Please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ihatebugs, Aug 5, 2007.

  1. ihatebugs

    ihatebugs Private E-2

    Last Sunday I let my 24 yr old son use my computer to check his 'myspace'. Monday morning when i logged on, i started immediately having problems and they're only getting worse! I have a system optimizer file in my registry that changes file names every 40 minutes with the command 'forkonce' behind it. i have run the cleaner, along with my avg at least once daily and am cleaning out the same 3 trojans each time, with a total of 3 instances of each of them in documents and settings, system, and system32. i really dont want to Fdisk, can someone help? Ive got log files if anyone would care to see them. Thanks, i'm ready to kill a kid here! :guns:guns
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. ihatebugs

    ihatebugs Private E-2

    i completed the prerequisites you asked for and everything seemed fine...for 40 munutes. At the end of the 40 minutes, my alarm went off, a registry entry had changed again. Also, an audio feed of what appeard to be some sort of news report started playing. I saw the window pop up and then close, but by the time i opened my task manager to see what was running it had stopped.
    this computer is only a few months old, and has maybe 6 gb total on it.
     
  4. ihatebugs

    ihatebugs Private E-2

    Please see attached hijackthis.log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually no you have not! Please see the instructions again and run ALL of the procedures and attach ALL 6 of the requested logs. HijackThis was not the first thing nor only the we requested. You cannot remove Virtumonde problems by just seeing and using a HijackThis log. Also you are using MSconfig to control startups. Based only on what I see in your HJT log it appears that you did not run most of the READ & RUN ME.
     
  6. ihatebugs

    ihatebugs Private E-2

    Panda Scan Finished Off My Ie

    did all the scans you asked except panda -- tried it 8 or 9 times, but it kept freezing up my IE and now it won't even load at all.
    i'm using mozilla foxfire for now, but since i have not completed all the scans you asked for, do you want any of the logs at all? REALLY need help before this is unfixable. thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If PandaActiveScan is the only thing you have not been able to run then attach the 5 other requested logs.

    Make sure that you have re-run HijackThis to get a new log after all the other steps were completed and make sure MSconfig is not being used.

    Why are you running this PC without proper protection?
     
  8. ihatebugs

    ihatebugs Private E-2

    Please don't chastise me for something i feel completely idiotic over already. I thought buying and running AVG Antispyware was sufficient for what i was doing, and it WAS...for what *i* was doing. Suffice it to say, i feel pretty stupid. If you can help me, that's great. My logs are attached, hopefully in the order you requested them. I'm sorry if i came across as presumptuous earlier by not running all scans, but in all honesty i was worried that they wouldn't load or run right due to the problems. I will send another msg with the remaining logs.
    hope u can help me.
    thanks.
     

    Attached Files:

  9. ihatebugs

    ihatebugs Private E-2

    additional logs attached.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see step 0 of the READ ME where we specify the MSconfig must not be used. Follow those directions and then get new logs from GetRunKey and HijackThis. Then we will be able to work up a complete fix.

    Note: I really was not chastising you about the protection. I just wanted to know why. We here all kinds of reasons for not having proper protection. And then there are also some people who really do not know that they were not properly protected.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I was waiting for you to attach the new logs, I started going thru all of your current logs and found you have a load of problems. It will simply some of our manual cleaning steps by having you run another tool which should help remove a bunch of problems. On the downside.....I will be asking you for another set of logs that from after you run this tool. Sorry but it will make it easier for later steps.

    But first Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11

    Now the other tool!

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
     
  12. ihatebugs

    ihatebugs Private E-2

    this is yet another problem. i keep disabling all on misconfig startup but it keeps coming back. i will try it again and rerun what you asked. sorry, i didnt realize it had come back on.
     
  13. ihatebugs

    ihatebugs Private E-2

    combofix is not giving me the option to save file, only to cancel.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could be because your Windows XP version is so out of date and it cannot be properly supported. This will make the fixes we have to do manually quite long and it will take a while for me to put this together.

    I will probably have something sometime tomorrow. Right now I need some sleep. I only had 2 hours yesterday! :(

    However let's give the follow procedure a run and see if it will run properly:

    Using SDFix


    If it runs, attach the log that is requested.
     
  15. ihatebugs

    ihatebugs Private E-2

    how bout i go buy a new copy of xp tomorrow and we start from there? :) get some rest, im high maintenance! :D:D
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why haven't you just upgraded this PC in the past? ;) However do not even attempt that while infected.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds