Pop-ups, Rootkit, Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by monalisa, Nov 15, 2009.

  1. monalisa

    monalisa Private E-2

    Hi,

    After Symantec started detecting viruses and I started getting pop-ups, I did the scans specified and attached are the log files.

    I could NOT run combofix, I kept getting the msg (after double-clicking combofix.exe) that "Data Error - Check you settings".

    I am still getting the pop-ups.

    Can somebody please take a look at my logs and help me disinfect my laptop.
    Many Thanks in advance.

    Regards,
    Monalisa
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to get ComboFix to run and get a log. Is this the exact word for word message with spelling captialization and punctuation that you received? Did you have ALL of your protection software including firewall shutdown before trying to run it? Did you also try running in safe boot mode if necessary?
     
  3. monalisa

    monalisa Private E-2

    Earlier I tried to run combofix thrice, each time the regular blue window of combofix came up, and then something like a dialog box popped up named "Data Error" and within the box was written "Check your settings" - But I dont remember which characters were upper case or lower case.
    I didn't try running combofix in safe mode though.

    Surprisingly, when I tried now, it ran successfully. I have no idea why. Attached is the log. And since MGTools is the otherwise last step, I attached a new log of MGTools.

    I see a new sign of infection - All this while, I was getting pop-ups when I used firefox browser. Starting this evening, even when I am browsing using Google Chrome, all on a sudden some audio is playing - sometimes music sometimes dialog. On disconnecting internet, it stops playing!

    Please help .
    Many Thanks.

    Monalisa
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (file missing)
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Srijit Mukherjee\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.anandabazar.com/wfplayer/tdserver.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061023/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now you need to get a real firewall installed to properly protect your PC. Download and install PC Tools Firewall Plus <-- make sure you uncheck the options to install Google Toolbar and Threatfire free edition. Also do not install anything else from PC Tools like Spyware Doctor if asked. There's is no sense in installing excess baggage.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. monalisa

    monalisa Private E-2

    Hi,
    I truly appreciate your help with getting rid of the malwares.

    But actually this time, as I was about to implement the steps you specified, the laptop stopped booting windows. And I had to reinstall the operating system, without formatting though. For now, its running ok. But I am keeping my fingers crossed.

    Thanks anyways for helping.
    Regards,
    Monalisa
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. To make sure remnants of what we were doing are cleaned up and to get your PC properly protected, you should do the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds