Malware Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by sparks_uk, Sep 1, 2012.

  1. sparks_uk

    sparks_uk Private E-2

    Hi Major Geeks
    Have complete the Read and Run Me guide and have posted logs.

    The problems I've been getting , being redirected when searching, sound of people talking or music comes through the speakers which I have no control over.
    This all started when a window appear saying that I had a hard drive problem press ok to fix it, yes like an idiot I press ok blaar blaar blaar, I'm sure you MG's have heard it a million times ( can't even blame the kids for this one).

    My main anti virus software is McAfee which is not picking anything up, so every couple of days I've been running Super Antispyware which picks up over 100 tracking cookies with each scan.

    Any Help would be appreciated

    Just a side question, I have the full package with McAfee, why is it not picking any of this up.

    Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the logs from running MGTools.exe--- C:\MGLogs.zip.
     
  3. sparks_uk

    sparks_uk Private E-2

    Thanks for the reply TimW,

    You asking for the MGlogs has shown me I've got other problems, when it first hit I remember that My Doc files became hidden, which I reversed and now I seem to have lost all my photos in My Pics.

    Back to MG tools I couldn't find the logs in MGlogs, for some reason the tdskiller logs where in there, so I run the MG tool another 3 or 4 times and then I reallised that the MGlog file has 1.3 Mb in it and the tsd files only add up to 300 Kb.
    I have right click and extract all, but all that appears in other MGlogs folder are the Tdskiller logs.
    I using Window 7 for a bit more info.

    Sparks UK
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. sparks_uk

    sparks_uk Private E-2

    Hi
    Posted OTL and the MGlog zip file has appeared, it wasn't there before, I'm sure it wasn't.

    Anyway posted MGlogs, but the whole zip file, hopefully file not to big to be posted. didn't know which one.

    Thanks TimW
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will be helping you along as TimW is very busy.

    Uninstall the below:

    • iLivid
    • MediaBar

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=4e1a161e0000000000004487fc9d0e4f&tlver=1.4.19.19&affID=17162
    IE - HKLM\..\SearchScopes\{44f44034-6036-4f06-9336-74ec4620edab}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=RGxdm331YYgb&ptb=52DA402E-E063-47A2-A66D-A81A965F6F20&ind=2011110610&ptnrS=RGxdm331YYgb&si=1579ciduk&n=77df1cd2&psa=&st=sb&searchfor={searchTerms}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms}
    IE - HKCU\..\SearchScopes\{136E381E-FD91-4420-A457-8F2B62BE29CA}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3196716
    IE - HKCU\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=4e1a161e0000000000004487fc9d0e4f&tlver=1.4.19.19&affID=17162
    IE - HKCU\..\SearchScopes\{44f44034-6036-4f06-9336-74ec4620edab}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=RGxdm331YYgb&ptb=52DA402E-E063-47A2-A66D-A81A965F6F20&ind=2011110610&ptnrS=RGxdm331YYgb&si=1579ciduk&n=77df1cd2&psa=&st=sb&searchfor={searchTerms}
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms}
    IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb174/?search={searchTerms}&loc=IB_DS&a=6PQHByUE7Z&i=26
    [2011/03/01 21:51:04 | 000,002,423 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    [2012/08/02 12:57:26 | 000,000,072 | -H-- | C] () -- C:\ProgramData\-Bf2ZCnggHGzsQsr
    [2012/08/02 12:57:26 | 000,000,072 | -H-- | C] () -- C:\ProgramData\-Bf2ZCnggHGzsQs
    [2012/08/02 12:57:17 | 000,000,368 | -H-- | C] () -- C:\ProgramData\Bf2ZCnggHGzsQs
    [2011/10/26 16:29:48 | 000,000,000 | -H-D | M] -- C:\Users\RIXS\AppData\Roaming\Babylon
    [2011/09/15 18:15:47 | 000,000,000 | -H-D | M] -- C:\Users\RIXS\AppData\Roaming\Bandoo
    C:\ProgramData\eObGhGc08505
    @Alternate Data Stream - 125 bytes -> C:\ProgramData\Temp:DFC5A2B2
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.



    Click start > and type in services.msc
    Scroll down to the Background Intelligent Transfer Service and let me know it's status and start up type if it is listed please.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Please download aswMBR.exe ( 511KB ) to your desktop.

    Double click the aswMBR.exe to run it.

    http://i1111.photobucket.com/albums/h479/MysticalMagpie/4.jpg?t=1303863006

    Click the "Scan" button to start scan

    http://i1111.photobucket.com/albums/h479/MysticalMagpie/5.png?t=1303863051

    On completion of the scan click save log, save it to your desktop and post in your next reply.
     
  7. sparks_uk

    sparks_uk Private E-2

    Thanks Kestrel13! for taking up my case,

    Have down loaded aswMBR.exe, but it will not run. Have try to run it as admin'
    and scan with super anti spyware, then try to run it. Also try to rename it on the desk top then run it but no luck.

    Uninstalled the two items
    I have run OTL and posted log
    The Background ITS
    Status - Started
    Startup type - Automatic (delayed start)

    Thanks again
    Sparks_uk
     

    Attached Files:

  8. sparks_uk

    sparks_uk Private E-2

    Sorry forgot MG log
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning Sparks, let's try this please.

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  10. sparks_uk

    sparks_uk Private E-2

    Good Morning Kestrel13!

    Here's the MBR log

    Sparks
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sparks you have an MBR infection. Do you have your Windows 7 boot CD/DVD?
     
  12. sparks_uk

    sparks_uk Private E-2

    Hi Kestrel13!

    No, I didn't get a disk. Windows 7 was already loaded when I brought it. I believe its on my hard drive somewhere?

    Sparks
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you don't have your Win7 disc, you can create a Recovery Environment disc for your system below: (small fee but worth it!)

    Download Windows 7 System Recovery Discs

    You can use ImageBurn to create the disc.

    Once the disc is created, boot into the bios and change the boot order to CD/DVD as first boot device. Put in the disc and reboot. Once in the RE, type this:

    Code:
    Bootrec.exe /fixmbr
    Note the space after the exe.

    Exit out when done and boot back into normal mode. Re-run MBRCheck and attach the new log.
     
  14. sparks_uk

    sparks_uk Private E-2

    Kestrel13!

    Have down loaded Windows 7 recovery disc and have alter the bios so dvd is the first boot device, but I won't load the disk brifley I get a black screen then windows starts. I have down loaded program 4 times on 4 different disc, can't seem to load it.
    also now I'm 100's at a time failed notices on email though not sending any email.

    I have got 3 windows recovery disc, which I made when first got the computer, don't know if these can help.

    Sparks.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you burn the disk at the correct speed?
     
  16. sparks_uk

    sparks_uk Private E-2

    The DVD have x16 on them, and has been burning at x16. Used also some cd and try to burn them at x5 but from the log ImageBurn burned it at x16.
    Think DVD writer lowest setting is x16.

    Sparks
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Sparks, did you follow these instructions for burning an ISO image with ImgBurn?

    Are you able to use another computer to burn this? So we can rule out yours as being troublesome?
     
  18. sparks_uk

    sparks_uk Private E-2

    Hi Kestrel13!

    Just burnt disc on someone else's computer, we transfer the file via drop box then burnt it.
    The differents to instruction was that the file was in my download file not on my deck top.
    Still no luck, I check each time that the dvd is on 1st boot, but windows starts up.

    Sparks
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try these instructions

    Now that you have the DVD, you need to boot from it to access the Windows 7 System Recovery Environment. You can read details about this in the below link:

    http://www.bleepingcomputer.com/tutorials/tutorial161.html

    Once you have gotten to the command prompt, you need to run the below command

    bootrec.exe /fixmbr


    Then you will reboot normally back to Windows and attach a new log from MBRcheck
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can't boot to the disc, let's try having you navigate to the C:\MGtools folder and double click on mbrfix.bat ( If not sure how to use Windows Explorer, you can optionally click Start > Run and enter C:\MGtools\mbrfix.bat into the run box and click OK. ) This will run quickly flashing a black screen in front of you too fast to read.
    NOW REBOOT!
    After reboot, re-run MBRCheck and attach the log.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    Then attach the new C:\MGlogs.zip file
     
  21. sparks_uk

    sparks_uk Private E-2

    Hi Kestrel13!

    Tried bleeping computer, pressing f8 at differnet times, but Windows kept starting normally. Have run mbrfix suggested by TimW and have posted log.

    Also have had my BT email account suspended by BT as it was being 'hacked' ( there words not mine) whether this is related.

    Thanks again
    Sparks
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you run MBRcheck afterwards?
     
  23. sparks_uk

    sparks_uk Private E-2

    log for mbr
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please delete your MGTools. ( You can run C:\MGtools\MGclean.bat ). Ensure the MGTools folder is gone afterwards and also the MGlogs.zip. Now download the latest version of MGtools and save it to your root folder.

    Run the MGTools.exe and attach the new C:\MGLogs.zip.

    Also explain what you see on the DVD please.
     
    Last edited by a moderator: Sep 16, 2012
  25. sparks_uk

    sparks_uk Private E-2

    On the dvd is a folder called boot and boot.cat
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run HitmanPro, spraks, does it detect the below?
    If so let it take action on it. Let me know how you get on.
     
  27. sparks_uk

    sparks_uk Private E-2

    Run Hitman pro, yes it picked up win64/boot , i think it said it was going to replace it.

    Just run ccleaner, then I ran super anti spy and It did not pickup any adware or virus at all.
    Is it to early to say we ( the royal we) might have got it.

    Sparks
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rerun Hitmanpro then now and show me (attach) the new log please.
     
  29. sparks_uk

    sparks_uk Private E-2

    Hit man pro log posted
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is everything running as it should do? :)
     
  31. sparks_uk

    sparks_uk Private E-2

    Hi Kestrel13!
    Sorry the delay in reply,
    Computer is running much better, no more redirect or sounds coming through.
    Run super anti spy still picking up 100+ adware, does seem to effect the computer.
    Still find ing files that are hidden but the mains ones are all back.

    Thanks for your time and effort in helping me, ( and TimW).

    Sparks UK
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. It was a long process I know. You sure all is well Sparks? If so...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds