My Laptop Virus Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by MikaMika, Dec 20, 2012.

  1. MikaMika

    MikaMika Guest

    All kinds of wierd things are happening on my laptop. It is like it has a mind of its own. According to cCleaner, I have MS Windows 7 Home Premium 64-bit SP1 Intel Core i3-2310M CPU @ 2.10 GHz, 4.0GB RAM, Intel HD Graphics Family. It is a Toshiba Satelite L747-S4210.

    Started out redirectly links (first one then any browser). Then MSE (Microsoft Security Essentials) disappeared. I can find it to run in Safe Mode. I tried different things I found on the web. I even deleted my firefox browser, and cannot get to its webpage to reinstall it. Everything would clear up for a bit, but then something else would start acting up.

    Malewarebytes sometimes found the svghost, or nothing. And Superantispyware sometimes finds trojans, or nothing. The latest was some kind of scan program that did nothing but throw popups at me.

    I am running through your redirect page again as I type this. This time after running tdsskiller, I cannot open anything. I have to right click and run as administrator if I can. Or the "Open with" menu box comes up for me to choose a program.

    So I continued onto your malware cleaning page. MSE is not listed anywhere to uninstall it and I was not able to change the user account control, I get that "Open with" menu box. Other than that, all the scans should be in here.

    Hopefully everything is here. I am attaching a zip file. I am not a computer wiz and it is difficult to work with everything going kerpluey on the screen. Somewhere in there, MG links started opening to warning pages so I had to find another computer to transfer the scan programs and results via thumb drive.

    Not sure when the very first redirect started, maybe a few days ago, maybe a week now. Not sure what I was doing either, maybe clicking on a link in facebook, not for sure.

    I apologize for interfering with anybody's holidays, or interrupting anyone's starting their new life in the new world that starts tomorrow (21st), but I do greatly appreciate the help!

    Thank you!
    Mika
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 7 detections:

    • [SHELLSPWN] HKCU\[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "%1" %*) -> FOUND
    • [SHELLSPWN] HKCU\[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "%1" %*) -> FOUND
    • [SHELLSPWN] HKUS\S-1-5-21-2571946279-1138501515-3639322655-1001[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "%1" %*) -> FOUND
    • [SHELLSPWN] HKUS\S-1-5-21-2571946279-1138501515-3639322655-1001[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "%1" %*) -> FOUND
    • [SHELLSPWN] HKCR\[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "%1" %*) -> FOUND
    • [SHELLSPWN] HKCR\[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "%1" %*) -> FOUND
    • [FILEASSO] HKLM\[...]\command : ("C:\Users\Mika\AppData\Local\tgj.exe" -a "C:\Program Files (x86)\Int") -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for these entries on file/folder tab...

    • [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$65f022bc5c13990d42ef21e1b2e0b37c\@ --> FOUND
    • [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-18\$65f022bc5c13990d42ef21e1b2e0b37c\U --> FOUND
    • [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-2571946279-1138501515-3639322655-1001\$65f022bc5c13990d42ef21e1b2e0b37c\U --> FOUND
    • [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-18\$65f022bc5c13990d42ef21e1b2e0b37c\L --> FOUND
    • [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-2571946279-1138501515-3639322655-1001\$65f022bc5c13990d42ef21e1b2e0b37c\L --> FOUND

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Delete these files:

    • C:\Users\Mika\AppData\Roaming\Microsoft\Windows\Templates\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
    • C:\Users\Mika\AppData\Roaming\Microsoft\Windows\Templates\n2ee12q3co7aih
    • C:\ProgramData\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Re run RogueKiller - just a scan. Attach log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. MikaMika

    MikaMika Guest

    Thank you Kestrel13!

    Your instructions look easy enough for me to follow, appreciate that. Will work on this today.

    Happy New World Day!

    Mika
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will be floating around somewhere. :)
     
  5. MikaMika

    MikaMika Guest

    Ugh! Having difficulty here. I do not see what you have listed for me to find on Rogue Killer. I doubleclicked to open it and ran a scan.

    Under the "Registry" tab are several checked "Found" boxes. It is impossible to draw out the program box any larger or make it full screen. I was able to slide around the column headings some to see more listed text. I cannot tell which seven boxes and lines you want checked and deleted.

    Under the Files tab same thing (sort of). I cannot make the program big enough to see all the text per line. Looks like the five lines listed are the five lines you want me to delete. But there are no check boxes in front of these lines. I assume hitting the 'delete' button while I am in that tab will delete everything is listed in the tab I am in?

    I went ahead and attached screenshots so you can see what I am looking at.

    (I do see the next three files you say to delete from 'Mika' and 'ProgramData', will do that after we get your first instructions finished.)

    Mika
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, the items in the files tab need to be deleted. Can you do that and then rescan (just a scan) and attach the latest RogueKiller log. Then continue with the rest of my instructions too.
     
  7. MikaMika

    MikaMika Guest

    Okay, deleted what was in the 'files' tab. Rescanned with RogueKiller (#4 attached).

    Then per your previous instructions I rebooted my laptop, deleted those three files, managed to add the reg file successfully, and rescanned RK (#5 attached).

    I did not see a "zip" file when I ran the 'GetLogs.bat' in MGtools. I attached the txt file it says it made. Mind you there are several files with the same date and time on them (12/22/2012 7:43pm) in the MGtools folder and most of the files in its 'temp' folder. Let me know if you want to see those.

    I will start playing on the internet with my laptop tomorrow. Hopefully I did everything correctly. Will let you know.

    Thank you Kestrel13!,
    Mika
     

    Attached Files:

  8. MikaMika

    MikaMika Guest

    Started back on the internet this morning on my laptop. Clicking on links is getting me redirected again. Redirects in Opera, Chrome, and iExplorer. Safari seems okay. I have not reinstalled Firefox yet. I assume if that were installed it would be redirecting in there also like it was before.

    I did not do anything else, no scans. I just got out of everything turned off the computer before anything started.

    Mika
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The MGlogs.zip should be right on C:\ if it is not there then you will just have to run the MGTools.exe and THEN attach the resulting MGlogs.zip.

    Where are you being redirected to exactly?


    Run this and attach the results.

    Using ESET's Online Scanner

    also...

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  10. MikaMika

    MikaMika Guest

    Thanx for replying. Need to do "Christmas" for a bit. Please enjoy yours! Will post next set of results 26th.
    Mika
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK I'll be online Christmas night and the following day is normal schedule for me. :)
     
  12. MikaMika

    MikaMika Guest

    Okay, here goes

    First, got a pot of coffee brewing.

    Second, to show you some of the redirects I ran some searches:

    In iE using Google:
    Did a search for "James Cagney"

    Should have opened
    themave.com/Cagney/
    redirected to
    /promotions.monster.com/keywordjobsearch/?WT.srch=1&WT.mc_n=olm_sk_srch_amp_RON18


    Should have opened
    en.wikipedia.org/wiki/James_Cagney
    redirected to
    209.200.35.38/click.php?clickdata=gfK4ou%2BaSKFmFQDYBpHa%2BWODLvAwGpDSFZXmxdSqCNI%3D

    In Chrome using Yahoo
    Did a search for "scrappy quilts"

    Should have opened
    quiltville.com
    redirected to
    blekko.com/
    (and a page of 'Quilt' search results)

    Should have opened
    www.bhg.com/crafts/sewing/quilt-patterns-for-scrappy-quilt-projects/
    redirected to
    beesq.net/find_1.php?k=scrappy+quilts&ts=1004TSE_1&num=8&subid=46355-9739_151$&click=1&tt=10585#b

    Third, reran MGTools from exe file (it finished this time, and like you said, the zip file was one up from the MGT folder). MGlogs.zip attached

    Fourth, ran ESET Online Scanner. Five long hours later . . . Instructions did not say to 'Uninstall application on close' or 'Delete quarantined files', so I hit 'Finish' without checking either of those boxes. ESET txt attached

    Fifth, downloaded and ran Junkware Removal Tool. JRT.txt attached

    Sorry to be such a pain with all this Kestril13! I do appreciate you still working with me. Thank you! Hopefully I did everything correctly this round. Time for a break. I think I drank waaaay too much coffee . . .

    Mika
     

    Attached Files:

    Last edited by a moderator: Dec 26, 2012
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just finished my mug of tea, too lazy to go get another, but I'd love one.

    Are you still being redirected after running those tools?

    Which browser(s) redirects please?
     
  14. MikaMika

    MikaMika Guest

    Thought I would give you a day off. Miss me? Used my laptop yesterday. Had not been using it since I posted here except for running the scans and whatnot. But with all this work, I thought maybe. . .

    Reinstalled firefox. Just clicking around in facebook and emails, gmail and yahoo seemed okay in firefox. Used iE, and just clicking insite seemed okay. But I noticed I still could not run Microsoft Security Essentials. I can see it but nothing opens. And that is my usual cue for a virus on here, trouble with seeing or running MSE. I restarted in Safe Mode. And MSE comes up then. I did not run anything (ss attached)

    So today I checked my browsers, and everything is back to redirecting (firefox, iE, opera, chrome). For what it is worth, it shows the google icon "g" in the search or address bars as it is redirecting itself.

    in Opera using Yahoo searched for "Candle Making Supplies"
    should have gone to
    www.candlemakingsupplies.net
    redirected to
    hxxp: //cookingtutorials.com/?sour...JO9vK8PYbnNCq/XYmJeFMe02LqyxoLWdyroTUisykvjo=
    (ss redirect01 attached)

    should have gone to
    www.candlemaking.com
    redirected to hxxp: //174.137.144.183/click.php?clickdata=gfK4ou+aSKHZ9fhbYRRNY4J524klkyQqJcZnb9F/W+w=
    (ss redirect02 attached)

    in iE using google seached for "honey candy"
    should have gone to
    vermontcountrystore.com/HoneyCandy
    redirected to
    hxxp: //63.209.69.107/see.php?q=honney candy&affid=err1&subid=1&p=2&r=0
    (ss redirect03 attached)

    should have opened
    thenerdyfarmwife.com/two-easy-honey-candy-recipes/
    redirected to
    same page actually

    in reinstalled Firefox using yahoo seached for "cotton batting"
    should have opened
    www.joann.com/fabric/batting
    redirected to
    hxxp: //www.bravotv.com/top-chef/season-10/videos/chiffonade-basil-like-a-chef
    (ss redirect04 attached)

    should have opened
    quiltersdreambatting.com
    redirected to
    hxxp: //63.209.69.107/see.php?q=cotton batting&affid=err1&subid=1&p=2&r=0
    (ss redirect05 attached)

    redirects in Chrome also (I think you have enough screenshots)

    and again Safari seems okay I don't like Safari, hardly ever even open that one.

    Ugh. I thought wrong.
    Mika
     

    Attached Files:

    Last edited by a moderator: Dec 28, 2012
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller just a scan, and attach the log. Also...

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  16. MikaMika

    MikaMika Guest

    Here ya go Kestrel13!
    (Just missed your post yesterday)
    Mika
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :) Got the RogueKiller log too?
     
  18. MikaMika

    MikaMika Guest

    'coming right up' . . .

    Mika
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    [2012/12/29 06:01:29 | 000,000,296 | ---- | M] () -- C:\windows\tasks\vlfov.job
    [2012/12/19 19:34:09 | 000,011,396 | -HS- | M] () -- C:\Users\Mika\AppData\Local\1pb78m8n6he1l1565b3k36w7o7of8ksb88y53s63tpqg0vl
    [2012/12/15 15:17:52 | 000,126,976 | RHS- | C] () -- C:\windows\SysWow64\net1J.dll
    [2011/12/11 10:38:10 | 000,009,708 | -HS- | C] () -- C:\Users\Mika\AppData\Local\n2ee12q3co7aih
    [2011/12/11 10:38:10 | 000,009,708 | -HS- | C] () -- C:\ProgramData\n2ee12q3co7aih
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    Now run OTL normally, let it scan again and attach it's new log.

    Any change at all??
     
  20. MikaMika

    MikaMika Guest

    Think I managed okay.

    Not sure about "click image", the run box on the reboot? The '.log' is attached.

    Just ran OTL "run scan", it was still set to "minimal output" but the lop and purity boxes were not checked like for post 15. '.txt' attached.

    I will start playing back on that computer and let you know.

    Thank you!

    Mika
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea, let me know when you can! :)
     
  22. MikaMika

    MikaMika Guest

    Happy New Year Kestrel13! Hope you did something fun. I spent the day watching all the Mummers in Philadelphia on my blotchy screen TV.

    I have been playing on my computer for a few days. All the browsers seem to be working fine, no redirects. Nice! No super long black screens on startup, no weird popups or scans trying to start themselves, Nice!

    And I got my Microsoft Security Essentials back (yay me!). I updated it. Have not run a scan on it yet.

    Did not think I was suppose to run anything until I got your okay. So I have not run any of my usuals. cCleaner, Superantispyware, MSE, and occasionally Malewarebytes.

    So . . . . ???
    Do I order me a t-shirt yet? Or do you need to check something else on this thing?

    Mika
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My New Years was quiet, just how I like it :-D Glad you enjoyed yours too.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. MikaMika

    MikaMika Guest

    Okay, followed the list as best I could. To my computer illiterate brain #8 should be before #4, but I do believe "it's all good". T-shirt is on its way! If this has been of a body looks any good in it, maybe I will try and post a picture somewhere (big "IF" there).

    Thank you soooo much Kestril13! !!!

    Now I am off to get rid of facebook's awful timeline. I know I saw a post on that somewhere in here . . .

    Mika
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Funny you should mention this as I updated the boilerplate several times over the past few months and even added some more clarity/details today. I guess Kestrel13! and may others had not noticed. But now they will. The current boilerplate looks like below. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Jan 4, 2013
  26. MikaMika

    MikaMika Guest

    You are beautiful too chaslang and much appreciated!

    Mika
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! If only it were true, I could be in movies and rich. :-D:-D:-D:-D

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds