server2.mediajmp help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sioko Ti, May 27, 2010.

  1. Sioko Ti

    Sioko Ti Private E-2

    I run a pretty clean machine (as far as malware goes) most of the time and when things go wrong I can usually fix it..... but this is sticky and I need expert help!

    3days ago I was checking my yahoo mail and when I was done I signed out and perused the headlines and I got this pop-up tab and pop up window that looked like a news story for work-at-home job. I was suspicious and clicked on NOTHING. I googled the supposed news station and of course no such station existed, so I esc out of the pop up window (just repeated it's headline on it) and x'ed the tab. shortly after I got another popup tab and window with a "you win!" scam on it. I looked at the address bar and it was "server2.mediajmp". A little while later while googling something else, another popup tab and window with a fake work-at-home news story popped up even before I could open any links and the address was "server2.mediajmp" again.

    So I updated and ran just about every scan in existence;
    AVG antivirus
    Superantispyware
    ad-aware
    spybot search and destroy
    hijackthis
    malwarebytes
    windows defender (would not update)
    ran CCleaner cleanup and register cleaner

    ALL came up clean. I tried surfing again, got another pop up and came to majorgeeks and ran the "read and run me" and the Windows XP cleaning procedure. Rootrepeal hung for 2days so I stopped it, but it came up with this;
    C:/hiberfil.sys STATUS: locked to the windows API!

    and I can't find MGTools anywhere (I just KNOW I downloaded it to C: but it's not there!), but after I turned my AVG back on it found it and all this;

    "C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP722\A0047161.exe";"Trojan horse Dropper.VB.DCI";"Moved to Virus Vault"
    "C:\System Volume Information\_restore{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP722\A0046992.SYS";"Virus identified Win32/Patched.DY";"Moved to Virus Vault"
    "C:\MGtools.exe";"Trojan horse Dropper.VB.DCI";"Moved to Virus Vault"
    "C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\fsyz1uz6.default\Cache\30036096d01";"Trojan horse Dropper.VB.DCI";"Moved to Virus Vault"

    I wasn't going to touch any of it till I got the go ahead from you guys, but I forgot I set AVG to do it automatically :( Sorry.

    Here are the logs I was able to get.... it's been a hectic and harried 3 days, I'm sorry if I've missed anything. Thanks guys, you rock! :guitar
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, Sioko Ti

    You may have to temporarily un-install AVG to prevent it from interferring with the download and running of MGTools.exe.

    Also please try to run this: GMER - running with a random name and attach the log from GMER.

    dr.m
     
  3. Sioko Ti

    Sioko Ti Private E-2

    AVG uninstalled successively. When I tried to download MGTools, I get a "file not available" message from firefox. Is there another location to download it from?

    Here is the log from Gmer
    Thanks for your help!
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Sioko Ti.

    No, that's the only location for the MGTools.exe download. Please try again - there have been occasional server "hiccups". Also try using Internet Explorer browser.

    dr.m
     
  5. Sioko Ti

    Sioko Ti Private E-2

    Got same error message in firefox. It downloaded fine in IE. Ran fine, no probs.
    Here's the log. thx. :)
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Sioko Ti

    * You have SpyBot Search & Destroy's TeaTimer function running, which can interfer with cleaning your machine. Please see the below link to disable it:
    How to disable Spybot's TeaTimer

    Let's cleanup after your AVG uninstall - please download the AVG Remover(32bit) from the below link > run it and re-boot > run it again.

    AVG Remover

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 3:
    Now install the latest Sun Java Runtime Environment

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  7. Sioko Ti

    Sioko Ti Private E-2

    I had no problems at all. All went smoothly. Thank you so much!

    Questions:
    Is there a reason you haven't updated XP to Service Pack 3?
    Do you recognize these addresses? 68.94.156.1,151.164.8.20


    I didn't know SP3 was out, I will update right away.
    Whois says those IP's belong to my ISP.

    I repeated my actions the day the problem showed up and I have not encountered the same problems. Thank you! I think the XP Cleaning procedure and your advice and patience got rid of the problem! YOU ARE AWESOME! :dood:guitar:boxing

    I've since reinstalled AVG 9 free and all is well :)
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool

    You're quite welcome, Sioko Ti.

    It is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    Last edited: May 30, 2010
  9. Sioko Ti

    Sioko Ti Private E-2

    Done and done! Thanx again! :) :-D:wave
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds