Malware Issue

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Cheryl Arensberg, Jun 1, 2011.

  1. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    I recently had friends tell me that my system was sending out forwards. I never send forwards so that was my first clue that I had some kind of malware. I followed all of the instructions in the Read Me post . Each thing I ran, MG Tools, Combo Fix, Super Anti spyware, Avg antivirus, Malware Bytes, all seemed to find and delete spyware. I hoped that would catch the problem but it appears the system is still infected. This morning I had emails from friends telling me they were still receiving forwards from me. I never send forwards so this is still the virus. Attached are the logs from running those programs.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please attach the below log:

    C:\Documents and Settings\cheri\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 05-31-2011 - 21-31-33.log

    Uninstall the below softwares 2 of which are garbage, the others are outdated java.
    • StartNow Toolbar 2.0
    • InstallIQ Updater
    • Java(TM) 6 Update 17
    • Java(TM) 6 Update 6
    • Java(TM) 6 Update 7

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
    O2 - BHO: WindowShopper - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files\Superfish\Window Shopper\SuperfishIEAddon.dll
    O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
    O9 - Extra button: Window Shopper - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files\Superfish\Window Shopper\SuperfishIEAddon.dll
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    After clicking Fix exit HJT.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Will get to work on that right away
    Thank You
     
  5. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Sorry I forgot to attach spyware log here it is
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, keep going. But bear in mind it's half past one in the morning for me here so I may get around to a response tomorrow if not this tonight. Attach the rest of the requested logs. :)
     
  7. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    No problem on the sleeping. I just appreciate that you do this at all so I can wait.
    But I think I must be doing something wrong with the the MG Tools analyze.
    The black box comes up when I double click and it runs but there seems to
    be no way for me to get the scan only. When it gets to analyze it just tells me that it's done.
    None of these come up or nothing asking for a fix.

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
    O2 - BHO: WindowShopper - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files\Superfish\Window Shopper\SuperfishIEAddon.dll
    O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
    O9 - Extra button: Window Shopper - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files\Superfish\Window Shopper\SuperfishIEAddon.dll
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue on for now and we can handle those in a different way later on.
     
  9. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Still encountering very slow start up. Takes a while to get Opera to load.
    Did the log attaching it. Have also updated Java.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run CCleaner and then go back to these folders and make sure they are cleaned out. Remove everything that you can:
    C:\WINDOWS\TEMP\
    C:\Documents and Settings\cheri\Local Settings\Temp\

    Your problem with email needs to be manually cleaned out. Load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. You may have to create a new folder and move only emails you really need into the new folder and then delete the infected folder. What email program are you using?
     
  11. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Using Yahoo mail. At least that is where the offending mail came in. Where do I find CCleaner?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can get CCLeaner HERE.
     
    Last edited: Jun 2, 2011
  13. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Used CCleaner and removed everything I could. I also deleted all emails in my inbox, spam, trash folser in yahoo.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should do it. Let us know if you still have issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  15. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Thanks so much. Will follow these steps and follow through as suggested.
    I really appreciate the help.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  17. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Ran into a problem uninstalling combo fix with these instructions

    If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "%userprofile%\Desktop\combofix" /uninstall
    Notes: The space between the combofix" and the /uninstall, it must be there.
    This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    I get a message to uninstall my Anti Virus. When I use start and type into the
    box it seems to load combofix and not uninstall it
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you download ComboFix? Is it on your desktop?
     
  19. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Yes it is on my desktop. When I do that it seems to be loading and then AVG
    ID's it as malicious program. I momentarily disabled AVG to see if I could then uninstall and it again seemed to load instead of install, but this time without the AVG interferance
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can just right click Combo and delete it. Then go to the C:\Qoobox folder and delete it. If you ran it, you can delete the C:\ComboFix.txt.
     
  21. Cheryl Arensberg

    Cheryl Arensberg Private E-2

    Ok Will do. Thanks
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds