New here, need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Musicinmysoul, Aug 9, 2008.

  1. Musicinmysoul

    Musicinmysoul Private E-2

    Hi there. I pirated some software that apparently contained viruses. If it helps at all, it was the new version of Winamp from Mininova. It changed my backround, sent me several popups for fake removal programs, and I've got "VIRUS ALERT!" in my tool bar by the time. Also, when I open the start menu it's only got the programs I put there and the most used programs, no Programs button, no My Computer, My Pictures, My Documents, My Music, anything. I ran SUPER Anti Spyware, but I'm still having a few symptoms, like the ones mentioned above. I have Spybot Search and Destroy, but I've had to download it again because it's not on my Desktop and I can't reach it any other way.

    Help please?

    Oh, and I don't know if this helps, but I keep getting this popup that says "Windows Security Alert

    Windows has detected an Internet attack attempt...Somebody's trying to infect your PC with spyware or harmful viruses. Run full systen scan now to protect your PC from Internet attacks, hijacking attempts and spyware! Click here to download spyware remover for total protection."

    Obviously I keep exing out of it, but still...

    Help!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Obviously you need to remove all pirated software immediately.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. Musicinmysoul

    Musicinmysoul Private E-2

    I actually went and followed that guide soon after I posted the thread, and I just got back on my computer after restarting after Search and Destroy finished it's scan. Most everything seems to be back to normal. No more military time, no more "VIRUS ALERT!", my Start layout is normal...everything seems to be good. Should I post the logs for reference for others? I don't know how much good it'll do anyone else but if it does...
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....you should attach the logs so that I can be sure that all of the malware is removed.
     
  5. Musicinmysoul

    Musicinmysoul Private E-2

    Alright, here they are.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I also need the MGLogs.zip.
     
  7. Musicinmysoul

    Musicinmysoul Private E-2

    Ok, here it is. I never ran it because I thought the problem was fixed.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Problem is nowhere near fixed...:(

    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 6"
    Java(TM) 6 Update 7
    Messenger Plus! Live --> main cause of LOP infections.

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Right click the desktop / properties / desktop / web --> make sure no box is checked and there is nothing there.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  9. Musicinmysoul

    Musicinmysoul Private E-2

    Ok, everything went fine except for this part:

    I just deleted all of the files in those folders, and Windows only gave me 1 error message on the 2nd folder of C:Documents and Settings\Danny\Local Settings\Temp, which I assume is because the files are from today. I didn't see any dates in either of the folders though.

    I attached the Avenger and MG logs.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears as though you did not disable TeaTimer ...so we still have some cleaning to do.

    Did you right click the desktop and remove the web settings? It is still showing in your HJT log:
    Desktop Component 0: Privacy Protection - (no file)

    Please disable all anti-virus and anti-spyware programs (Including TeaTImer) while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  11. Musicinmysoul

    Musicinmysoul Private E-2

    I've disabled TeaTimer twice now, and it appears as though the change isn't saving because every time I reopen Search and Destroy it's been enabled again.

    I just disabled TeaTimer and the option above it. Then I closed and reopened S&D, and TeaTimer was enabled again, but not the option above it. Then I closed and reopened, again, and it was finally disabled.

    When I right click the desktop and go to Properties\Desktop, it gives me options for my background, there's no mention of web settings.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have to click the customize button ( sorry for not mentioning that...we get a little rushed at times).

    Did you do the rest of what I gave you to do?
     
  13. Musicinmysoul

    Musicinmysoul Private E-2

    Ok, I did the Desktop thing and it doesn't look like anything was checked. I've attached the new MGTools zip file, and you didn't ask me to do anything with Avenger this time around so I'll assume it's just ok to attach the same log file.

    Hmm....weird. It doesn't look like I can attach attachments.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I wanted you to run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  15. Musicinmysoul

    Musicinmysoul Private E-2

    Weird...the "Manage Attachments" button isn't there any more when I use FireFox...
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not uninstall Messenger Plus! Live --> which I told you was the cause of your LOP infection.

    You also have not disable the guest account in user accounts.

    We also need to fix this ( unless you set it..which I doubt):
    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    What is this:
    C:\WINDOWS\T4

    After doing the above, run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  17. Musicinmysoul

    Musicinmysoul Private E-2

    The Guest Account has never been activated, I have no use for it.

    Why though is my Firefox not working any more? I can't attach attachments on here, I have to go to Internet Explorer. Also Wikipedia and Youtube don't work any more. I've attached a picture of what Wikipedia looks like when I try to access it.

    I don't know what C:\WINDOWS\T4 is.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure what you are trying to show me with that screen shot.

    If you con't know what these are, delete them:
    C:\Documents and Settings\All Users\Application Data\T2
    C:\WINDOWS\T4

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download HOSTER and then follow the below steps.

    * Unzip Hoster to a convenient folder such as C:\Hoster
    * Run Hoster.exe, click Restore Original Hosts and then click OK.
    * Click the X to exit the program

    Re-run ATF Cleaner .....tell me exactly what is still happening.

    When on MG's you may have to hit F5 on occasion to refresh the page.
     
  19. Musicinmysoul

    Musicinmysoul Private E-2

    I'm trying to show you that Firefox is acting abnormally for whatever reason. Wikipedia looks like that, and Youtube videos don't even load. I don't know if it's because I deleted those Java Updates or what...but I've attached more pictures to what these websites have looked like since I started this computer cleansing process.

    I put a black box around the problem on the attachment.jpg picture.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In your browser..open Tools / options / content....are your java boxes checked?

    This is only with FireFox..not IE, right?
     
  21. Musicinmysoul

    Musicinmysoul Private E-2

    The Java boxes are checked and yes, this is only on Firefox.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is not a malware issue....and would best be handled in the software section. But one thing to do it to uninstall, run CCleaner, reboot and re-install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds