need help computer has some type virsu

Discussion in 'Malware Help (A Specialist Will Reply)' started by noles23, Dec 25, 2010.

  1. noles23

    noles23 Private E-2

    virus wont let me open anything up, keeps saying program is infected, wont let me connect to internet, keeps asking me if I want to activate spyware protection
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. noles23

    noles23 Private E-2

    here is my that info from scan
     

    Attached Files:

  4. noles23

    noles23 Private E-2

    here is the second log
     

    Attached Files:

  5. noles23

    noles23 Private E-2

    here is from super spyware scan
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget the log from running MGTools ---> C:\MGlogs.zip :)
     
  7. noles23

    noles23 Private E-2

    I think these should be the files
     

    Attached Files:

  8. noles23

    noles23 Private E-2

    when I start up my computer in normal mode, I have to open task manager right away. when I do this I am able to get the fake antivirus software from downloading by deleting wroqdeclajb.exe from the processes running, but it still does not allow me to connect to internet. when I try to diagnose problem when connection it gives me this( see attatchment)
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to be in normal mode preferably when carrying out this fix. Not safe mode.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • O4 - HKLM\..\Policies\Explorer\Run: [qesvnkjj] rundll32 "C:\WINDOWS\system32\toolhelpf.dll",qbmzeuvtb

    After clicking Fix exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\Temp
    • C:\Documents and Settings\Administrator\Local Settings\TEMP
    Java(TM) 6 Update 18 <--- uninstall outdated Java

    Now please run Combofix as per the instruction in the Read and Run Me First.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Then: run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. noles23

    noles23 Private E-2

    wont let me install new java saying system administer wont allow
    tried doing in safe mode java woudn't install
     

    Attached Files:

  11. noles23

    noles23 Private E-2

    i think this is what you wanted
     

    Attached Files:

  12. noles23

    noles23 Private E-2

    couldnt find this, wasnt in there anywhere (O4 - HKLM\..\Policies\Explorer\Run: [qesvnkjj] rundll32 "C:\WINDOWS\system32\toolhelpf.dll",qbmzeuvtb)

    hard to do this some stuff in normal mode because it wont let me connect to internet, fire fox keeps saying proxy wont allow connection
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There was a typo in my script. Let's try again:

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    You must tell me how things are running at this point.
     
  14. noles23

    noles23 Private E-2

    sorry been gone for a few days can I do this in safe mode?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can try doing it in safe mode.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes do try in safe mode if normal is problematic, but ultimately we need to be seeing logs from normal mode. Do it in whatever mode you can and we will take it from there. :)
     
  17. noles23

    noles23 Private E-2

    I am doing this in safe mode. So after I ran those files I used google and when I search it still keeps redirecting me to different sites. I checked normal mode I dont have the the pop up saying my computer is infected with a virus, but my firfox or explorer wont connect
     

    Attached Files:

  18. noles23

    noles23 Private E-2

    i seen that when I try to connect to internet it says firewall is set to block connection, but wont let me change it.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  20. noles23

    noles23 Private E-2

    here it is
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should have fixed your issues, but let's have you do this:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  22. noles23

    noles23 Private E-2

    after I ran the tdsskiller i was still unable to access internet in normal mode
     
  23. noles23

    noles23 Private E-2

    here is the mbr file
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MBR is clean now. I would like you to do the following in normal mode:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  25. noles23

    noles23 Private E-2

    here
     

    Attached Files:

  26. noles23

    noles23 Private E-2

    I am able to access internet in normal mode
    I went into Explorer internet options to advanced and reset settings and bothe explorer and firefox work
    how does that log look
     
  27. noles23

    noles23 Private E-2

    I appreciate all your guys help, if there is any thing else I need to do after looking at the mbrlogs just let me no.
    really appreciate the help
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point, you need to download and install an AV program. You can choose which one you want from reading the link on How to Protect Yourself.

    Let's just do this and then you are good to go.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  29. noles23

    noles23 Private E-2

    when I start my computer I have to open task manager then close it before I can use any program?
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why>? What happens when you try to open a program normally?
     
  31. noles23

    noles23 Private E-2

    well say I open internet expoler when it opens up it goes to home page but won't let me click on anything in it or do a search unless I open task manager and close it.
    also unless i open task manager and close it i cant open anything up in the start tab or toolbar
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's a new one on me. I suggest that you follow up with this in the software forum. It certainly didn't have anything to do with the malware removal.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds