Some advice please

Discussion in 'Malware Help (A Specialist Will Reply)' started by ragexzero, Aug 12, 2009.

  1. ragexzero

    ragexzero Private E-2

    I got badly infected with malware yesterday, and Ive been trying to run the "Read and Run me first" with not much luck.

    Once I finish the scans, and the computer is apparently clean, I seem to get re-infected as soon as I reconnect to the internet. As of now, my computer is not online anymore for this reason and Im posting this message from a different PC.

    I dont know how to go about posting my logs here cause the last time I reconnected to the internet, and did a scan, MBAM showed 29 infections! as opposed to just 4 from the previous scan. It seems that the more time I stay connected, I get infected worse and worse. Im not even surfing the web or doing any downloading either. Just from a couple seconds of online connection, this happens.

    So the problem is that the scan logs are on the infected PC and I was thinking about copying the logs to a flash drive and posting them with this PC but Im afraid that will infect this computer as well.

    What should I do?

    Edit: I updated all anti-malware programs before I did the scans, yesterday. And I also thought I shoud note that whenever I re-plug my PC to the internet and reboot, I get an error titled "install.exe" that says "Windows doesnt have access to the device, path or file. You may not have permissions to access this element" (or along those lines, since I have to translate it from Spanish).
     
    Last edited: Aug 12, 2009
  2. ragexzero

    ragexzero Private E-2

    Urgent help needed

    Ok, I decided to get back online and run the "Read & Run Me" again.

    -SAS came up clean.

    -MBAM couldnt seem to delete a "wiaserva.log" file, but other than that clean.

    -Root Repeal did the scan but then when the program says "Initializing" my computer restarts on its own and I dont get a log. It happens every time I try it.

    -ComboFix runs fine and so does MGTools.

    BUT, it seems tho that when I turn off my firewall and AV program to run ComboFix, I immediately get re-infected. Its like Im under constant attack and the firewall is the only thing preventing it. Cuz after I ran ComboFix and MGTools, I re-ran MBAM just to make sure, and lo and behold, it came up with 18 new infections that werent there in the previous scan just minutes ago.

    Logs are attached and I hope you can all help me out. (Im attaching 2 MBAM logs, one from before turning off the firewall to run ComboFix, and the other one after. I hope thats ok).
     

    Attached Files:

  3. ragexzero

    ragexzero Private E-2

    Second post so I can post SAS log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Uninstall the below software:
    Java(TM) 6 Update 13
    Viewpoint Media Player <-- should have been uninstalled in step 5 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
    O3 - Toolbar: QT Tab Standard Buttons - {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - mscoree.dll (file missing)
    O4 - Startup: ikowin32.exe

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the new SAS log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 16, 2009
  5. ragexzero

    ragexzero Private E-2

    First, thanks for your response.

    I followed your steps successfully. But after I did the ComboFix scan and it rebooted the computer, my firewall restarted too and it went crazy, giving me all kinds of warnings and prompts about "this is trying to run everytime the computer starts", "this process is trying to access the internet", blah blah. I didnt know what to do, so I denied all of them. I dunno if I messed up ComboFix by doing that. But it felt fishy so I denied all.

    And just for the hell of it, after all your steps were done, I did a quick scan with MBAM. And I had 18 infections. Im attaching that log too.

    It seems that whenever I turn off the firewall now, I get infected again in a flash, without even browsing online or anything. It shouldnt be like that, should it?

    Im not getting the error with the "install.exe" title on reboot anymore.

    Also I should note that I couldnt find this item on the HJT list:

    O4 - Startup: ikowin32.exe
     

    Attached Files:

  6. ragexzero

    ragexzero Private E-2

    Attaching MBAM log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if they really were deleted by doing the below.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    No it should not but if a malware type site or hacker has discovered your PC, turning off the firewall can give them access. So from now on if you need to turn off your firwall, unplug your cable to the internet first.
     
  8. ragexzero

    ragexzero Private E-2

    Followed your steps successfully again and it seems promising that Avenger didnt find any of the files. Here are my logs.

    My computer seems to be running fine, so I got no complaints. The only thing is that Im now scared that my firewall wont start for some reason and Ill get re-infected in a flash. But yeah, I dont think I need to turn off the firewall for anything other than installing new software and sometimes not even for that. So Ill follow your directions and unplug the internet first if it comes to that.

    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds