Really !@#?% up my computer. Tried everything!

Discussion in 'Malware Help (A Specialist Will Reply)' started by aclark88, Dec 3, 2008.

  1. aclark88

    aclark88 Private First Class

    Stupidly got infected with AV 2009, and downloaded and run heaps upon heaps of programmes trying to get rid of the viruses. None seem to have worked. I've attached my FixIEDef log and a HJT log for all you experts to look at and hopefully one of you kind people can help me!

    Logfile of Trend Micro HijackThis v2.0.2
     

    Attached Files:

    Last edited by a moderator: Dec 4, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. aclark88

    aclark88 Private First Class

    Ok ran all tests and here are all logs. Comp still sluggish. Would be real thankful if you could check over logs please.
     

    Attached Files:

  4. aclark88

    aclark88 Private First Class

    And remaining 2 logs...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans took care of a lot of it...so let's just do this:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7"

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  6. aclark88

    aclark88 Private First Class

    Many thanks Tim for your help. Followed every step carefully. Here are the 2logs you requested.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....though you should run this:

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    If you are not having any other malware issues, then:

     
  8. aclark88

    aclark88 Private First Class

    Many thanks Tim.

    All seems well as we speak.

    -Adam
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     
  10. aclark88

    aclark88 Private First Class

    Ok, so today come on. And BAM! Anti Virus 2009 pop ups are back? What's up with that? Is there any chance that the virus left some traces or symptoms behind??
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That or you hit a web site again that got you re-infected.

    You know the drill now, so get me the requested logs and we will do it again. :(
     
  12. aclark88

    aclark88 Private First Class

    Ok Tim, but I've had this laptop for 2 years and only ever go on the same sites and never encounted a problem like this so i don't think it's a coinicidence that it's come back a day later? I'll do the logs and post them up for you.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Get me the logs...I may have missed something. :(

    Or something mutated, which is not unusual.
     
  14. aclark88

    aclark88 Private First Class

    Ok so here are fresh logs. I really hope this can be fixed... pop ups have sort of stopped but computer still feels slow etc...
     

    Attached Files:

  15. aclark88

    aclark88 Private First Class

    And final 2 logs...

    Good luck Tim, hope you find something!

    Thanks!
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo found these:
    c:\windows\system32\pitirima.dll
    c:\windows\system32\vonatahi.dll

    I have no idea where they came from.

    What is this:
    C:\Documents and Settings\Adam\Local Settings\Application Data\.#

    Do you or did you use a thumb drive?

    Lets see if bitdefender finds anything.
    Using BitDefender Online Scan
     
  17. aclark88

    aclark88 Private First Class

    Don't know whatthose .dll's are. I've been keeping a list of the .dll filenames that keep popping up and they aren't on it.

    Don't know what the # file is, only two little files in it. Probably safe to delete.

    Never used a thumb drive?

    Scans looking like taking 2 hours so I'll post the log when it's finished.

    Many thanks Tim.
     
  18. aclark88

    aclark88 Private First Class

    Ok so ran the scanner but there was no option for .txt. Only save as .html?? Tried to upload but tells me it's an invalid file?? Any suggestions Tim.

    Ok, just opened the .html and copied & pasted into notepad and saved as .txt. Probably not what you need but might help?
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing it found was in your restore files. So lets go ahead and toggle system restore so we clean those out.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file so I can see if anything else showed up. :)
     
  20. aclark88

    aclark88 Private First Class

    I really hope this is the last step...

    MGLOG uploaded.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And here I though we were having fun.....:)

    I don't see any problems, so lets do a little final cleaning and you can rest:

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now you can do the final step once more.


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection, but are effective as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:
     
  22. aclark88

    aclark88 Private First Class

    Fun?

    Pulling hair this side. Ok done final steps. Fingers crossed.

    Many thanks for your help Tim, I don;t know how you read those logs etc. A load of jibberish to me.

    I hope I don't have to call on you anymore. Been a pleasure.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...but do let me know it you run into any more problems. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds