New to forum and would appriciate any help...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kent Setty, Jul 16, 2008.

  1. Kent Setty

    Kent Setty Private E-2

    I have incountered a rash of computer poroblems in the last 24 hours, all having to do with malware.

    My computer is working slow and the IE is jumping me to strange websites and launching on it's own. I have also noticed that some of my IE security setting have been changed.

    I also have lost the tab to my get to my system restore settings; it is just gone!

    I am running XP SP2 and have already scanned with SUPERanti-spyware, spybot S&D, Malwarebytes, combofix and MGTools (however, I don't think that the last scanned correctly).

    Would there be someone that could talk me through this? I have some experience with computers but I am not "upto-speed" with this forum.

    Thanks in advance...
     
  2. Kent Setty

    Kent Setty Private E-2

    Here are the logs for Superantispyware and Malwarebytes...
     

    Attached Files:

  3. Kent Setty

    Kent Setty Private E-2

    Here are the logs for Combofix and MGTools...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually you look pretty good ....let's do a few things to clean up:

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2

    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Use windows explorer to find and delete:
    C:\Temp
    C:\WINDOWS\SYSTEM32\olixds01

    Now download and install:
    Java Runtime 6

    Now tell me what other malware issues you may be having.
     
  5. Kent Setty

    Kent Setty Private E-2

    Question...

    When you say the bold type below do you mean starting with: REGEDIT4
    or just: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-
    "updateMgr"=-

    ?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The entire quote box content ...starting with Regedit4 .....we are just removing some startup nuisance stuff. :)
     
  7. Kent Setty

    Kent Setty Private E-2

    Thanks for you help... things have setted down on this computer. :)

    my AVG scan from last night came up with: Trojanhorse Generator10.BDSL located in C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP834\A3341371.dll

    I am not noticing any strange behavior with the computer or IE. I am still missing some of my tab when I right click on mycomputer and select properties. I only see tabs for general and shortcut. I thought that is where I could toggle on and off the system restore and other functions. Any thoughts?:confused

    Oh, might be that I am paranoid but it looks like the icon in the left corner of my IE7 tab when I am on the Google web page has changed to a lite blue diamond instead of the dark blue lower case "g". I did notice that some of my IE security setting were being changed before.

    Again, thanks for you patience and advice!!!!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Avg is reporting an item in your system restore files ..which will go away when you toggle it.

    Did you remove the folders I asked you to remove?

    Perhaps you should re-run SAS, MWB's and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Attach the logs.
     
  9. Kent Setty

    Kent Setty Private E-2

    Yes, I deleted the files you asked for and re-installed java. Thanks for your good directions; everything went smoothly.

    The SAS scan found some Vundo Variants but the Malwarebytes was clean. I can't follow the MGTools so I hope that things are looking good.

    Question... Is not beening able to get to and disable my system restore letting some malware be reinstalled?

    Last message your wrote, "Avg is reporting an item in your system restore files ..which will go away when you toggle it." Could you eleborate on this more? I don't understand what you are meaning.

    Here are the logs of the last three scans...
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, in the Combofix quarantine folder and your system restore files.

    Please go to start / program files / accessories / system tools / and is there not an option for system restore? If there is, click it and lets see how far back you can go.
     
  11. Kent Setty

    Kent Setty Private E-2

    I looked at the system restore and my farthest day back was on Monday; it said that it was the "last known good configuration". Unfortunetly it wouldn't restore to that date when I clicked on it. It went through all the work but said that it couldn't restore the computer to that date.

    Should I retry Monday or try the next day, Tuesday? It has Tuesday listed as a system checkpoint.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try Tuesday....
     
  13. Kent Setty

    Kent Setty Private E-2

    No luck with Tuesday's restore. Said it couldn't do it. Wednesday is when everything started going "south" on my computer.

    What do you want me to do next?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this first:





    If it still is not working:
    Restore System Information
    -- see line #221 at right -- :
    http://www.kellys-korner-xp.com/xp_tweaks.htm
     
  15. Kent Setty

    Kent Setty Private E-2

    Cool!!!

    Worked like a charm!

    Thank You!

    That did the trick and all my tabs are back in working order.

    What next?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the system restore tab and uncheck the box for system restore ...reboot and then reopen it and check the box.

    What other problems are you having?
     
  17. Kent Setty

    Kent Setty Private E-2

    System restore disabled, rebooted and enabled.

    I think that everything is looking and working well. I don't know of anything else that is going wrong.

    Is there anything else you would like me to do?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!

    You can skip #11 as you have already done it.
     
  19. Kent Setty

    Kent Setty Private E-2

    Thanks again for all your help! You are very good at this and I was easily able to follow most of your directions.

    Eveything else is done but:

    I am not finding the following: "Delete the C:\cf folder from combofix."
    I was able to delete the combo-fix files with that run sequence but I don't see a "C:\cf" folder. I do have a "C:\combofix" folder that has one program in it "nircmd" (an mos-dos program). Is this what you are wanting me to delete?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....you can safely remove that folder as well as any of these that may still be left: ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt

    Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds