PC accessing internet at boot and playing porn sounds

Discussion in 'Malware Help (A Specialist Will Reply)' started by JMBM, Mar 3, 2009.

  1. JMBM

    JMBM Private E-2

    My first post at MajorGeeks... I'm only afraid because I didn't discover this site before... :(

    Let me try to resume the situation:

    1) Aprox 1 month ago I discovered a process eating my CPU. It was wingrowup.exe
    I did some research and found it was malware, Bagle. I follow some instructions (I'm sorry I was not systematic at all, and after deleting some register keys, some files in user/Roaming/AppData/drivers, etc. and reinstalling my Norton 360, I thought I got rid of it.

    2) Since then (I think it was at the same time), every time I turn on my computer, and while the normal stuff is loading (sidebar widgets), a piece of sound from a porn film starts playing. (At least it changes each time I boot :) )

    3) I've detected that at the same time the pc access the net and starts downloading (I see it at DU Meter), so I assume this is the porn sound track

    4) I've turned on my linksys gateway log, and I've had detected that my PC accesses a lot of ip addresses like 87.248.xxx.xxx )eg. 87.248.210.148, 87.248.218.101 and a lot more)

    5) Two days ago I received a letter from my ISP asking me to check my installation, as they detected spam coming from my IP address.

    I've run all the steps from your (excellent) "read and run me first", but the problem is still there.

    So... I would like to have your help before reinstalling Vista (or maybe XP).

    Attached the different logs. Thank you in advance, and I hope my english is good enough to explain my problem.

    Regards,
     

    Attached Files:

  2. JMBM

    JMBM Private E-2

    2nd part.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is there a reason you are going thru a proxy server?

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Use windows explorer to see if this still exists and delete it if it does:
    C:\Windows\system32\SpywareRemover.exe

    Have you checked your firewall policies?

    I am not seeing any thing else in your logs.

    But lets have you try this:
    Using BitDefender Online Scan.
     
  4. JMBM

    JMBM Private E-2

    Thank you for your support, TimW.

    No, I'm not going thru a proxy. I checked both IE and Firefox, and both are configured as "no proxy". (It's true that there was an IP in the proxy field, but the button radio was not checked. Anyway I deleted it)

    I received the "successful" message for the merge of the register, and then I deleted C:\Windows\system32\SpywareRemover.exe, that was still there. (And empty the recycle bin).

    Finally I run Bitdefender wich detected some stuff. Log attached.

    Regarding the firewall policies, to be honest, I don't know what to check. I have Norton360 as AV and firewall.

    I will check again, but it seems there was not sound playing when I reboot.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if the issue continues......in the mean time ....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. JMBM

    JMBM Private E-2

    TimW,

    very good news: issues are not there anymore!

    I just run the final steps, and I'm following your protection recomendations.

    I thank you soooooooo much for your help... :celebrate
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds