Malware Removal Win XP 32bit

Discussion in 'Malware Help (A Specialist Will Reply)' started by ddbart, Apr 25, 2013.

  1. ddbart

    ddbart Private E-2

    Dear Major Geeks - thank you for all the information you provide to help with infection issues. My email address was hijacked yesterday and 47 people in my address book or from emails floating around the web or my server, received the hijacker's message that looked like it came from me. I even got one from me to myself. The subject line was read only "Fwd:" and the messages was a link. Several recipients contacted me right away asking about it. I advised them to delete the email and to not click the link. I dont think it is an ordinary phishing situation because I right clicked the message that was sent to me from my own email address and viewed Properties. Usually a plain phishing message reveals the senders actual email address. This one did not. It had no long message or codes but mainly the sender email was mine.

    I have read all the steps from your forum page about Malware removal and have progressed to the point where I have unchecked the hidden file options and also I have run HJT and will attach my Startup Log to this thread. My virus protection is up to date and current - Microsoft Security Essentials. I also ran an updated version of Stinger - both found no infections but both scanned my system before I made the hidden file unchecks. I also ran the paid version of Malware Bytes which had not been installed until I had this problem. I reinstalled it and ran it. No issues were found. I will uniinstall this program after submitting this note so that I have only one installed security program per your request.

    I contacted my host tech support - Host Gator - they provided a detailed page of data from their look into my problem. I do not understand everything their report shows but they advised that more than likely I have a trojan virus that is known to them. They recommended that I come here to MG forum and get started trying to dig it out. I hope you can help me do this and thank you in advance for all you do for so many. I will try to attach the HJT log now.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything. Note if you cannot save things in C:\ then just save them to your Desktop. Make sure that you have disable UAC and rebooted first if you are running Windows Vista or Windows 7.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.



    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!

    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:


    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. ddbart

    ddbart Private E-2

    Thank you Tim. I have run all the programs and obtained the logs - attached to this reply. My problem may be different from the usual infection because I am trying to find a trojan virus or something on my machine that is related to my email being hijacked a few days ago - my server Host Gator said that the outgoing messages they viewed are "consistent" with kind of trojan virus somewhere on my machine. Anyway, this is all beyond me and I am attaching the logs in case you can see something that will help get rid of the problem. Thank you again for your help.
     

    Attached Files:

  4. ddbart

    ddbart Private E-2

    Sorry - forgot Malwarebytes log (attached)
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running RogueKiller.
     
  6. ddbart

    ddbart Private E-2

    Sorry I missed that - thanks again for your help.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not finding much in the way of malware. Let's just do this:

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [TASK][SUSP PATH] At1.job : C:\Documents and Settings\User\Application Data\DSite\UpdateProc\UpdateTask.exe /Check [-] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now rerun Hitman and remove what it found.

    Reboot and rescan with both RogueKiller and Hitman and attach those new logs as well.

    Tell me how things are running.
     
  8. ddbart

    ddbart Private E-2

    Tim - thanks again for your help. I attached 3 RogueKiller reports because I wasnt sure why I ended up with 3 instead of 2 requested - maybe #3 was generated when I deleted the one file per instructions? #4 is log after reboot and re-run of RKiller.

    My machine seems to be running with no issues. One thing that bothers me is that when I attempt to access my online bank acct, since the email hijacking, I get a warning message that the site I am trying to visit has an expired certificate (see attached screenshot) The warning suggests that my machine may have a virus. This is not why I started the thread here at MajorGeeks - I started the thread at the advice of my internet server Host Gator. I reported the email hijacking to them and they looked thru my outgoing messages and sent a complete report to me showing that 47 people from my address book were randomly sent the spam mail from me by the hijacker. As far as I Know the spam message contained a link only. At least that is the message I got since the hijacker sent it to me as well. One friend emailed to say he clicked the link and it was a webpage selling Rasberry drops - of course that might have been a virus infecting site - I dont know.

    One other possible coincidence that is worth mentioning is that I have 2 external hard drives, F and G. I keep the F drive turned off because it is full with video and media files. It also has a downloads folder and a folder I created and copied old files from my previous computer which was infected. I am concerned that this F drive could be a hiding place for some infection and maybe even the one that is associated with my recent email hijacking. I turn that drive on occasionally when I want to retrieve a media file - interestingly, the email hijack may have occured when I recently had the F drive on. Unfortunately, none of the scans from this thread looked at the F drive. It seems the G drive, which is on all the time, was not scanned by any of the actions taken so far, either. Should we get some of these malware programs to look at those drives? Thanks again for your help - much appreciated.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I trust you have cleaned out your emails.

    Turn on your drives and try an online scan:

    eSet Online Scan.

    Be patient as it will take a while.
     
  10. ddbart

    ddbart Private E-2

    Was long process but might have done something - thanks Tim. Long because of so many files, mostly video and media files. I have a log to show you. It shows 9 threats were found and quarantined by ESET - I saved the list to my desktop (attached) Then I selected uninstall ESET and Delete the quarantined files - which I hope means they are deleted off my system completely. I then rebooted.

    I value your thoughts on these results.
    Currently, when I reboot the pc Malwarebytes automatically scans something and shows a report. I have the pro version because I bought it several years ago. Should I uninstall it or Microsoft Security Essentials or leave either or both running on my machine? I have Stinger and CCleaner on my machine also - should I keep it or remove it? Also what should I do with the other malware programs that I have installed during this process?

    Also I ran ESET from IE and after running it I was getting a popup in IE asking if I wanted to download an RKiller file from MajorGeeks and I did not understand that but the thing saved a log to my desktop (attached) It had some notes about things FOUND that I thought you should see but for some reason I cannot get the attachment to upload here at MG.

    I appreciate your help very much - please advise what you think and whether I should do any other scans etc. Thanks very much.
     

    Attached Files:

  11. ddbart

    ddbart Private E-2

    Meant to add that I had not deleted emails until I saw you last comment. I had over 4000 messages saved in my inbox and almost 8000 in my sent box. I deleted all of them before running the ESET scan. I have many email folders filled with emails that I have saved - orders from online stores, taxes all kinds of contacts etc. Are these emails a threat?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Don't uninstall anything. You should keep both MBAM and MSE. What issues remain, if any?
     
  13. ddbart

    ddbart Private E-2

    Understood. I have no noticable issues on my computer and did not have any obvious issues leading up to my original post. I started this post because Host Gator advised me to come here to try and get my machine cleaned because someone hijacked my email last week. According to them the outgoing messages they looked at were consistent with some kind of trojan virus on board that was sending out spam mail using my email address. Other than that I have no issues. I did notice that I get that warning when I try to access my bank acc online - this started happening after the hijacking. I get that notice warning me to not proceed to my bank page because they say the security certificate has expired. That message never happened before. So I am concerned that the hijacker is watching my logins etc to access my online accounts. I value your thoughts and thank you very much for your help. How can I visit my online bank page without getting that security warning?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you use a different computer to access your bank, do you still get the same warning?
     
  15. ddbart

    ddbart Private E-2

    I have not had a chance to try that. I usually accessed the online account from a link I saved that took me directly to the login page. That is the link that gives me the warning message. If i go to the bank home page first and then login I do not get any warning message.

    I just discovered another odd thing. I rarely login at facebook but did so this morning. I got a message from fb that my page was temporarily blocked because someone tried to login from an unexpected/unfamiliar location to fb. They gave me a "continue" button to resolve the issue. I followed it and they showed a map with an arrow in some place in NJ and asked if I approved that access. I said "no" and then fb allowed me to login. I am not sure it was related to the email hijack because I had not logged in at fb more months and the hijack happened a week or 2 ago. I had given google permission to update my fb page from youtube - this was a few weeks ago. Perhaps that was the NJ attempt to login at my fb page - I don't know.

    Thanks very much for your help and time, Tim. I will copy the link to my login page at the online bank and try to use it from another computer when I get opportunity. Perhaps the local public library would be a good place to do it. Will let you know what I find one day this coming week when I can get to the library during their open hours.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You just need to delete that old link and establish a new link.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  17. ddbart

    ddbart Private E-2

    Tim - I could not find the malware programs that I added to my desktop to uninstall them. They did not show up in Add/Remove Programs or in my start folder. Right clicking them on the desktop there was no uninstall option. However, when I ran MGClean.bat it removed all of them and itself, leaving only HitmanPro. I cannot find a way to remove HitmanPro.

    I have not done anything else yet from your last instruction. Can you tell me how to get rid of HitmanPro? I will then proceed with your other instructions. Thanks again for your help. So far all is well.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just right click Hitman and choose delete. ;)
     
  19. ddbart

    ddbart Private E-2

    Well Tim - it took me awhile to get thru all the tips and so far no further issues on my machine - thanks so much for your help. The only tip I have not acted on so far is changing to a different firewall than Win Security Essentials. Since I am keeping Win Security Essentials as my antivirus I thought to leave the firewall alone - it is enabled. Thank you again - very much appreciate your help. If you have any further suggestions I'll be happy to review them.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome. Safe surfing. :)
     
  21. ddbart

    ddbart Private E-2

    Tim - sorry to trouble you with this but sure hope you can help. I accidentally dragged a desktop calendar off the screen to the bottom side and cannot reach it with the mouse to drag it back to the viewable part of the desktop. How can I fix it? I have a lot of important dates and apptments on the calendar that I do not have recorded anywhere else and need the thing. Hope you can tell me what to do. Nevermind Tim - I found a way to get it back - I changed desktop settings to lower resolution temporarily and the calendar showed up - i moved it up and then changed settings back. Sorry to bother you. skip
     
    Last edited: May 24, 2013
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. ;)
     
  23. ddbart

    ddbart Private E-2

    Tim - not sure I have any issue but my computer has become slow when clicking around the internet. Is that the real time protection from Malwarebytes slowing me down? More a concern is that recently I am noticing Outlook Express is not saving all my email replies. For some reason it does not save replies to certain people. I have always had it set to automatically save replies. Any thoughts? skip
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are having issues with your email, best to post in the software forum for additional assistance.
     
  25. ddbart

    ddbart Private E-2

    ok Tim - thx.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Safe surfing. :)
     
  27. ddbart

    ddbart Private E-2

    Tim - I do a lot of video processing and uploading to youtube and have found my machine running more slowly, especially when working on video files and even playing them back. I think I might have made some changes to the Malwarebytes settings and those changes have slowed everything down. Now I cannot even play a high quality video clip without it being pixelated and freezing after a couple seconds. When this happens, my whole pc is unresponsive until whatever is going on is finished. Do you think Malwarebytes real time protection is doing this? Is there any way I can keep it running but still have the ability to handle my video files? Right now I'm thinking about uninstalling Malwarebytes.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As long as you have a way of reinstalling it, go ahead and uninstall it and see if that helps. Otherwise, post in the software forum for additional assistance.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds