Probably infected with something, requesting help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Angelus21, Jan 4, 2009.

  1. Angelus21

    Angelus21 Private E-2

    Hello all,

    I was recently having problems trying to play some mp3 files with Winamp. It would give me a "Bad DirectSound Driver" error and no audio. I figured it was merely my drivers so I uninstalled and then reinstalled them. The problem seemed to go away and I was listening well and all.

    I played some World of Warcraft and then decided to listen to some music again. Well I got the same error again, I figured I'll just uninstall and then reinstall the next day since it was getting late.

    I decided to log onto AOL to check my email before shutting the computer off. Well as soon as I logged on Internet Explorer launched and started creating multiple tabs opening up sites. I knew I was infected with something at this point.

    I have since gone through the RUN & READ ME FIRST steps and am posting the required logs for examination. All of these behaviors really only started yesterday 1/3/09. I would like to thank you in advance for taking your personal time to help me with my problem.
     

    Attached Files:

  2. Angelus21

    Angelus21 Private E-2

    MGlogs.zip attached below.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    You are also out of date with the version and definitions for Malwarebytes, run it and update to the current database and run a new scan with it too. Attach the new log.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 10


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.


    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    • and don't forget the new logs from SUPERAntiSpyware and Malwarebytes
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds