Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by killian, Mar 7, 2010.

  1. killian

    killian Private E-2

    My kids got the pc infected yesterday; I ran SAS and Malwarebytes yesterday, and today ran all steps from READ ME FIRST. Attached are the logs including the SAS and Malwarebytes logs from yesterday, thanks
     

    Attached Files:

  2. killian

    killian Private E-2

    Here are rest of logs.
    Problems with pc: pc is v. slow, and using the internet is problematical - clicking links on google searches brings to unwanted sites
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much in your logs. Have you run SAS and MBAM on the other ( children, I assume ) account?

    Do you know what this is in your startup folder:
    C:\Documents and Settings\Juliana\Start Menu\Programs\Startup\61871.lnk

    You should not have Bittorrent running at start up. So please:
    copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now try doing this:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Tell me what issues you still have.
     
  4. killian

    killian Private E-2

    I hadn't run SAS or MBAM on the kids' account because the infection happened when they were using their mother's account.
    I ran SAS and MBAM now (attached are logs).
    I ran the TDSSKiller.
    Problem persists with links being redirected, and a 'virus scan' automatically checking the pc for viruses which starts from a clicked link.
    Thanks,
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you set up this machine to use a proxy server?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.135.162.56:80

    If not, please see this Proxy Servers

    What "virus scan starting from a clicked link?"

    Does it happen in IE as well as FF?
     
  6. killian

    killian Private E-2

    Yes, proxy had been set up by me (not currently used).

    "What "virus scan starting from a clicked link?"" I tried to recreate it but it isn't doing it right now; basically, a "My Computer" window opens and under the c drive info, a scanner runs and then says pc is infected and directs me to internet site to "fix".

    IE seems to be unaffected (I hadn't checked IE before).
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if it occurs again.
     
  8. killian

    killian Private E-2

    The problems of redirected links still persist; just not the auto scan so far
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. killian

    killian Private E-2

    Thanks; ran them and problems persist. The auto scan is back - it is called scan1 . all - way - defendere . com
    This started a scan and attempted to get me to start an .exe file to load software.
    The problems with the google search link redirects persists,
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run both ComboFix and the C:\MGtools\GetLogs.bat file. Then attach the two new logs.
     
  12. killian

    killian Private E-2

    Thanks, attached are the logs (link redirect problem persists)
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you install this:
    C:\Documents and Settings\Juliana\Local Settings\Application Data\Windows Server

    What is this:
    C:\temp\AURDATA --> numerous files in that folder.
     
  14. killian

    killian Private E-2

    - I don't know what that is...

    - that may be the initial malware problem.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you delete them? Do we need to run a removal tool to get rid of them?
     
  16. killian

    killian Private E-2

    OK, they are deleted; but link redirect problem persists,
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this happen in all browsers?

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  18. killian

    killian Private E-2

    Not with IE, only FF (we only use FF really)

    Attached is zip, thanks again,
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you uninstall firefox and be sure to remove all folders and profiles. You can follow these Uninstall FireFox

    Then run CCleaner and try re-installing.
     
  20. killian

    killian Private E-2

    TimW, excellent, that has resolved it, thanks very much
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  22. killian

    killian Private E-2

    While the link redirect problem is gone, I decided to run SAS yesterday to doublecheck for any problems and unfortunately I found some. I ran SAS and MBAM again today, along with GetLogs (wasn't sure if I should!). Attached are logs; again, I appreciate your extended help!
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Apparently, you had not deleted the Windows Server file. The rest are infected system restore files. Those will go away when you toggle system restore. How are things running now?
     
  24. killian

    killian Private E-2

    OK, I had deleted the Windows Server from C:\Documents and Settings\Juliana\Local Settings\Application Data\Windows Server only; didn't realise similar folders were elsewhere. Everything seems fine, thanks again,
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Keep your SAS and MBAM updated and use them on a regular basis. Safe surfing. )
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds