Malware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lithium5, Oct 1, 2010.

  1. Lithium5

    Lithium5 Private E-2

    Hi guys,

    I'm having a lot of problems with trojan horse malware etc. I tried everything, but they are still on my laptop.

    It started a few weeks ago.
    I ran trough your 'read me first' topic, installed everyting, ran everyting and my computer was functioning back to normal (as I thought).

    But yesterday the problems started again. Suddenly a window pops up, saying that Iexplorer.exe is a virus and I can't go on the internet. Also I tried 'ctrl alt del', but the same window pops up that says 'task' is also a trojan horse, so I can't do that either. Thanks to my other computer I read the 'read me first topic' again and after some problems, everything seemed to run just fine...

    But now today I downloaded asquared and scanned again. It says that there are still a lot of trojans on my laptop. So now I'm desperate...

    1) Super anti spyware ran fine, and I got a logfile from that.
    2) Malware bytes ran fine, and I also got a log from that.
    3) Combofix on the other hand, I had some problems with. When it was at part 7 or 8 or so, my laptop just shut down... I started it again and combofix created a logfile.
    4) I tried running Rootrepeal, but that just stopped running without a logfile.
    5) I also ran Hijackthis. I tried running it in normal mode, but that didn't work. I tried running it in safe mode and then I got a logfile.
    6) At the moment asquared is still running and it says that there are a lot of trojans on my laptop. I will post a logfile from asquared later if you guys want it.

    So at the moment I don't know what to do. I hope you guys can help me because I tried everything.

    In before, thank you.
     

    Attached Files:

    Last edited: Oct 1, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the log from running C:\MGTools.exe --> C:\MGLogs.zip.
     
  3. Lithium5

    Lithium5 Private E-2

    Hello TimW,

    I forgot to make a MGtool logfile yesterday. I was to excited that everything was 'fine' again, until today.

    asquared anti malware finished a few hours ago and I removed all infected files with it... Should I redo all steps of the guide so you have the correct updated logs?

    -Steven
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, please re-do your scans and attach new logs. ;)
     
  5. Lithium5

    Lithium5 Private E-2

    Ok, I did everyting again.
    Rootrepeal crashed so I wasn't able to get a log from that. :(

    -Steven
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay, I was out of town yesterday. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  7. Lithium5

    Lithium5 Private E-2

    Hello TimW

    Thanks for the help, but when I uninstalled combofix, I had to restart my laptop, and when my desktop appeared AVG anti virus said I had a trojan on my system32 =_=".

    Did the anti malware scanners miss something?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the log from AVG. I need to see what it is complaining about.
     
  9. Lithium5

    Lithium5 Private E-2

    AVG did a scan.

    I tried to remove the file, but it said that by removing it, my computer could crash, so I'm not going to risk that :(
     

    Attached Files:

    • Log.txt
      File size:
      455 bytes
      Views:
      1
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding anything related to that file. Did you have AVG quarantine it?
     
  11. Lithium5

    Lithium5 Private E-2

    I tried moving it to vault, but it showed the same message: "forced removal can cause system unstability or even crash".
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, then first create a restore point. Then use windows explorer to find the file. Rename it by adding a .old extension to it. Let me know what happens.
     
  13. Lithium5

    Lithium5 Private E-2

    Ok I renamed it by adding '.old', then it said that it was in 'read only 'mode, and some windows screens popped up saying 'click to proceed'.

    Now I can't find the file "mspnp5b6f" anymore.
     
  14. Lithium5

    Lithium5 Private E-2

    also I just noticed from an old log from combofix from a few days ago, that it also found the file "mspnp5b6f.exe"

    I uploaded the old file.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    But you didn't crash!! Which is a good thing. Does AVG still report on it? You should get me a new MGLogs.zip so I can take a look. Just run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator), if you haven't removed it yet.

    Then attach the below logs:

    * C:\MGlogs.zip
     
  16. Lithium5

    Lithium5 Private E-2

    Ok the MGlog zip file is attached.
    I'm going to run another AVG scan now.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Perhaps AVG removed it once it was renamed, I am not seeing it in the logs.
     
  18. Lithium5

    Lithium5 Private E-2

    AVG found it again :(, I attached the log.
     

    Attached Files:

    • Log.txt
      File size:
      457 bytes
      Views:
      1
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you still have ComboFix on your desktop or do you need to re-download it?

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Windows\System32\mspnp5b6f.old.exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach the Combo log. Then re-run AVG and see if it is truly gone.
     
  20. Lithium5

    Lithium5 Private E-2

    OK, everything went fine.
    Combofix log is attached.

    I'm running AVG scan at the moment.
     

    Attached Files:

  21. Lithium5

    Lithium5 Private E-2

    scan is complete and no virus found ^_^

    Thank you very very much for your help! =)
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. You can do the final clean up steps once again if you need to.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds