Need some help

Discussion in 'Malware Help (A Specialist Will Reply)' started by KujoWolf, Dec 17, 2009.

  1. KujoWolf

    KujoWolf Private E-2

    Couple of days ago (Monday evening/Tuesday Morning) I was watching an online Show hosted by MegaVideo, but linked through allusee.

    Paused the show a few minutes in, and left for a moment to do a couple of things. Came back and BAM, spyware/malware galore. So many pop ups and other stuff was going on it bogged my system to crawl.

    First thing I did was unplugged my internet connection and shut off the computer. I tried to reboot to safe mode, but was sent back to the start up screen. So loaded windows normally, system bound up within seconds of logging on.

    Next i hooked up the hard drive to another computer to scan it with Malware Bites, Spybot, and Bitdefender. it removed well alot of spyware and malware (around 1200+). After all this was done, i put the hard drive back in.

    I was able to get to my desktop, but when i connect to the internet and click on anything i still get random pop-ups and redirected webpages. Roommate told me to come here, and i followed all the instructions. oh and also i'm running Windows Xp

    The Exception is i wasn't able to run ComboFix due to it being down at the moment. Still can't boot to safe mode, nor can i go to any webpage without being redirected to something else.
     

    Attached Files:

    Last edited: Dec 17, 2009
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    First - let's update some of your tools:

    1) You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    2) As ComboFix is now available - use the below link for installing and running it.

    Windows XP Cleaning Procedure

    3) Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • updated SAS.log
    • C:\combofix.txt
    • C:\MGlogs.zip

    Once you have attached the new logs, I will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. KujoWolf

    KujoWolf Private E-2

    Ok ran Super and MgTools, however i couldn't run Combofix.exe
    When i tried to run Combofix, i got several errors saying

    32788r22FWJFW\iexplore.exe
    32788r22FWJFW\hidec.exe
    32788r22FWJFW\n.pif
    32788r22FWJFW\nircmd.cfxxe

    "Windows cannot access the specified Device, path or file. You may not have the appropriate permissions to access the item" The errors popped up several times each.

    i am logged in as the only user i have setup on the computer, and i double check its listed as a computer admin.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below fixes and advice are specific to this member's problem and should be used for issue(s) on this machine only.

    Hello KujoWolf, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Comment: I see that you do have a ComboFix log from running it on Dec. 17th - attach it to your next reply.
    Step 1:
    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.

      C:\win32kdiag.exe -f -r

    • When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log.

    Step 2:
    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exe into the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Step 3:
    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inherit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Step 4:
    To remove a leftover from AVG - check on the following link, download the AVG Remover(32bit)version ---> run it, re-boot, then run it again.

    AVG Remover

    Step 5:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 6:
    Using Windows Explorer - navigate to and delete:
    C:\MGtools(2).exe

    Step 7:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 8:
    Now install the latest Sun Java Runtime Environment

    Step 9:
    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • Win32kDiag.txt
    • C:\ComboFix.txt <--- from the Dec.17th running

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  5. KujoWolf

    KujoWolf Private E-2

    Ok ran all the programs as intructed and here is are the log files,

    ********

    Problems i had during:

    1)After running avg remover, on restart right after the Windows screen. my system stopped at a black screen. hit the reset button after about.. 1-2minutes had passed and it loaded just fine.

    2) i noticed when running Getlogs.bat that during the scan, it found a file missing, however i couldn't get the name of the missing file. i know it was a *.sys file

    ******

    So far i haven't been redirected when clicking on any link after doing a Google search, though at the moment, i have only done a handful of clicking before finishing this reply, about 10-15 clicks to see how it was performing. if anything odd happens I'll post again.
     

    Attached Files:

  6. KujoWolf

    KujoWolf Private E-2

    As an update today, i was looking something up on google and got redirected. took 3 tries to get to the wikipidia page i was trying for.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Happy Holidays, KujoWolf

    Please go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip log to your next reply.
     
  8. KujoWolf

    KujoWolf Private E-2

    Logs as per request.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    "Happy New Year, KujoWolf!

    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\avenger.txt
    • C:\MGlogs.zip

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  10. KujoWolf

    KujoWolf Private E-2

    Ok ran The Avenger software as instructed, however on reboot the software ran into the following error:

    C:\ Cleanup.exe unable to run. Windows cannot access the specified Device, path or file. You may not have the appropriate permissions to access the item" The errors popped up several times each

    However i think it still made a log, hopefully its the right one.

    Still getting redirected whenever i use Google homepage for searching. Don't know if the following will help or not, but sometimes i get the following error

    Invalid query: Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (11)
     

    Attached Files:

  11. KujoWolf

    KujoWolf Private E-2

    another message I'm getting from doing searches from Google is

    "Invalid query: Too many connections"

    also please ignore the part in my previous post about "The errors popped up several times each" i copied and pasted the text from an earlier post since it was the same error, just a different file. just forgot to delete that part.
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    (Drats)
    *A reminder -
    Ok, let's do this again.
    Using Avenger which you should still have on your desktop:
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\avenger.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  13. KujoWolf

    KujoWolf Private E-2

    Only had one error this time.

    when running the program, it couldn't run Cleanup.exe access was denied. i don't recall the error code it gave
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Have you downloaded a particular cleanup tool that is generating this error? I see no remaining malware in your logs. This issue should be taken up in our Software Forum

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds