Please check my logs my comp may be infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by jacob123, Apr 26, 2009.

  1. jacob123

    jacob123 Private E-2

    Hey I have been waiting six hours did the maintenence thing where i remove unused registrys with ccleaner and remove cache files then used jkdefrag to defrag my system and it made it a tiny bit faster but it still lags,
    I removed all the quarantine files and I removed my recycle bin files but it's still a lot laggy.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the following:
    Yoog Removal

    Now, Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Lu-Ann\Application Data\029F71
    C:\WINDOWS\rmursyaa
    C:\WINDOWS\hpexcocd
    C:\WINDOWS\system32\bc4cd24c-cd33-558d-e215-51f55655666d.exe
    C:\WINDOWS\system32\ren247.tmp  
    C:\WINDOWS\system32\ren248.tmp
    c:\windows\system32\wogiregu.dll
    c:\windows\Jqelego.dll
    c:\windows\ebimecusura.dll
    
    Folder::
    C:\Documents and Settings\Lu-Ann\Application Data\029F71
    C:\WINDOWS\rmursyaa
    C:\WINDOWS\hpexcocd
    
    AtJob::
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Ahofajugabor"=-
    "Yqebamerihesog"=-
    "CPM3b1f5b48"=-
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. jacob123

    jacob123 Private E-2

    Okay sorry it took so long I have been on a vacation and I totally forgot about this post but I remembered, And I did everything you said, But the yoog removal didnt work, I removed it from the manage default search engines thing and it came back, i went into the folder went to go remove the .default like you told me on yoog, It came back right when I opened firefox, And I went to remove it from internet explorerer

    it shows [Yoog Search] On my top right but I go to the search engine place and it shows like 1 million googles so it took me 10 mins to get all the way down to the bottom, i saw the yoog at the bottom and the default search engine thing you told me about, I opened default one like you said, It didn't show yoog under there, I went under manage addons didnt find that stuff, And I only found

    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)

    and

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    there was no

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Heres my logs I hope theres something else I can do, I already tried wiping out my computer with the windows installation disc, It didn't work, Best buy is asking 200 dollars to do it, and this other place is telling me id be waiting 5 weeks for it to be wiped out...

    Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the new logs. TimW cannot continue with you until you attach them.
     
  5. jacob123

    jacob123 Private E-2

    There you go sorry sometimes I tend to be an idiot, Well here you go.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any references to yoog in your logs. Did you do the removal procedures in safe mode? Did you do all of the instructions? Esp. going to the profiles folder -> C:\Documents and Settings\UserName\Application Data\Mozilla\Firefox\Profiles\default.zdt?
     
  7. jacob123

    jacob123 Private E-2

    Yea safe mode with networking and I took all steps
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tim,

    They were in the first ComboFix log and still need to be removed.

    When you do additional scans with ComboFix, you need to use the Extra:: command if you want to see all supplementary scan info. Normall the Supplementary Scan output is only generated in the ComboFix.txt if the user double clicks ComboFix.exe to run it. It is not generated automatically when using CFScript.txt
     
  9. jacob123

    jacob123 Private E-2

    http://i150.photobucket.com/albums/s110/abombapoc/majorgeeksyoogpic.jpg

    Here is a pic, look on the top right of the pic it shows the yoog search bar

    It's here also
    http://i150.photobucket.com/albums/s110/abombapoc/YoogIsthere.jpg

    But it's not here.
    http://i150.photobucket.com/albums/s110/abombapoc/Butitsnothere.jpg

    Thanks, And yes I went into "Safe Mode with Networking"
    I deleted the firefox .default thing, It came back after i reopened firefox, I deleted it again, And I tried doing the internet explorer but It didn't seem to work either, I don't know why maybe I should just use safe mode not with networking? =) Okay Thanks!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java(TM) 6 Update 13
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus - McAfee, antispyware - Spyware Doctor...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. jacob123

    jacob123 Private E-2

    Okay did it, It's the same way, yoog search is still there,
    Am I not cureable? Will i have to look to *gulp* Wiping out my computer and reinstalling windows xp?
     
  12. jacob123

    jacob123 Private E-2

    Lol sorry forgot to upload XD
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any traces of yoog in your logs. If you are still having it as an issue, then you probably need to totally uninstall FireFox. Here are the instructions for removing it completely. After which, you will need to run CCleaner ( both the cleaner and the registry - making the backup when prompted):

    Uninstall FireFox.

    Then you can reinstall it and see if the issue persists.
     
  14. jacob123

    jacob123 Private E-2

    yep still there, I'm gonna reboot my computer with Microsoft Windows XP Proffessional Gateway System Recovery CD/DVD to reinstall windows! That will probably work.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That would be one way to go. Uninstalling FireFox as I directed would be the other way. Let me know how things work out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds