please help - internet virus/malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by kianhazer, Jul 19, 2008.

  1. kianhazer

    kianhazer Private E-2

    my basic problem was some virus-trojan downloader and ads.js which appeared as soon as i got connected to the internet on opening either IE or opera. it was detected by kaspersky and AVG8 as i tried both separately but could not be deleted and appeared on opening each internet page.

    i followed ur advice for malware removal
    great work folks.
    ur advice was followed diligently by me.

    there were 2 problems though
    super antispyware, spybot n malwares was installed properly as advised

    there was some problem with combofix.
    as soon as i typed in RUN & clicked OK, it showed that its an old version and that i had to update to a newer version.

    since i had switched off all antivirus and antispyware, i just connected to internet and downloaded, without any protection at that time.
    hope that has not damaged the good work done by the other 3 wonderful programmes.

    the second problem with combofix was that as soon as i started the newer version that i downloaded and changed its name to combo-fix, it would not accept the change in name when i typed OK and the programme was not running.

    i then changed the name back to combofix ithout the "-" and in the RUN as well and then combofix worked and created a log.

    then ran mg tools too.

    i am attaching all the logs.
    if u can, please go through the logs and let me know if there is a mistake or if still some malware is there.

    also what further do i need to do further, whether to uninstall any of these programmes now form my laptop and which of these to keep.

    please help me out.
    thanks

    how do i attach the mg logs file, i have attached the maximum 3.
     

    Attached Files:

  2. kianhazer

    kianhazer Private E-2

    my logs for scan/ please help

    adding the mg logs.
    i think there was some problrm with combofix, plz help me with that
     

    Attached Files:

  3. kianhazer

    kianhazer Private E-2

    again the same problem inspite of following malware removal guide.
    as soon as i opened the internet AVG 8 showed
    "Threat detected
    free.idcards.info/day.js
    Exploit MDAC Active X code execution (type 268)"

    this keeps on appearing on each and every internet page that i connect
    im tired of it sir.
    please help me out of this virus which seems to have no end.

    Do i need to get a system format done.
    Im a doctor and have a lot of books and patient info on the laptop which i might loose.
    please help me.
     
  4. kianhazer

    kianhazer Private E-2

    please help me.
    my internet connection is again showing the threat as soon as i open any internet page.

    AVG 8 shows" Threat- free.idcards.info/day.js
    Exploit MDAC Active X code execution (type 268)

    im a doctor and have lots of books and patient information on my system.
    do i need to format ????

    please help me fast
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm not seeing any real problems in your logs other than the fact that this PC is being used to download torrents and similar for possible illegal software installations. This is a bad practice for anyone, but for a work PC, especially if you are really a doctor and have patient records, well you are asking for big trouble and potential lawsuits when and if your patient records and personal information get stolen.

    However I have a few things for you to do. Let's see what happens afterwards.

    You have some left overs from Symantec that need to be cleaned up. Run the below, reboot (don't skip), then run it a second time.

    Norton Removal Tool (SymNRT)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now let's flush the Java Cache
    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.


    Now let's flush the FireFox Cache


    To flush your FireFox Cache:
    • click Tools
    • select Options
    • select Privacy
    • in the section labeled Private Data click Clear Now
    Now let's flush the Internet Explorer Cache


    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 20, 2008
  6. kianhazer

    kianhazer Private E-2

    thank you sir for replying fast.
    me actually a doctor, am an anaesthetist and into critical care.
    yes, i had actually downloaded lots of stuff from torrent sites including medical books and loads of music.

    ok sir, will follow the advise given by you and attach the logs later on.
    but presently want to thank you for the fast reply and the good work u guys r doing.

    i think i would rather add another title to ur site - computer doctors?????

    well that message that i get right now on opening the IE browser the threat still persists with each and every internet page.
    i will follow ur advise and attach logs for reviewing.

    thanks guys, good job, keep it up.
     
  7. kianhazer

    kianhazer Private E-2

    sir,

    the regedit changes were a success and i followed all the instructions as to how u advised

    im attaching the combofix and mglogs for ur perusal.

    sir, still on opening ech IE page or opera page i keep on getting this same popup which shows that threat is detected and this is how it shows

    Web shield Alert
    accessed file is infected
    Threat detected

    Threat:v.freefl.info/day.js
    Threat name: Exploit MDAC Active X code execution (type 268)



    this keeps on on appearing at each and every page and at times while the page is being opened the threat is detected 4-5 times which they i have to click ok.

    also no antivirus including kaspersky or AVG gives an option to delete it.

    this opens only on connecting to the net and not on offline web pages.

    sir, im unable to understand the problem and please help me with that.
    lookingforward for ur instructions.

    the combofix file is not getting attached sir
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since this is being reported as an exploit, the first thing you should do is get all of your Microsoft Updates installed. Goto the below link and get all security patches installed:

    Windows Update

    It's up to you whether you want to upgrade to Win XP SP3 or not. But if you don't want to put in the SP3 update, you still need to get all of the other updates.

    The exploit being mentioned is most likely related to this: http://support.microsoft.com/kb/329414
     
  9. kianhazer

    kianhazer Private E-2

    sir this previous message was detected on opening each and every IE/ opera page by AVG 8

    Web shield Alert
    accessed file is infected
    Threat detected

    Threat:v.freefl.info/day.js
    Threat name: Exploit MDAC Active X code execution (type 268)


    I then uninstalled AVG and am using kaspersky 2009 now.
    also started using mozilla firefox.

    now Kaspersky 2009 still detects something like this, as a pop up on each and every IE/mozilla firefox page and it shows as

    Application firefox(or IE/opera): contains links to web page http://v.freefl.info/day.js, used to steal passwords, credit card numbers or other confidential data. Denied.

    view report

    the report of kasersky 2009 shows it as anti-phishing event and access denied.

    In the explorer bar of firefox, the site name appears for a flash of a second and then disappears or is blocked and the site or webpage that i want to connect to, opens up with the above mentioned pop up.



    sir, the kaspersky antivirus, super antispyware, spybot & malawarebytes anti malwares fail to detect any virus, trojan, spyware or malware on the comp.

    what do i do next sir. is my computer hacked and is the only option left is formatting and will that too help me get rid of my problems.

    please help me sir, seems like no end to this problem.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First I need to know if you did what I requested in my previous message.

    Now show me a real log from Kaspersky.

    Are you using a router? If so, as a temporary test please by pass your router and directly connect your PC to the internet thru your cable or DSL modem...etc and tell me if you still have any issues opening browser pages.
     
  11. kianhazer

    kianhazer Private E-2

    sir,

    im attaching the logs of kaspersky 2009, the system security and the online security

    i tried to get the patch "MS02-065: Buffer overrun in Microsoft Data Access Components can lead to code execution" as advised by you but the page requested for download could not be found.

    also for the SP 3 update they have advised for activating automatic updates but sir, that is already activated and all the automatic updates have been installed by me.

    do i still need to get SP 3 or SP 4 and the others like SP4 hotfixes download.

    are these downloads are about 365MB .
    is it the right file to download.

    also im not using any router.
    it is a direct broadband cable connection that i use.

    thanks for all the previous advise.
    kindly let me know what to do next and what about the reports of kaspersky scans - they still show these pop ups on each and every mozilla/IE page - Applicaton firefox - contains links to web page http://v.freefl.info/day.js, used to steal passwords, credit card numbers or other confidential data. Denied.


    thanks for all the help
     

    Attached Files:

  12. kianhazer

    kianhazer Private E-2

    1 remaining attachment sir
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The last service pack for Windows XP is SP3. If you are having problems with getting Windows updates or this service pack, you should post in the Software Forum.

    Your logs does not show any cases of this after 8/2/2008. Are you still getting them?
     
  14. kianhazer

    kianhazer Private E-2

    thanks a lot for such an early response.

    i will download the SP3 pack and install that.

    about these pop ups, yes sir, they r still there, kaspersky is detecting them and shows it has denied the access.

    im attaching the logs of yesterday and today sir. and this event is still happening.

    is there something else that i need to do???

    sir, even as i opened the new page to attach the following log, this antiphishing event according to kaspersky was again detected and showed on my screen as a pop up.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go to Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    Now please disable all addons for FireFox and see if you have the problem.

    Also please try using Internet Explorer and tell me if you have the problem. (make sure no other browsers are open when you use IE).
     
  16. kianhazer

    kianhazer Private E-2

    thanks for all the help.
    u guys r doing a great job.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does this mean you have no more problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds