Really bad virus! Possible rootkit.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ModeGone, Jan 12, 2014.

  1. ModeGone

    ModeGone Private E-2

    Hey guys, looks like I have a really bad virus. I don't know much about them or whatever so I could really use some help. So for here are the following things this virus or virus's is/are doing:
    1. Playing constant audio ads in the background. (Which isn't really a problem since I can make the volume of it to 0, I don't notice it's existence any more really)
    2. Restarting my computer by closing vital services such as DCOM and Plug and Play. (This happens especially when I run malwarebytes) every now and then. The length of the intervals for this is always random. Sometimes it'll be eight hours sometimes my computer won't be running for 20 minutes till I get a message telling me my computer is about to restart.
    3. Taking 100% of my CPU. The program in the taskmanager that is eating all of my CPU and a huge chunk of my memory is called the svchost.exe. I understand that this is an important thing to be running but I am also aware that some rootkits attach themselves on these kinds of things as it were.
    Other than that I can't think of anything else.
    I don't remember what I could've possibly done to get this virus. I remember I was playing League of Legends with my girlfriend when I heard the ads start playing really loudly. The last thing I remember downloading and installing is LoLrecorder, a program that records your LoL games.
    Here are some logs. I understand that I probably shouldn't have ran combofix as it's not recommended here, but I did because of advice from a friend.
    Also, I only found out when I was reading your forums that running the same scan more than once is probably a horrible idea. Some of these scans I ran once since I got this virus, some of them more than once. None of them more than twice besides Malwarebytes which I ran a lot :\
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. Did you forget to run MGTools? I need to see the MGlogs.zip from running that too, please. Thanks. :)
     
  3. ModeGone

    ModeGone Private E-2

    I should also mention I ran most of these in safemode besides one that wouldn't let me get a log unless I was connected to the internet as it is kind of impossible for me to run scans without safemode at the moment.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete all of the Potential Unwanted Programs.


    Uninstall the below softwares:

    • Update Manager for SweetPacks 1.1
    • SweetIM for Messenger 3.7
    • Trustworthy Toolbar
    • Messenger Plus! Community Smartbar


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\dosearches.xml
    C:\Windows\SysNative\iezaplo.yvb
    C:\Windows\SysNative\qsqbue.qpa
    C:\Windows\SysNative\sgzsn.aek
    C:\Windows\SysNative\ymfpr.fyw
    C:\Windows\SysNative\ypixz.kxs
    C:\Users\Krayak\AppData\Roaming\SearchProtect
    
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Disabled (Startup Manager)]
    "SearchProtect"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "SweetIM"=-
    "Sweetpacks Communicator"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "SweetIM"=-
    "Sweetpacks Communicator"=-
    "SearchProtectAll"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{99C85C14-E620-4CCB-9BD9-0C008E7FF1DE}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.




    Now (in NORMAL mode if at all possible please...) run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. ModeGone

    ModeGone Private E-2

    So far:
    No more audio ads! CPU usage back to normal! Weehaw!
    I don't even know where to begin to thank you, just understand that I am extremely grateful to you. You had no reason to do this other than to help out a fellow creature and I will never forget this! You are my savoir. Thank you!!!!!!!!!!!!
    Here are the logs in case there is something else I need to do. Is there anything you'd personally recommend me to do to avoid ever getting anything like this again?
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome for the help. :)

    Messenger Plus! Community Smartbar <<< This is still installed. Can you remove it please? If you have difficulties, just yell.


    Few of those files didn't go, so let's try another approach.


    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. ModeGone

    ModeGone Private E-2

    I get this when I try to uninstall Messenger Plus!
    gyazo.com/7de531652565d3181de0b47e2df72943
    Here is the log you requested again.
     

    Attached Files:

    Last edited by a moderator: Jan 15, 2014
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds