New member...Internet 101

Discussion in 'Malware Help (A Specialist Will Reply)' started by iamluvable, Jul 5, 2007.

  1. iamluvable

    iamluvable Private E-2

    Hello there! I found this site through a search for virus removal...due to my BIOS system being overrun with...who knows what...I know nothing at all about computers and have fallen to the hands of my recovery disk...I am currently reformatting my hard drive in my other computer which is having a lot of trouble...some ghost.err???...I wish there was someone nearby that could show me what to do....I lost a lot of important stuff...I did use 10 in 1 Mcaffee...still I was invaded...so here I am...hello...I have a lot of reading to do...thank you for offering help to those in need...
    PS the link on the malware thread which goes to bleeping computers sent me a trojan...Autoit.A...Now my recovery disk is infected...is there a method to clean any of my computer or disk without spending anything? I really need help...luv
     
  2. iamluvable

    iamluvable Private E-2

    Hi! i was reading the posts in this forum...combo.exe link is giving me the Autoit.A trojan...via bleeping computers...is there another link that is clean?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are formatting your PC, why are you even trying to run ComboFix. Any malware within your OS will be gone after a repartition and format. Also in addition the link for ComboFix at bleepingcomputers is not infected. Your copy of McAfee is wrong.(I assume this is what is saying that since you did not say) Autoit.A is aTrojan-Keylogger which ComboFix is not.

    Why are you saying your Recovery Disk is infected? Are your Recovery Disks the original CDs that came with your PC or are you referring to something else?

    Problems with formatting or using your Recovery Disks do not belong in this forum. This forum is only for malware removal. You should post problems like this in the Hardware Forum or possibly the Software Forum if you have questions about using the Recovery Disk software.
     
  4. iamluvable

    iamluvable Private E-2

    Chaslang
    Thank you for your reply. I did post this in the hardware section last night (early am)...somehow it was redirected here...I had to check my postings to see where this went...anyways...
    On June 30th Win Def started to pick up Winfixer and Downloader.Win32...I chose to reinstall my McAfee 10 in one and remove Spysweeper with Anti Virus...My system got worse...pop ups galore unable to reboot in safe mode etc...so I did a google search and found bleeping computers...after I read through some of the malware forums I followed the advice to run multiple programs to fix my machine. The problem that one poster had was almost identical to mine. I downloaded CW Shredde, About Buster (Which removed my IE but pop ups of IE remained), Smitrun, Ad Aware, AVG, Run CC, Ewido and a few others...It helped my computder for about an hour then it shut down with the blue screen...I called Microsoft and the tech said I had an infection in the Systems Bios settings...since my computer wouldn't run the recovery disk (original from Toshiba) He told me my disk was infected...That is when I found this forum...I had used a recovery disk from my older Dell computer...which worked I then shut off my machine with the drive open....when it was off I put in recovery disk (Toshiba disk) and started it up...it worked!!! I did wash my cd off with soap and water...I thought that is what cleaning your disk was...whatever I did it worked...thank you for replying...luv
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so are you saying you have no more problems at this time? If you are not having anymore problems with malware, you should work thru the below:

    How to Protect yourself from malware!
     
  6. iamluvable

    iamluvable Private E-2

    Chaslang
    Thank you very much for the link. I have been working on getting these programs installed...but my machine has been very slugish...and I have had to remove my router...which has gone from 100 mbs to 10 mbs...my computer was not showing I had one connected...hmmm I think I will just follow your advice and install the needed programs...skip my wireless/router and deal with it...once again I thank you for your knowledge and assistance..if you notice misspelled words...it is another issue I will need to resolve...my computer is not recording all of my key stokes...bye for now!--Lu
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Slow PC syndrome is more frequently caused by what you have installed and are running then it is cause by malware. That does not mean malware cannot slow a PC down. It can do that. It's just that more frequently people have this problem due to loading to man unnecessary programs at startup, using resource hog internet security suites (note that McAfee can be a resource hog), too many toolbars (none of which are really necessary)....etc.

    If you wish to give your PC a fully cleaning that will check it out for all kinds of malware (and we will frequently even suggest a few things to help performance) then work thru the below:


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
    Last edited: Jul 7, 2007
  8. iamluvable

    iamluvable Private E-2

    Once again...Thank you! I do have a "newbie question...Did I download the correct "Java" file...Sun Download Manager 2.0 (Web)? There were non with the exact name mentioned and I honestly do not have a clue what its for...I do know that a lot of programs need it and thats all I know. Thank you!!!

    Also, Do I have the correct anti spy, spam, malware, virus and firewalls? I have disabled Microsoft Windows firewall...
    a squared free 3.0
    a squared HiJackFree 3.0
    CCleaner
    COMODO Firewall Pro
    J2SE Runtime Environment 5.0 Update 1
    PC Tools AntiVirus 3.1
    Spybot-Search & Destroy 1.4
    SpywareBlaster v3.5.1
    Windows Defender
    Whew!! I hope I have done this correctly! Please let me know...also which ones NEED to be in the start up directory. Many Thanks!-Luv
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! The link for the current version is in the READ & RUN ME in step 6 where it says to uninstall all old versions and install the current version. You have at least one old version (J2SE Runtime Environment 5.0 Update 1) installed.

    These are all okay but the below do not need to load/run at startup:
    a squared free 3.0
    a squared HiJackFree 3.0
    CCleaner
    Spybot-Search & Destroy 1.4
    SpywareBlaster v3.5.1
     
  10. iamluvable

    iamluvable Private E-2

    Ok...I am so sorry to take up so much of your time...it would be a lot easier if someone were here to walk me through this process...that is my method of learning...so i may seem slow to catch on...really I am not its just i need to see it done while you tell me what you are doing...otherwise i can read the messages and do the process but i am not learning much...EXCEPT I want you to know that i DO appreciate your help...I would not be on the internet right now if you hadn't helped me...Now the java dillemma...I wil do my best to choose the right one...they all look the same...and thre ar so many programs...oops...will the java fix my keyboard...since it is not logging all my keystrokes...you are brilliant! :dood Thank so much for your tim!
    Luv
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All we would be doing is listing the steps of the READ ME one at a time. You just need to follow the directions and complete them one step at a time. But if you formatted your PC, why are you running the READ & RUN ME now? If you have not reinstalled your Windows software and all drivers for your PC properly, then you are in the wrong forum.


    What are you referring too? There is nothing to chose from? Just uninstall the old version that I already told you to uninstall and install the new version from the link given in the READ ME ( this is the link given Sun Java Runtime Environment )

    ????????

    What keyboard problem are you referring too? This is the first you mentioned it. But no! Keyboard problems will not be fixed by installing Sun Java.

    I'm not exactly sure what it is that you are even trying to do anymore. In your first message you said you are formatting your hard disk in another computer. So as I stated above, if you already did format your hard disk, then what exactly is it that you want us to help you with in the Malware Forum.

    Also you said you put in a recovery disk from an older Dell PC into a Toshiba. I'm not sure what you were even thinking but they are totally incompatible. This is also not something we can help you with in the Malware Forum. If you need to reinstall Windows, you either need an original Microsoft Windows XP CD, or an OEM Windows XP from Toshiba, or you need the System Recovery Disks for your Toshiba to bring it back to the state in which it was shipped to you. However, none of this is a topic for the Malware Forum.
     
  12. iamluvable

    iamluvable Private E-2

    Chaslang i have a preliminory report in reference to the Malware (showed its ugly face...may I send it PM...confidentiality reasons...There have been 3 incidents where my comp rebooted itself...if ok I will PM the info. I appreciate your patience with me. Yes I have been off topic quite a bit...I do think it is all related to malware issues...I hope to hear from you soon!!
     
  13. iamluvable

    iamluvable Private E-2

    Re: New member...Internet 101---My computer is now posessed....

    As a starving student single parent and interning adult I am very sad about these Dialers, Trojans, registry deleters And turning my password protected computer on?? I might as well leave the front door to my house open...has anyone seen chaslang??? I will PAY him--all of you as witnesses--to get this fixed...my biggest concern is my computer is not just private use...it had confidental, sealed documents...etc...I guess uncle sam needs to invest in a different AV, FW etc...seriously most of the stuff is on write protected disks...but there is still a history etc...correct? I will wait for chaslang...i need help before I can reboot in safe mode...I think these "sheetsy" things that are infecting us were released ---there goes my comp again...it shut off...wait it is the screen that is flashing...I will shut up now...oh yeah...I wonder if some brilliant person decided to celebrate the 4th by infecting so many computers???? Just a thought....luv
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: New member...Internet 101---My computer is now posessed....

    I'm not sure what you want to discuss in a PM, but go ahead and send me some info. You have to note that we really cannot work in PMs for multiple reasons. One of which is that they are severely limited in size. And secondly cannot contain any attachments. Thus it is basically impossible to work there. You really need to answer my questions/comments in message number 11. If you have properly formatted your PC, you should not be infected again unless you did one of a few things:
    1. reinstalled from infected media
    2. reinstalled applications or programs that contain infections
    3. connected to the internet without proper protection and quickly became reinfected (it can take as little as 10 seconds to get reinfected if a PC is not properly updated and protected. You don't even have to open a browser.)
    Again if your problems are not malware (and most do not sound like malware), I cannot help you in this forum as we are too busy working on malware problems.
     
  15. iamluvable

    iamluvable Private E-2

    Chaslang-
    I attempted to use the Toshiba recovery disk 3 times...at about 20-25% it would give me an error about ghost.err? i think then insert disk...then to the DOS screen choose retry abort and another option. I was frustrated and thought I can use my DELL windows disk which is included in their recovery disk. The problem witnessed by a sr tech at microsoft is there were chages done with the BIOS as soon as the computer would read the dik it would just stop...no f2 no f8 and no f 12...it froze went to the DOS screen and said C:\delfiles.cmd file is missing type in a new path...some thing similar at least
    Thisa happened each time i attempted to format the computer.
    I got the idea of a BIOS infection from the microsoft guy....I dont recall his name...he did say he was from india...STRONG accent. incidences happened prior to reformatting the hard drive the computer had

    I am not one of the “great communicators through email, forums, etc…
    Here is a copy of what is on my add/remove programs window…these changes happened between 10:05 and 10:15 this am. I know this because I was working on the Sun systems issue. Nothing will uninstall. I did see this issue on another forum when I did a yahoo search on my other computer…here is the other thread second to last post…

    http://forums.pcpitstop.com/index.php?showtopic=135264&pid=1334546&st=0&#entry1334546

    ADD/REMOVE PROGRAM LIST
    **At the time of this report there were no remove/repair buttons of any kind. Many of the programs “vanished” When I did a search for a program…just anyone my machine warned me the virtual memory was low…over the course of just the past 3 days the system has shown that warning at least 6 times…it went into sleep mode then would wake up with files moving around on the desktop.and whenever I deleted one then one would pop up.
    I did copy the report(detailed)

    **AiO_Scan (no size noted) ---It disappeared
    CD Keys (.30 MB) I added this one
    Free PDF Converter (1.84 MB) I added this one
    HP Driver Diagnostics (1.86 MB) I added this one
    HP Photosmart Essential (12.29 MB) I added this one
    J2SE Runtime Environment 5.0 Update 1 I added this one (I tried to remove it so I could install the correct one but nothing will uninstall)
    Keyfinder Advanced 2007 (Trial Version) (.94 MB) I added this one
    Microsoft .NET Framework 1.1 (no size noted)
    Microsoft Office Standard Edition 2003; 175.00 MB
    Microsoft Works 285 MB
    MSXML 4.0 SP2 (KB927978) 2.56 MB
    **QFolder (no size noted)
    **Scan (no size noted)
    Shipping Assistant 3.1 (8.35 MB) I added this one
    Sonic DLA 2.60 MB
    Sonic RecordNow! 13.9 MB
    **WebFldrs XP (no size noted)
    Windows Defender 9.57 MB
    **Denotes files I did not and the system restore disk did not install…Please note There is NO option to ADD/REMOVE ANY of these!

    Much of my stuff is gone but many things show up in Software Explorers…strange here is the start up list….
    Agere SoftModem Messaging Applet
    ATI Desktop Component
    CD/DVD Drive Accoustic Silencer
    COMODO Firewall Pro
    LtMoh Application
    Microsoft Userinit Logon Application
    Microsoft Windows Explorer
    PC Tools AntiVirus Client
    PC Tools AntiVirus Client
    RAMASST
    Software Upgrades
    tfswctrl
    THotkey
    TOSHIBA Virtual Sound
    Windows Defender

    Windows defender has in history with ?’s This program has potentionally unwanted behavior for each of the following :
    07/08/07
    TvsTray.exe
    thotkey.exe
    RAMASST.lnk
    Ltmoh.exe
    AGRSMMSG.exe
    tfswctrl.exe
    toscdspd.exe
    atiptaxx.exe

    07/07/07
    inspect.sys
    cmdagent.exe
    cmdmon.sys

    07/06/07
    hpqscnvw.exe
    hpqkygrp.exe
    HKCU@S-1-5-21-1707895500-344746961-98094002-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar
    HKCU@S-1-5-21-1707895500-344746961-98094002-1006\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\\provider
    HKCU@S-1-5-21-1707895500-344746961-98094002-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page
    wpsdrvnt.sys
    Teefer.sys

    07/05/07
    a2hijackfree.exe
    a2free.exe
    NDSTray.exe
    ACU.exe
    cfmain.exe
    AVFilter.sys
    AVHook.sys
    AVRec.sys
    file: C:\WINDOWS\tasks\At21.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At21.job

    file: C:\WINDOWS\tasks\At18.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At18.job
    file: C:\WINDOWS\tasks\At22.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At22.job

    file: C:\WINDOWS\tasks\At16.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At16.job

    file: C:\WINDOWS\tasks\At15.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At15.job

    file: C:\WINDOWS\tasks\At13.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At13.job

    file: C:\WINDOWS\tasks\At3.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At3.job


    file: C:\WINDOWS\tasks\At14.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At14.job


    file: C:\WINDOWS\tasks\At1.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At1.job

    file: C:\WINDOWS\tasks\At2.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At2.job

    file: C:\WINDOWS\tasks\At10.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At10.job


    file: C:\WINDOWS\tasks\At4.job
    file: C:\WINDOWS\system32\tn6K54vk.exe
    taskscheduler: C:\WINDOWS\tasks\At4.job

    clsid:
    HKLM\SOFTWARE\CLASSES\CLSID\{AEEAEC2D-7EE9-4C66-937C-80BF8B03FD54}
    regkey:
    HKLM\SOFTWARE\CLASSES\TYPELIB\{07E69192-65E2-41A1-B9F4-3B5A619E4732}\1.0
    070507 (con’t)
    regkey:
    HKLM\SOFTWARE\CLASSES\CLSID\{AEEAEC2D-7EE9-4C66-937C-80BF8B03FD54}
    regkey:
    HKLM\Software\Classes\*\shelles\contextMenuHandlers\PCTAVShellExtension
    contextmenu:
    HKLM\Software\Classes\*\shelles\contextMenuHandlers\PCTAVShellExtension
    typelibversion:
    HKLM\SOFTWARE\CLASSES\TYPELIB\{07E69192-65E2-41A1-B9F4-3B5A619E4732}\1.0
    Typelib:
    HKLM\SOFTWARE\CLASSES\TYPELIB\{07E69192-65E2-41A1-B9F4-3B5A619E4732}
    File:
    C:\Program Files\PC Tools Antivirus\PCTAVShellExtension.dll

    There are a couple more…if you nee them let me know…I need a typing break…I haven’t even seen outside since this happened TUESDAY!!

    There is Nothing in Quarantine
    There is Nothing in Allowed items
    That concludes Windows Defender…

    *Currently in the Quick Launch are:
    A2, IE, PC Tools AV, Desktop, Spybot, Media Player, Yahoo Mail and YIM (left side)
    Task Manager, PC Tools AV, COMODO, Local Area Connection, volume and CD/DVD Drive Acoustic Silencer (right side)
    I have verified msconfig is set normal start up…but will I be successful in SAFE MODE with the malware still in system???

    19:15 070807
    A-squared is running a quick scan. I shut down the computer (Toshiba) disabled the LAN, WIRELESS and 1394 to keep it from going to the internet. I did this to both computers, earlier…shut them down d/c the cables etc…Well I was gone for about an hour…when I came home the computer was on and files were moving around….I HAVE THE WELCOME SCREEN PASSWORD PROTECTED…LET ME BACK UP FOR A MOMENT TO GIVE YOU A SCENARIO…JUST AFTER EASTER MY WIRELESS WAS GONE IN A MATTER OF A FEW SECONDS I PURCHASED THE ROUTER ON 4-13-07 ON THE 18TH MAJOR PROBLEMS…SERIOUSLY…I WAS DOING HOMEWORK GRABBED A BITE TO EAT…BACK IN LESS THAN 5 AND THE WHOLE INTERNET CONNECTIONS WAS GONE…NOTHING IN PROGRAMS ETC…I EVEN HAD A GEEK SQUAD GUY TAKE A PEEK..HE ASKED ME IF I FORGOT TO INSTALL THE WHOLE DISK…IT WAS SUPPOSED TO BE PREINSTALLED…? The point is it worked before this incident,,,They had to have been there. DRIVERS…ETC…SO I WENT TO BELKIN SITE AND THERE WAS A BIG NOTICE ABOUT MY VERSION OF ROUTER AND TO CALL MY ISP. I CALLED BELKIN ANYWAYS…THE MAN WAS HELPFUK UNTIL I MENTIONED THE MODEL…HE SHUT UP QUICKLY AND TOLD ME I HAD TO CALL THE OTHER NUMBER…LEGAL STUFF…BACK TO THE PRESENT…IT WASN’T UNTIL I DID A QUICK CHECK TO VERIFY THE ROUTER IS THERE…THE PROGRAMS THAT I TRIED DON’T LOCATE A ROUTER OR ANYTHING CLOSE TO THE WORD BELKIN!!! I REQUESTED A REFUND THEY SAID I HAVE TO FILL OUT A FORM THEN VERIFY THE “VALIDITY” OF MY REQUEST….WHAT A BUNCH OF CREEPS…I BOUGHT THE ROUTER IN APRIL HAD IT HACKED IN APRIL…CONVINCED BY CLEARWIRE THAT IT IS OK NOW…LIKE THEY CAN TELL OVER THE PHONE…
    July fourth the neighbor had told me that she too had problems with all three of their computers.


    A-SQUARED HAS FOUND---
    Heuristic.dialer.RAS
    location is
    C:\SystemVolume Information\_restore{5B686006-38BC-4D60-BDB1-AFED744EDC32}\RP3\A0002188.exe
    C:\SystemVolume Information\_restore{5B686006-38BC-4D60-BDB1-AFED744EDC32}\RP3\A0002190.exe
    The scan was brief,,,the computer froze up
    07/08/07
    20:25
     
  16. iamluvable

    iamluvable Private E-2

    OK for the crap cleaner it wants to delete 100.1MB...is this ok to do?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!!!! Everything we give you in the READ & RUN ME is safe to do any we need you to follow those instructions completely and attach the logs! Until you do this, we cannot help you. All the information we need to get started will be provide to us when you follow those instructions. You are just making it take longer to get any help by not following those instructions. I don't need you to post the information that you posted in message number 15 (which is the same as posting inline logs). I need you to run the READ & RUN ME.
     
  18. iamluvable

    iamluvable Private E-2

    Three files attached
     

    Attached Files:

    Last edited by a moderator: Jul 11, 2007
  19. iamluvable

    iamluvable Private E-2

    View attachment avg scan report.txt

    I was DENIED access to counter spy....even in the administrator profile.
    Since my scans:

    Virus or unwanted program 'TR/Hijack.Explor.3615 [TR/Hijack.Explor.3615]'
    detected in file 'C:\WINDOWS\system32\tn6K54vk.exe.
    Action performed: Move file to quarantine
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only item of concern from all of your logs was this file:
    C:\WINDOWS\system32\tn6K54vk.exe

    However, whatever you posted the log from in message # 19 says it was quarantined.

    Thus I see no malware problems.
     
  21. iamluvable

    iamluvable Private E-2

    Pefect! Thank you for your help and resources!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds