MGLogs and any help you can offer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ecl1psE5, Apr 17, 2009.

  1. Ecl1psE5

    Ecl1psE5 Private E-2

    Hello everyone...

    I'm new here and willing to try anything at this point to clean this computer. Its my Father/mother in-laws computer, and they are not very safe when browsing the internet. And there son and daughter are just as bad.

    But they asked me why there computer wouldn't let them go to any websites. At first glance i can tell this computer has some type of a browser redirector, because you cant even search in google without getting shot around to a bunch of different sites. You also cant view any thing in Flash, no matter how many times i update the player.

    I cant install SuperAntispyware as this is one of the programs i prefer to use, and it just errors out every time i try to install it. Doesn't matter if i'm on admin, user, or safe mode.

    They had a friend of theres install quite a few programs, and i cant get any of them to update or find anything wrong with the computer. Including AVG, Spy sweeper, and Comodo.

    I have attached the logs from MGTools, and have tried to follow every step in your XPcleaning procedures as well as many other procedures on this site. So far, nothing has helped.

    If Anyone can help or offer solutions i would be greatly appreciative.
     

    Attached Files:

  2. Ecl1psE5

    Ecl1psE5 Private E-2

    I did forget to note that i could install Malwarebytes but it would not run the program. Also combofix.exe would not run either. The only program i could get to run was MGTools.
     
  3. Ecl1psE5

    Ecl1psE5 Private E-2

    OK, progress.

    I was digging around some more and found the link for disabling the TDSSserv and that was what had the choke hold on my computer.

    http://forums.majorgeeks.com/showthread.php?t=177951

    I am Currently scanning with each of the 4 programs and then going to post the logs your request.

    This website is great, its so full of information. Thanks
     
  4. Ecl1psE5

    Ecl1psE5 Private E-2

    Ok, final update until i hear back from anyone wiling to help. :)

    I was able to get all but Combofix to work. when i double clicked on combofix it would just sit at the blue screen and not do anything. i let this go like that for almost 2 hours. Still nothing. So i moved on to the MGtools and that worked.

    So here are 3 of the logs that you ask for.

    thanks in advance for any help.

    Aaron
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are way out of date with your version of Malwarebytes. Please run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Note that you have AVG and Spy Sweeper installed and they are not compatible. See http://free.avg.com/faq.num-1328?srch=SpySweeper#faq_1328

    You more than likely had a problem getting ComboFix to run because you did not get AVG, Comodo, and Spy Sweeper shutdown before running ComboFix.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
    O4 - HKUS\S-1-5-20\..\Run: [lomafawipi] Rundll32.exe "C:\WINDOWS\system32\sivopize.dll",s (User 'NETWORK SERVICE')
    O4 - Startup: PowerReg Scheduler.exe
    O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. Ecl1psE5

    Ecl1psE5 Private E-2

    Thanks so much for the reply!!!

    I have followed all your instructions and am attaching the 3 logs requested.

    So far the computer is operating as a normal slow computer would. Its older so the hardware is very old, but things once hindered by the malware are now operating fine. There is no longer a redirector on IE and I was able to update all my scanners.

    Also, i am going to be uninstaling Spysweeper, do you recommend any other programs? Or am i proteced enough using Comodo/Avg?

    Thanks again for all your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have already done this before doing the rest of my instructions. ;)

    Your logs are clean, what we recommend for protection is included in my final instructions below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds