder? Do you know what it realtes to? If not, Tell me or show me with a screenshot.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKCU\..\Run: [Configuring] rundll32.exe C:\DOCUME~1\User\LOCALS~1\Temp\26440921.txt,M
    • O18 - Filter hijack: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - C:\Documents and Settings\User\AppData\LocalLow\MicroƱoft\redir.dll
    After clicking Fix exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me ... how is the computer behaving at this point?
     
  21. sukatski

    sukatski Private E-2

    Ok, heres my ODUI folder->> http://img155.imageshack.us/i/22745924.png/
    as you can see theres ObjectDock, the program i used to get look like mac's...(i didnt even know if theres a virus or if there isnt).
    and heres my MGlogs.zip >>
     

    Attached Files:

  22. sukatski

    sukatski Private E-2

    Hmm i just restarted my pc, and im not getting the error :)). should i do anything more , or we are done here? :)
     
  23. sukatski

    sukatski Private E-2

    plus.. could that virus or malware see the passwords i used? and should i change them?
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes the objectkdock folder is fine.

    You do any online banking? If so you should change the passwords. Best to be safe.

    Delete the below folders:
    • C:\Documents and Settings\User\Application Data\DriverCure
    • C:\Documents and Settings\User\Application Data\ParetoLogic
    • C:\Documents and Settings\All Users\Application Data\ParetoLogic

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  25. sukatski

    sukatski Private E-2

    Few more questions:could the virus read game passwords(not the browser ones),and should i leave msconfig at normal startup?
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I doubt it would bother. But like I said, do change them if you wish!

    Yes. I believe I said to you before that you should always remain in normal start up mode. Any other mode is used primarily for diagnostic and troubleshooting purposes.
     
  27. sukatski

    sukatski Private E-2

    Forgot to say something...Thank you so much ! :) :) :) :) :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hey you're welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds