Malware Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by mahlerosa, Aug 28, 2012.

  1. mahlerosa

    mahlerosa Private E-2

    My internet access is painfully slow to the point of timing out.
    Dell seems to think it is a virus or something similar. I am stumbling thru this process I have I have attached everything you need to help me. I cannot for the life of my figure out how to save the log for hitman pro. It did not follow the same path as the direction stated.
    You help would be greatly appreciated.
    Thnx! Michelle
     

    Attached Files:

  2. mahlerosa

    mahlerosa Private E-2

    hitman
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    What are these files? If you do not know then delete them.

    • C:\Documents and Settings\Mahlerosa\Local Settings\Application Data\rwm24r6hc455p7p67o
    • C:\Documents and Settings\Mahlerosa\Local Settings\Application Data\cbp.exe

    Delete this folder:
    • C:\Program Files\Common Files\Spigot

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    • Click Start, click Run, type services.msc, and then click OK.
    • In the list of services, right-click Automatic Updates, and then click Properties.
    • In the Startup type list, click Automatic (if it is not already), and then click Apply.
    • If Service status is set to Stopped, click Start, and then click OK.
    • Right-click Background Intelligent Transfer Service, and then click Properties.
    • In the Startup type list, click Manual, and then click Apply.
    • If Service status is set to Stopped, click Start, and then click OK.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. mahlerosa

    mahlerosa Private E-2

    Ok I have done everything you sigested. Here is the attached file. When it got to the end a box popped up asking me if something I did not understand. I have attached a sceen print.
    I am rebooting.
     

    Attached Files:

  5. mahlerosa

    mahlerosa Private E-2

    I have rebooted and there are items in my start-up that I have not seen in a while. Like messenger. BUT now I have this funmoods that has taken over my IE and chrome. I found it last night while in safemode using superantispy ware. The program said it was removed but it is not. I am now in safemode rerunning superantispyware. So far it has not found it. I do not know if this is a new problem or part of the first problem.
    your help it appreciated. Thnx!! Michelle
     
  6. mahlerosa

    mahlerosa Private E-2

    My problem still exsists. My internet is really really slow. Like so slow I can click on a link on your site and go to the bathroom and it will still be loading.
    Is is faster in safemode if they means anything. Is it the funmoods or is it an additional problem?
     

    Attached Files:

    • OTL.Txt
      File size:
      104.7 KB
      Views:
      1
  7. mahlerosa

    mahlerosa Private E-2

    Anti-superspyware found the funmoods but after removal there are parts still popping up. But my original problem is still here. It took me probably 4 minutes of loading to get back to the forum to post. I had to disable trend micro to speed it up a bit. I do not know what to do from here. I am having you can help me as my business is on line and I can't make my living right now. :cry
    Much appreciated. Michelle
     
  8. mahlerosa

    mahlerosa Private E-2

    Update. I uninstalled Trend Micro again but did not reinstall it but instead installed Avast! and my internet is working better. But the stupid funmoods search is still popping up. Any suggestions?
    Michelle
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    
    SRV - [2012/07/26 19:40:56 | 000,794,560 | ---- | M] (Spigot, Inc.) [Disabled | Stopped] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
    DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\xuauhiwq.sys -- (xuauhiwq)
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0Bzz0A0CyC0F0A0B0D0Ezz0CtC0DyE0CtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1429552643
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0Bzz0A0CyC0F0A0B0D0Ezz0CtC0DyE0CtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1429552643
    IE - HKU\S-1-5-21-2830206439-242661526-2777770831-1005\..\SearchScopes\{B11C1FED-1BEF-4924-BF98-1408288EB94E}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0Bzz0A0CyC0F0A0B0D0Ezz0CtC0DyE0CtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1429552643
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Ask.com"
    FF - prefs.js..browser.search.defaultthis.engineName: "myplayyard Customized Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2402548&SearchSource=3&q={searchTerms}"
    CHR - homepage: http://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0Bzz0A0CyC0F0A0B0D0Ezz0CtC0DyE0CtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1429552643
    CHR - default_search_provider: search_url = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0Bzz0A0CyC0F0A0B0D0Ezz0CtC0DyE0CtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1429552643
    CHR - homepage: http://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0Bzz0A0CyC0F0A0B0D0Ezz0CtC0DyE0CtN0D0Tzu0CtByEtCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1429552643
    O4 - HKLM..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe" File not found
    [2011/05/21 05:48:48 | 000,019,312 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\rwm24r6hc455p7p67o
    
    :files
    C:\Program Files\Application Updater
    C:\WINDOWS\system32\drivers\xuauhiwq.sys
    C:\Program Files\Common Files\Spigot
    C:\Documents and Settings\All Users\Application Data\rwm24r6hc455p7p67o
    
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now run OTL like you did before - no fix - just a scan and attach the log.
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. mahlerosa

    mahlerosa Private E-2

    Here you go....
    When using the MGtools an trend micro hijack this windows pops up. Is it supposed to? I have enclosed a screen print of it. Also, right now when I open a new window in firefox the search pops up as funmoods.
    Thnx! Michelle
     

    Attached Files:

  11. mahlerosa

    mahlerosa Private E-2

    Also Hitman pro pops up and runs when I reboot. It is saying:
    a host needs to be repaired. C:/windows/system32/drivers/ect Host file compromised BOM obfuscation.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does Hitman give you the option to reset host file?

    We are going to be uninstalling your old version of FireFox and installing the new version. (But when you uninstall it please use Revo uninstaller!!! see instructions further below) So do the below to save bookmarks:


    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Is it redirecting now or is everything ok?
     
  13. mahlerosa

    mahlerosa Private E-2

    Hitman gives you the option of "repair".
    Should I?
    The other problems seemed to be cleared up.:-D
    Thank-you! Michelle
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not if everything is ok, I wouldn't ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. mahlerosa

    mahlerosa Private E-2

    Hi
    Ever since I cleaned my computer even though I ran the suggested program, my setpoint.exe gets and error when I shut down and I cannot restore to a set point.
    Any ideas?
    Thnx!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You'll be better off posting about it in the software forum ;) Not topic for this forum.
     
  17. mahlerosa

    mahlerosa Private E-2

    Even thought the problem started as part of my malware problem? As part of the fix I was told to turn off set point.
    I can;t find the info on the program to restore the setpoint.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Show me where please.
     
  19. mahlerosa

    mahlerosa Private E-2

    Is the System restore the same as the set point? Maybe I am confused.

    If you are running Win 7, Vista, Windows XP or Windows ME, do the below:

    Refer to the cleaning procedures pointed to by step 7 of the READ ME
    for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    Then reboot and Enable System Restore to create a new clean Restore Point.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Two totally different things, yes. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds