Ran Read me first, still having problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kirk48, Feb 27, 2011.

  1. kirk48

    kirk48 Corporal

    Okay, I was able to run all of the programs except Combofix. The computer crashed when I tried to run it. I've attached logs for the other four programs.
    I'm still getting redirectors on the internet. I'd be grateful for any input.

    Thanks

    Steve
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. kirk48

    kirk48 Corporal

    Okay, ran the rootkit remover. Log attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  5. kirk48

    kirk48 Corporal

    Okay here is the MBR log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your MBR is okay. TDSSkiller found and attempted to fix a couple of problems. How are things working right now?
     
  7. kirk48

    kirk48 Corporal

    Things are much improved. No longer running up against redirectors and running faster overall.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's good. I have some more for you to do to finish this off. While I finish creating the fix, uninstall the below which is likely the source of some of your problems. It installed the Yantoo Layers junk too.

    Drop Down Deals 1.10.01

    If you don't see Drop Down Deals in Add/Remove programs, look for 889DF117-14D1-44EE-9F31-C5FB5D47F68B
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here's the next fix.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: C:\Windows\system32\rjdfg9dxls.dll - {B9B220C2-A500-59BD-F210-02B53A2C8953} - C:\Windows\system32\rjdfg9dxls.dll (file missing)
    O4 - HKLM\..\Run: [DriverUpdater] F:\New Folder\DriverUpdater.exe tray
    O22 - SharedTaskScheduler: dgushef87w3ruiijfgsdigdgs - {B9B220C2-A500-59BD-F210-02B53A2C8953} - C:\Windows\system32\rjdfg9dxls.dll (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Users\SmG\AppData\Local\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. kirk48

    kirk48 Corporal

    Alright, I ran all the stuff and deleted as instructed. I feel like overall I'm better off, but when I run a search for major geeks through the Yahoo search it starts off well then I get sent to another site altogether. If I run the search through the Norton search it comes up clean. I've attached the requested logs.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay a few items did not get fixed also I see that you re-enabled UAC. You must keep UAC disable until we are finished. So disable it now and then reboot so that it will take affect before continuing with the below.

    Now let's try again and this time we will see if we can get ComboFix to work. First delete the ComboFix.exe file that you already have and then download and save (just ave it right now. Do not run it. We will run it below with a script. ) this one to your Desktop: combofix.exe

    Now make sure that you shutdown all of your Symantec protection before continuing or it could get in the way.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {B9B220C2-A500-59BD-F210-02B53A2C8953} - (no file)
    O4 - HKLM\..\Run: [DriverUpdater] F:\New Folder\DriverUpdater.exe tray
    O22 - SharedTaskScheduler: dgushef87w3ruiijfgsdigdgs - {B9B220C2-A500-59BD-F210-02B53A2C8953} - (no file)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. kirk48

    kirk48 Corporal

    Well alrighty then. First off sorry about turning UAC back on prematurely, Windows was hollering its *** off about it so I weakened.I turned it off,rebooted and the HJT fliles were now gone. I ran the other stuff and attached the logs. I was able to get to the MG support site without being sent off on a wild goose chase this time, big improvement there.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes things work much better when UAC is disabled. ;)

    Your MGlogs.zip file is incomplete. Make sure UAC is still disabled and Norton/Symantec is disabled ( your ComboFix log showed you forgot to disable the firewall and the antispyware component ) and then do the below to get a new log but it is looking pretty good now based on what ComboFix removed.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
     
  14. kirk48

    kirk48 Corporal

    I turned off Norton Antivirus and firewall using he method I found on Bleeping Computer. Hopefully I got it this time. When Getlogs.bat gets to the process DLL portion I get a popup window telling me the app generated and exception. I hit OK and Getlogs.bat finished. I think I might have hit cancel the last time. That might explain why it didn't run all the way.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it still did not run all the way properly. The issue with processDLL is not a problem as it can just be aborted when the .NET Framework application is not present or crashes. Try the below and tell me what happens.


    If these seem to run, then attach the new MGlogs.zip file.
     
  16. kirk48

    kirk48 Corporal

    All of the processes ran with no errors from the command prompt and generated logs. I ran it again from he logs batch file and it hung at the same dll error. I hit ok to terminate and it seemed to complete.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not what I wanted you to do. The individual files created logs when they ran and put them into the MGlogs.zip file automatically. Just run the individual commands and then attach the MGlogs.zip file. Do not run GetLogs.bat.
     
  18. kirk48

    kirk48 Corporal

    Slow learner, but I'm getting there. (I think I think too much!)
     
  19. kirk48

    kirk48 Corporal

    I attached the file but I don' see it there. I tried again and I got a message saying I had already sent it on this thread and blanks me out. ???
     
  20. kirk48

    kirk48 Corporal

    Still can't get the uploader to accept Mglogs.zip. I've sent the individual txt docs for three of the programs. I didn't get a log for nwktst, but it ran without errors.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your logs are clean now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. kirk48

    kirk48 Corporal

    Okay, thanks so much for taking the time to get this mess straightened out. And a special thanks for being patient when I know you felt otherwise. I learn something each time, although it might be hard to tell.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you are learning something from this. :)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds