Lost control of computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by mam9103, Jul 8, 2008.

  1. mam9103

    mam9103 Private E-2

    Started having problems with windows millenium computer, and the situation has gotten worse. I ran spybot, avg, and have attached a mglogs.zip and a saslog.text. Here are a few things that I have noticed with the computer. Zone alarm asks "SSDP service on windows millenium to assess internet." If I answer yes then Azureus, Mike:Mike, and Mike:Mike appear under network places. The mouse stops during safemode. Spybot runs slow and mentions microsoft windows redirected host and virtumonde.dll during search terms. Cannot type anything whether an excel document, word document, find/search, or internet explorer search. If type internet address it says that internet explorer will open it for you dialogue box. A find what dialogue box pops up also. AVG mentions a hosts change (C:\windows\hosts). Lastly while trying to save the attachements many screens were opened such as excel, picture viewer, acrobat reader, and many more. Afterwards the background was highlighted and if left click opens my documents. These are a few of the weird things that my computer has done. Thanks in advance.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need to see the logs from MalwareBytes, ComboFix, and you need to re-run C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file but this time make sure you agree to the HJT license and let it run until it tells you it is finished.
     
  3. mam9103

    mam9103 Private E-2

    I tried to find combofix and malware bytes files. When I run combofix, it mentions cannot find'%system root%/regedit.exe.' When I run malware bytes, it says requires windows NT 4.0 or later, my system is windows millenium. Also sent two dialogue boxes: desktop file does not have program associate with it for performing this action, C:\MyDocument does not have program associate with it for performing this action. I ran MGtools again but it didn't ask about HJT license. Again I couldn't find the zip file. Where is it located. I have attached the to two text files though if that matters.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The MGLogs is exactly where it is supposed to be:
    C:\MGLogs.zip

    please attach that. :)
     
  5. mam9103

    mam9103 Private E-2

    I thought that is what I already attached, but here it is again because I ran the scan again. However, it didn't mention HJT question. I might need to reinstall it?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware ....let's see what an online scanner will detect ...Using IE:
    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    You can also try any of the online scanners listed HERE.
     
  7. mam9103

    mam9103 Private E-2

    Now the internet works without the dialogue boxes as mentioned before. I can also type documents without the dialogue boxes. Not for sure of why. I ran bitdefender anyways though, and it found no viruses. I guess it was a fluke? What about the hosts change, and the SSDP warnings (mentioned in first post)?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still getting the messages? Have you re-run Spybot?
     
  9. mam9103

    mam9103 Private E-2

    Everything seems to be running fine. Not for sure the reason for the loss of control because the scans resulted in little findings, a couple malware. Thanks for your input though
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (substitute for cf whatever you renamed it)
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds