Need Help Removing Malaware, Kind of Stuck

Discussion in 'Malware Help (A Specialist Will Reply)' started by ocanyc, Dec 4, 2008.

  1. ocanyc

    ocanyc Private E-2

    I wish it was as easy as doing a search for a post similar to your issue but it seems for the most part everyones issue is different or how they've gone about handling it. Let me just start by saying that I'm kind of stuck at the moment and am at work. The issue is with my Dell laptop at home. I've been running McAfee AV/Firewall protection for a year or so and I guess that wasnt good enough. Here is what I think I've found and done so far.

    1. Downloaded Adware 2008, cant update it as malaware wont let me. I ran it as is and found like 33 things, but removing all that didnt help.
    2. Downloaded CCleaner, and cleaned things up. That didnt help. I disabled soem unrecognizable programs at startup. Doubt that worked.
    3. I found that getmodule30.exe with ccleaner and disable this at startup. I think that worked not 100% sure.
    4. I found the winweb security process and removed the program, and deleted the registry entry for it.
    5. Tried to download malawarebytes anti-malaware and couldnt get it to run the install. Not sure how I finally got it to install from a usb stick and then it doesnt even run.
    What ever malaware virus I have is really good.
    6. I then read to try cureit, and then try to run the anti-malaware. I got cureit on my laptop and that doesnt want to run properly.

    I know I fixed maybe one symptom, but others definitely remain as my firefox and ie browser keep getting redirected and just pop-ups keep coming. I got the blue screen of death a couple of times as well. I cant update any software says it cant connect, and some web addresses I try wont connect as well. This malaware has definitely taken over.

    So as you guys can see, I'm not getting far. What basic steps should I take now so that you guys can guide me to a solution? Thanks in advance. Seems like a great forum and I plan to learn to not only help myself in the future but others as well.
     
  2. ocanyc

    ocanyc Private E-2

    BTW, I tried the READ & RUN me first but the furthest I got was uninstalling the java. I tried to install new version and said it wasnt a valid win32 application. I restarted my computer and it wont boot up all the way. I mean the desktop comes up but doesnt get all the icons on the bottom right on the taskbar like the network connections. Before I even uninstalled java yesterday I had to reboot it like 6 times until it finally booted up completely. I believe I tried to boot up in safe mode and that wouldnt boot up all the way. Any suggestions would be appreciated, thanks.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. ocanyc

    ocanyc Private E-2

    Ok thanks for the reply. I got up and running before I heard a reply here. I disabled the tdsserv driver, and ran malaware bytes. Then I proceeded with the READ & RUN. I'm attaching my logs and I'll await further instructions
     

    Attached Files:

  5. ocanyc

    ocanyc Private E-2

    Please let me know if I'm missing any logs. Thanks, I tried to follow all instructions under READ&RUN precisely.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are looking much better....just a few things to deal with:

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let me know if you get a success message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. ocanyc

    ocanyc Private E-2

    Hi TimW, thanks for your assistance. I'm attaching the updated MGlogs.zip file. Just a question, what did I fix by doing this last step. I understand I removed that rpbryx.dll file but what harm was this file doing? Thanks again ;)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The file was left over from the infection. Your logs look good and clean now.

    If you are not having any other malware issues, then:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds