Issues with malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lindon, Dec 20, 2010.

  1. Lindon

    Lindon Private E-2

    Hey guys,

    Been having some issues with my computer so I was searching for malware removal instructions and I came across your site. Its been helpful so far, however I think I may have issues that I have been unable to fix.

    Am running Windows 7 64 bit version.

    Anyway, a bit of background information. Went to the read and run first post, have done most, if not all of it. When I removed java to update, my computer lost all internet connection. I had to download the up to date java version onto a 4 gig flash disk that I am using to transfer all files/programs to and from my computer at the moment. I saved all the programs to the desktop on another computer, copied them and placed on the flash drive, then copied to the desktop of the computer I am trying to fix, where I ran them (except in the case of MGTools, which I created the root directory C:\MGTools).

    Not certain whats going on, but my adsl modem says that I am connected to the internet, however when I try to run any browsers, they are unable to connect, and all the programs that have tried to update themselves automatically (SUPERAntiSpyware and Malwarebytes Anti-Malware) have failed. Can't recall the messages of the top of my head, I believe SAS told me that it was blocked by the firewall. I'm currently running ESET Smart Security. When looking in network connections while trying to update SAS, I didn't even see it attempting to connect.

    Anyway, I ran SAS portable as it was downloaded from this site. It found and removed 2 threats, however it didn't seem to log them. When looking at the log, there are no entries, however I ran the scan last night and certainly recall the two entries. Won't be able to attach a log for that.

    MAM was run, it detected four threats, and the log is attached. I do note that when running I was informed that it was 22 days out of date. Unable to connect to the internet to update, I downloaded the offline update files that you have here and installed them, and was told that the scanner was 15 days out of date at the time of running. Not certain if I need to download further updates.

    Ran combofix from the desktop. Was not present for most of the scan, logs are attached.

    Did not run RootRepeal.

    Ran MGTools and have attached the logs. Did note that when running MGTools.exe that all the scans started immediately, which was strange as I am running Windows 7 and your instructions for MGTools said that the scans would not start automatically upon running MGTools.exe.

    I still do not have connection to the internet, despite all the lights on my modem indicating that I do. Not certain if uninstalling Java completely has caused any conflicts or affected the software that came with my modem.

    Any help would be appreciated.

    Thanks

    Lindon
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try and run SUPERantispyware in safe mode or rename it's executable to 123.com and try again.

    Let's try going to the repairs tab in SUPERantispyware,use the Repair broken Network Connection (WinSock LSP Chain) option. Let me know how that goes.

    Did that help with your connection at all?
     
  4. Lindon

    Lindon Private E-2

    Booted the computer in safe mode, ran SAS - the file name im running it from is SAS_7489.COM from the desktop - the file name that the portable version of SAS was downloaded as. Every time I run the file, it asks what default language I would like to start it in. Not certain if this is an issue.

    Ran the repair broken Network Connection - computer required a restart, let it boot back into normal windows. Tried Firefox 4 (Beta) my default browser, still can not connect to the internet.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How about stable versions of browsers? Using a beta browser while investigating connection troubles is not a good idea really.

    Did SAS find anything?
     
  6. Lindon

    Lindon Private E-2

    Ran SAS in safe mode, no harmful files found.

    About a week or so ago I uninstalled all other browsers excluding Firefox beta. I do have Internet Explorer 7, which I don't use and which doesn't connect to the internet either.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then I would suggest you further discuss this and hopefully get the issue resolved in the networking forum. I am not seeing any malware in those logs.

    But before you do, just run this, I am curious to see whether it will find anything or not, but I suspect not.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  8. Lindon

    Lindon Private E-2

    Ok, so I can get the internet working, however it drops out oddly. I think I may head over to networking, after I've contacted my internet provider just to check if they are dropping out and maybe speak to their tech support if need be.

    Back to the malware issue, once I got the internet working, I updated SAS and MAM and ran a scan with MAM, then booted to safe mode and ran a quick scan with SAS. MAM found 1 threat, SAS found none. Logs for MAM are attached.

    Downloaded TDSS and ran it, logs attached. Nothing detected in that.

    So, am I just paranoid? A few issues with malware, but nothing major? I'm not certain myself, which is why I'm asking.

    Appreciate all the help.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reboot the machine, and then run a scan in NORMAL mode (not safe mode) for both SAS and MBAM and attach the logs here.
     
  10. Lindon

    Lindon Private E-2

    Rebooted, scanned with SAS and MBAM in normal mode, no threats found with either. Logs attached.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then try the networking forum as earlier suggested.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. Lindon

    Lindon Private E-2

    Alright, thanks for that. Will be calling my ISP tomorrow morning, and will jump on the networking forum if the problem persists.

    Thanks for your help.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! :) safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds