Numerus Malware problems, help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by Althea, Aug 31, 2008.

  1. Althea

    Althea Private E-2

    Within the last 24 hours or so (cant be exact as entire family use the desktop PC) the following symptoms began on the pc.

    • Hijacked Background: Currently appears as a warning about spy/malware
    • Hijacked Internet: Currently IE will not allow any sites to be visited and crashed when any attempt to do so is made.
    • Task Manager Unable to be opened
    • Lots of random infection messages with link to anti spyware/malware sites

    Having gone through the run first tutorial Issues 1,3,4 are resolved it seems, however the internet connection issue is still there and thus the pc cannot be used for browsing the internet. I had a few issues with some of the scans but heres the log files requested
     

    Attached Files:

  2. Althea

    Althea Private E-2

    additional post for other log file.....
     

    Attached Files:

  3. Althea

    Althea Private E-2

    Also need to know a few things, Are other PC's linked to a home network at risk if the infected pc is linked to said network and is it safe to use the infected pc for non internet related activities such as word processing and offline games.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The best/safest approach is to always remove the infected PC from the network and do not use it at all except to clean it. The more it is used, the more it reboots or powers down....etc, the more the infection can spread and mutate. When you do have to connect the PC to the internet to download tools and get updates, it would be best to disconnect all other PCs first to avoid the possibility of the infection spreading over the network.



    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Policies\Explorer\Run: [UYbuvR1Xef] C:\Documents and Settings\All Users\Application Data\jqfojulw\zqxghcdw.exe
    O21 - SSODL: DscGen - {35CBF1EF-55F3-B3FA-B06C-06C4A6FC20A9} - C:\Program Files\hicxwgc\DscGen.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Althea

    Althea Private E-2

    Still having problems with my internet connection, my homepage loads then as soon as i try and search or goto a website another blank IE pops up and crashes while the other does nothing.

    Logs as requested:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your infection mutated and spread. Probably occurred in between posting your first logs and running my last fix. Make sure that you do not reboot or power down from now on after attaching any logs. Hang on while I work up another fix.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does your copy of Spyware Doctor also include and antivirus? If not, you have no antivirus protection installed.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [SetShSmart] C:\WINDOWS\system32\olkjulkt.exe
    O4 - HKCU\..\Run: [sysmnt] C:\WINDOWS\system32\fgxotcfs.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now doubleclick the fixme.reg patch saved to your desktop in the previous fix and allow it to be added to your registry.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    Remember do not reboot or power down until I can get back to you about your status.
     
  8. Althea

    Althea Private E-2

    Hopefully it will stay online, it has crashed once since the last fix though.

    If you need new logs since it crashed lemme know =0
    Thanks for he help too its really appreciated ^^
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you saw my fix in msg # 7??

    Just run the new fix and give me the new logs and we will go from there. If the PC does crash or does get rebooted for any reason after you attach the new logs, make sure you come back and let me know before I post another fix. We would have to get new logs to make sure we are addressing the real current problems. ;)

    You're welcome.
     
  10. Althea

    Althea Private E-2

    Ok same problem with my internet explorer. The only reboot was that done by combofix no others yet since this last fx.

    My Spyware Doctor does have the antivirus add on yes =)

    Logs:
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean now so your IE problems do not appear to be due to any remaining malware.

    What browser addons do you have? Try disabling all of them under Tools, Manage Addons.

    Does it have the same problems in safe boot mode?


    If still having problems try this.

    Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Try another browser like Mozilla FireFox Does it work OK.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, do you know what the below is for?

    S3 Revolution1;Revolution1;C:\Documents and Settings\User\Desktop\Revolution_Engine_7.2\Revolution Engine 7.2\SHAK3.sys []
     
  13. Althea

    Althea Private E-2

    Certainly seems damage was done to IE,

    I tried disabling add ons no joy, So i took firefox from my laptop, put it onto the desktop and firefox works fine. no problems or issues there.

    And yea I know what that is =) Had to get an explaination from a family member but yea.

    I also reset web settings no joy too, seems to just be IE though. What would you suggest I do with it =)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it happen in safe boot mode? This may be a problem that someone in the Software Forum would have ideas about. Possibly uninstalling the IE7 update, rebooting and then reinstalling.
     
  15. Althea

    Althea Private E-2

    Does the same regardless of wether im in safe boot mode or not.

    How would i go about uninstalling and re-installing IE?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well this is why I suggested the Software Forum since they would have more time to discusss this and work on any issues you run into. I'm not even positive that reinstalling IE will fix the problem. You may need to look at your Event Viewer logs to see if there is information there on why it is crashing.

    However see this link for installation info: http://msdn.microsoft.com/en-us/ie/aa740486.aspx


    Also see the below for info on Event Viewer:

    http://support.microsoft.com/kb/308427
     
  17. Althea

    Althea Private E-2

    Think I got it fixed =) Thankyou for all the help, hope my next visit here wont be for similar reasons to this one ^^ You guys are doing a great job keep up the good work =)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds