Malware report after seing changed home page

Discussion in 'Malware Help (A Specialist Will Reply)' started by cafemuse, Oct 5, 2010.

  1. cafemuse

    cafemuse Private E-2

    Hope I can get some help on this. Got this report off yesterday and tried to run combofix again but admin keeping me from doing so. This was being run for awhile with some file sharing software as a mode which might be causing conflicts as well. Thanks in advance!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want ot know if you have any malware problems, you need to run ALL of the cleaning procedure below and attach all 5 logs. Also you need to properly update programs. You are extremely out of date with Malwarebytes and you do not have ComboFix on your Desktop as required

    READ & RUN ME FIRST. Malware Removal Guide

    Please explain what malware problems ( if any ) that you currently have.
     
  3. cafemuse

    cafemuse Private E-2

    Apologies for jumping the gun. Having no functionality on new exes to clean system. I must have changed a setting that even as administrator I cant even override.
     
  4. cafemuse

    cafemuse Private E-2

    the message says file cant be open because its not win 32 compatible
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then how did you run ComboFix and Malwarebytes? And why didn't you update the definitions for Malwarebytes since it was able to be run?

    Also why was there a 4 day span between running ComboFix and Malwarebytes?

    Open Task Manager and look for randomly named or strangely named processes and kill them. If not sure, ask us first. After killing the process ( which is typically seen running ) you may be able to run other tools.


    Did you actually try downloading and running MGtools or did you just assume it would not run?

    If still having a problem getting started, try the below.



    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.



    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware make sure you update it if possible.

    Now run this: Using MGtools



    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  6. cafemuse

    cafemuse Private E-2

    First off, not all my exe's are not able to be open only the new ones (defogger, mb). Since I already uninstalled the MB I was unable to run the new one which was my next step on the cleaning. Combofix will run as will most programs. Its a permissions on new downloads which I cannot figure out. What happens is the exe shows up like an msdos doc with no icon and when I try and unblock it it doesnt take. It might be a Zone Alarm issue so I am going to uninstall it. As far as the lag time on combo and mb it might have been an earlier scan which i attached. Thanks again will try
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you attempted to run MGtools? If not, please do so.

    Did you try to run each version of Rkill? Did you try exeHelper?

    Also have you tried running things in safe mode?
     
  8. cafemuse

    cafemuse Private E-2

    i ran the exehelper and rkill. however the rootrepeal would not run, just said intilializing. all other logs attached. some may seem old but pc was turned off in between scans.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to at least double the memory in this PC. Your logs show the below which is going to result in poor performance.
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 62.36 MB
    Please delete the below. It is not the correct place nor correct filename for MGtools.
    C:\Documents and Settings\Administrator\My Documents\Downloads\MG.exe

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} -
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
    O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. cafemuse

    cafemuse Private E-2

    thanks so much for your help. the virt mem was set at "2". see attached
     
  11. cafemuse

    cafemuse Private E-2

    thanks a lot! Turned out my virt mem minimally set at "2" duh. see logs...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds