need help getting rid of malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by raekwon, Jun 4, 2009.

  1. raekwon

    raekwon Private E-2

    My computer got infected with some nasty malware about a month ago, i have no idea what the source was. Anyway i did some scans and could clear some malware out but not completely, I did the windows XP cleaning procedure and it got rid of all the symptoms except for my browser always redirecting me when i clicked on links, but other problems and malware would always come back after some time and rebooting. I've tried a bunch of different scans and nothing has been able to kill it completely. I had some time today so i decided I would try and get rid of this once and for all and i need some help. I did the XP cleaning procedure again, and again it got rid of all the symptoms except the browser redirect, but im also 100% sure more problems would come back when i reboot as this has happened before, so i don't know what to do from this point. Here are my logs
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Part of your problem is that you are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKUS\S-1-5-18\..\Run: [SYSDLL] SYSDLL (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [SYSDLL] SYSDLL (User 'Default user')
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new SUPERAntiSpyware log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. raekwon

    raekwon Private E-2

    ok so I did everything you said to do in your post a few hours ago and ive been using the computer, my firefox will still redirect me to other pages when i use google, but i havent noticed any other problems coming up yet, the only other thing that happened was that after combofix rebooted my PC, the next time i went to open firefox it said that it was no longer my default browser. It seems that the original malware is still present. here are the logs
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again to remove your redirect problem.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. raekwon

    raekwon Private E-2

    hey i ran all your steps a couple days ago and ive been using my PC since with no problems at all, the redirect is gone and ive rebooted several times and no malware has resurfaced so it seems like its all gone thanks :D.

    theres one thing im concerned about which is the virus or one of the viruses i had seems to have infected my ipod, now every time i connect my ipod, itunes tells me it has been corrupted and needs to be wiped. I actually looked up one of the viruses i had before and i saw descriptions saying it can jump to removable drives and etc., so im thinking that this malware will reinfect my PC if i connect my ipod again. do you have any suggestions about this?
     

    Attached Files:

    Last edited: Jun 14, 2009
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall your iTunes/iPod software and then reboot your PC. As it is rebooting plugin your iPod. When your PC comes up, it may be possible that you can detected the iPod as another storage device (like another hard disk) and you may be able to remove any bad files from it manually.

    Also with the iPod plugged in, you can run scans with your antivirus, SUPERAntiSpyware and Malwarebytes and make sure you scan the drive letter representing the iPod. Attach logs.

    Run this Running RootRepeal and make sure all drives are selected. Attach the requested log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds