Redirects and Security Center Woes

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Pyrath, Jul 18, 2011.

  1. Pyrath

    Pyrath Private E-2

    It all started four days ago, when I was looking for a no-cd crack for my Civ3 install, as my dog kind of went to town on it. (Excuses excuses, I know it's illegal) Ran the new .exe and I saw the w7 busy cursor (Spinning gradient circle) for a few seconds and nothing happened. I knew bad things had just happened so I immediately went to my process list to find new unfamiliar processes. I also used the resource monitor to see what applications were sending and receiving data. I deleted two files, the names of which I cannot remember, unfortunately. (Recycling bin has long since been cleansed by this point). While looking up various .exe's online I was redirected a few times. Got a pop-up saying Windows Security Center was disabled, and it wouldn't open manually.

    At that point I had to leave, and my computer has been off for the past two days, as I was away from home.

    First thing back, I downloaded MalwareBytes and ran it. This log is attached as MWBOrigLog.txt.

    I then tried fixing WSC using the start menu, typed in 'Services', and was told it wouldn't open due to an activex error. Fixing that required me to run regedit, go to 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ '
    and delete a bad key that'd been inserted.
    Now I open the Services utility, and find that WSC has been set to 'disabled'. I set it back to 'Automatically' [boot with windows on startup], and turn it on manually. It turns off anywhere from 5s to 1m later.

    I also manually reset my router, to make sure the redirects weren't a compromised router issue.

    At that point I was out of ideas and I came here, and ran your suite. As I run w764, I did not run RootRepeal. Also, MGTools did not work on my system, and running the troubleshooting steps did not solve the problem. It would run, but never extract any .bat files to its self-made directory.

    So, attached are:
    MWBOrig.txt (The first scan)
    MWBSecondLog.txt (The scan as a part of your scanning suite)
    SASLog.txt (Scan as a part of your suite)
    ComboLog.txt (Scan as a part of your suite)

    Thank you all, loads. This is a fantastic website, and I'm just saddened that I have to post on this forum, finally. :l
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. Pyrath

    Pyrath Private E-2

    TDSSKiller Log Attached.
    OTL and Extras attached.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You ran OTM and Combofix from D:\ but I see there is a C:\ drive also. Do the problems exist on the C:\ or D:\ drive? :confused
     
  5. Pyrath

    Pyrath Private E-2

    My mistake. And forgive me, but OTM? Closest I've read/had to run is OTL.

    Also, I used audit mode during install to set D (Disk drives) as the default for appdata and user data, and have symbolic junctions from those directories in C (Solid state) to those in D.

    Anyway, attached is Combofix run on the C drive. Elaborate on OTM and I will gladly run that as well.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, sorry, I meant OTL. The Combofix log did not attach. Can you also do this on the problem drive:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  7. Pyrath

    Pyrath Private E-2

    For MGTOOLS:
    The MGTools was downloaded and run on my D (non-system) drive, which I learned while running the commands in cmd is not the drive it is trying to call. I have re-run MGTools on my C drive. It worked properly. Attached is the default MGlogs.zip

    Also attached are
    Combofix on C
    OTL on C (There was no extas.txt)
     

    Attached Files:

  8. Pyrath

    Pyrath Private E-2

    Obviously it's too soon to determine, but Windows Defender as well as Security Center are both working again, and I've been clicking on google links for five minutes without a single redirect, so I'm wanting to lean towards a fixed system.

    Any further instructions as to verifying system security and (fully and completely) Uninstalling all the programs and their various tentacles would be fantastic.

    Knock on wood, but you guys are amazing and I am so glad there are people who do what you do here. Thank you for fixing my machine.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs look promising. Everything still running normally today?

    Running from: C:\ComboFix.exe <--- Move it to your desktop so that final steps run smoothly.
     
    Last edited: Jul 20, 2011
  10. Pyrath

    Pyrath Private E-2

    Yep, everything seems to be going swimmingly. Which is fantastic. Combofix has been moved to desktop.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. Pyrath

    Pyrath Private E-2

    You, sir, get a cookie. A whole tray of warm cookies.

    And OTL doesn't require anything but a deletion of the .exe, correct?

    Thanks millions. Enjoy your cookies.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Please double-click OTL.exe to run it.
    • Click on the CleanUp! button at upper Right corner. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTL attempting to contact the internet you should allow it to do so. After the list has been download you'll be asked if you want to Begin cleanup process? Select Yes.
    • This step removes the files, folders, and shortcuts created by the tools I had you download and run.
     
  14. Pyrath

    Pyrath Private E-2

    Excellent. All done. Everything is functioning at pre-infection levels. :D

    Masterful work MajorGeeks!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad you're all sorted. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds