Some sort of bad thing.

Discussion in 'Malware Help (A Specialist Will Reply)' started by gin5ny, Aug 20, 2009.

  1. gin5ny

    gin5ny Private E-2

    Hi there. I'm not a techy person at all, but I was able to follow all the instructions in the "Read and run my first" thread. The logs are attached.

    On Friday, I started getting all sorts of bells and alarms from Avast saying that a virus had been detected. It also told me to "not worry, as Avast had stopped it from entering the system". Ran Avast, and quarantined a bunch of files so I thought it was done. Logged on to Facebook, and ended up spamming my friend list several times over with "LOL video" messages and links.

    Ran avast again, and it didn't find anything. But in the meantime, I've noticed that whenever I search (in either IE or Firefox) Google and click on a link in the results, I'm redirected to random search pages. I can hit the 'back' button and get to the original page, but there's obviously something still a bit hinky in my system.

    Any and all help would be much appreciated!!
    Ginny
     

    Attached Files:

  2. gin5ny

    gin5ny Private E-2

    here's the log for MGTools

    Thanks again!!

    Ginny
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not attach it. We need this log to continue. I'm only seeing one possible issue thus far in your ComboFix log.
     
  4. gin5ny

    gin5ny Private E-2

    Hi there...thanks for your reply! I noticed the log missing a while after I posted the initial message, but didn't want to add it and bump myself down the line. Here it is now.

    Ginny
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you did not have the current updates for Malwarebytes installed. If you had them, it most likely would have fixed your problem. If the malware was blocking the updates, you could have used the manual download link we provided. Try the below.

    First please remove MGtools.exe from your Desktop. That is not where we asked you to save it.
    C:\Documents and Settings\Ginny\Desktop\MGtools.exe


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) SE Runtime Environment 6

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • the new Malwarebytes log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. gin5ny

    gin5ny Private E-2

    Hi! Sorry for the delay in my reply, we were away on vacation. Thank you so much for all of your help, I've really learned a lot from being a part of this site!!

    Ok. I ran everything suggested, and am posting the logs. The redirect appears to be cleared up (yea!!). Are you able to tell whether any of the malware was grabbing passwords or personal info (ie) banking?

    Thanks again for all your help. Please let me know if there is anything else that I should do.

    Ginny
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    I don't have any information that indicates that this infection is an information stealer; however that does not mean that it is not. If you are concerned about security, then use another PC and change all passwords.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. gin5ny

    gin5ny Private E-2

    Hi again...we're having another problem, and I'm not sure whether I'm supposed to start another thread, or continue with this one.

    In any case, this morning I was trying to do some cleanup of old programs, but was locked out of the add/remove programs at the control panel. I was also not able to access the security centre, or the user accounts. The message said "Error loading C:\Windows\system32\shell32.dll Access is denied"

    I ran the read and run me once again, the logs are attached. Combofix stalled at the screen where it says it will take about 10 minutes to complete the scan. I tried to run it several times and it always stalled at the same spot.

    Root Repeal did not appear to run the same way as I remembered, or as it was described in the tutorial. The Drivers tab was empty, and when I pressed "scan" this was the log that was created. Currently in the RootRepeal folder I have a "blurry magnifying glass" icon that is named "rootrepeal" and is an Application file, not an .exe None of this is familiar to my remembering of the last time we went through the cleaning process.

    Any advice this time?

    Thanks so much
    Ginny
     

    Attached Files:

  9. gin5ny

    gin5ny Private E-2

    sigh.

    I know that this is going to bump me way down the list, but I thought I would take another crack at those programs that didn't work the first time (combofix and Root repeal) once I had some time and distance from my initial frustrations.

    Re-downloaded, and ran Combofix (log attached) which worked this time.

    Re-downloaded and reread the instructions for Root Repeal, and followed them correctly this time. Sorry about that. The actual log is posted.

    As an update, I am still locked out of every function in the Control Panel, although I was able to access them as the Administrator in Safe Mode.

    Thanks again for all your help, I truly appreciate it!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't appear to be having malware problems. Your logs are all clean. I suggest that you try disabling the Comodo Firewall and see what happens. Otherwise, post in the Software Forum.

    Now repeat my final cleanup instructions from msg #7.
     
  11. gin5ny

    gin5ny Private E-2

    hmm. Such a simple fix, it's a bit embarrassing that I didn't try that out myself. Would downloading a different firewall make a difference or is this standard behaviour with any firewall?

    Thanks again for all your help. It's nice to know that I'm only being paranoid rather than reinfected!!

    Ginny
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many people having problems dealing with the use of firewalls and knowing what to allow and what not to allow. And some firewalls do a little more of the work for you than others and take some of the decision making process out of your hands. This can be good and bad since you will not always know what they have done. At anyrate you have to get smarter about knowing what you have allowed and what you have blocked and when you run into issues where something is not working properly, make sure that you have not some how blocked it.

    All that being said, you could try another fire wall to see if it is any easier for you. Both Comodo and PC Tools Firewall get high grades. Make sure you don't install any of the other baggage like ThreatFire or Spyware Doctor if you decide to try PC Tools Firewall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds