reboots and redirects

Discussion in 'Malware Help (A Specialist Will Reply)' started by hornit, Oct 6, 2010.

  1. hornit

    hornit Private E-2

    I have search link redirects in both mozilla and ie. also system will reboot itself. When system boots, multiple iexplorer.exe in the processes. Ran all removal tools and still have issues. I have had to create a second user on the computer to run the tools without an immediate reboot, but will still do it eventually under the new user. System is also very sluggish. All logs are attached. Thanks for any help.

    Also could not run root repeal. Says it does not recognize partition.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    • If TDSSkiller found any problems, make sure you reboot immediately after running.
    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the TDSSkiller log
    • the MBRCheck log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. hornit

    hornit Private E-2

    Thanks for the fast reply.

    Haven't had any blue screens or auto reboots as of now. Still a lot of ie in the processes though and still running slow. I attached all logs.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC without protection?

    Not according to your logs! Did you kill them before running MGtools? Reboot your PC and do not do anything at all except run C:\MGtools\GetLogs.bat. Then open your browser to come here and attach the new C:\MGlogs.zip file.



    You need to be much more specific. Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any/every application?
    • Is it also slow in safe boot mode?
    • Also are any processes showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
    Let's also make sure that TDSSkiller really did fix the problem it found. Run TDSSkiller again and attach the new log.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 17

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\temp
    C:\Users\Brad.Michele-PC\AppData\Local\temp\4153031819369113.tmp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Now attach the new c:\combofix.txt log
     
    Last edited: Oct 8, 2010
  5. hornit

    hornit Private E-2

    OK. All ie processes are finally gone after all steps. Do still have a lot of svchost.exe though (but don't know if that is normal).

    As far as slowness...Shut down seems a little quicker, start up still slow, opening programs slow. No large CPU usage in processes. Everything so far seems fine.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to answer the below questions:
    Normal.

    Just due to what you are running. Many unnecessary Toolbars and brower helper objects for games and also a bunch on unnecessary processes.

    I have on more fix for you in which we will remove some unecessary junk from Google and Yahoo along with a few other unnecessary items. You should consider uninstalling things like below if you want more tweaks:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. hornit

    hornit Private E-2

    I thought I was running protection, but I guess it was the wrong kind. I will be downloading AVG after all is clean.

    I cannot uninstall the following. No uninstall available in uninstall programs list.

    Virtual Hottie 2
    VirtualFem
    Virtual Woman Millennium Beta .93
    Video Download Toolbar (been trying to remove this for a year now)

    Computer is definitely doing a lot better. I attached logs.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What did you think you had? There was none present.


    Would you like me to give you instructions to force them out?
     
  9. hornit

    hornit Private E-2

    I had super anti-spyware and norton, but I deleted norton about 3 weeks ago when I started having problems. I also ran malwarebytes once a week.

    I would appreciate your help with forcing out those lingering programs as well, thank you.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The free SUPERAntiSpyware does not protect you. And since you uninstalled Norton, you therefore have no protection.

    Will post below.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Oct 14, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds