Still infected. May I please get a log review

Discussion in 'Malware Help (A Specialist Will Reply)' started by MikePike2580, Nov 5, 2008.

  1. MikePike2580

    MikePike2580 Private E-2

    My girlsfriends computer. It has been getting a trojan horse clicker virus warning. Basically I get this 663Q2l31.exe program that runs which then opens up internet explorer through a system process (not user process, user being the administrator). System resources gets sucked up and current Internet eplorer session gets shut down. I have downloaded and runs programs to the best of my ability but the program is still there.

    Any help is greatly appreciated. Thanks.

    Mike
     

    Attached Files:

  2. MikePike2580

    MikePike2580 Private E-2

    The rest of the logs
     

    Attached Files:

  3. MikePike2580

    MikePike2580 Private E-2

    sorry went over the 10 minutes to edit mark.


    So a little more about this. Ive been keeping an eye on the running processes via task manager. Every 15-20 minutes or so this 663Q2l31.exe program starts up which then opens up internet explorer as a system process meaning I can not see any open internet explorer pages. Got it about 1 week ago. Not sure if I followed the read and run directions word for word as I have been having trouble finding the time to try and resolve this. I did have AVG free version installed which notified me about a trojan horse clicker infection and some browser helper infections but it was unable to resolve the issue. I removed AVG and spent the money on mcafee which I am now running which cant seem to find it. The only program that was able to find trojans was MBAM. It "fixed" the files but obviously the computer has become infected again. There is also a variation of 663Q2l31.exe which is 663Q2l31.exe.a_a


    also I ran combofix in safe mode





    Thanks again
     
    Last edited: Nov 5, 2008
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to let you know we are currently reviwing your logs and will be back to you with a plan of action as soon as possible. Thanks for your patience.
    Did you run Combofix in safemode because you had problems running it in normal mode?

    kes
     
    Last edited: Nov 5, 2008
  5. MikePike2580

    MikePike2580 Private E-2

    thanks for the reply.

    I ran it in safe mode because I had heard mixed reviews on the program. Mostly that it had been causing some systmes to crash. My computer has been running really slow lately. PF usage at 1.00 GB or more. Starts at 370 MB then slowly climbs up to 1.00-1.4 GB within an hour of start up. I was worried it might crash my system. Also I ran it before about 3 months ago when I was infected with virtumundo. It fixed the issue but after running combo fix I got the "blue screen of death" when trying to restart. I then rebooted in safe mode then rebooted once more and everything seemed fine. So no combofix wasnt giving me any problems this time, just a precaution I took.

    thanks
     
  6. MikePike2580

    MikePike2580 Private E-2

    sorry for the unintentional bump. I forgot to add this last night. When running combo fix, in between running its stages and preparing the log it needed to reboot my system. I chose to reboot back into safe mode. After rebooting combofix came back up stating 'preparing log do not start any other programs' (something like that) but do to rebooting mcafee loaded and a few other essential programs/services loaded during this combofix process. Obviously it finished and produced a log so I dont know how much this could have interfered with combofix.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please disable the Guest account through User Accounts if this hasn't already been done so.

    2) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    3) Please go to Add and Remove programs and uninstall the following software:
    • Viewpoint Media Player

    4) Please navigate to the following...and delete the AVG directory

    C:\Documents and Settings\All Users\Application Data\AVG8
    C:\Program Files\AVG

    5) Please disable Spybot's TeaTimer. This can be done two ways.
    First:

    • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
    • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
    • If you have Version 1.4, Click on Exit Spybot S&D Resident
    or Second, For Either Version :

    • Open Spybot S&D
    • Click Mode, choose Advanced Mode
    • Go To the bottom of the Vertical Panel on the Left, Click Tools
    • then, also in left panel, click Resident shows a red/white shield.
    • If your firewall raises a question, say OK
    • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
    • OK any prompts.
    • Use File, Exit to terminate Spybot

    6) Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:

    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    7) Now Run Ccleaner!

    8) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger

    *Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now*
     
  8. MikePike2580

    MikePike2580 Private E-2

    thanks for the reply. I am at work until tomorrow morning so I wont be able to get at it until then. One question,

    How do I go about disabling the guest account? If I do so will this mess with my internet connection?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi, no problem, I will be waiting for you when you are ready to continue :)
    With regards to the Guest account..you can simply go to control panel > user accounts... and disable it that way. It won't have any negative affect on your internet connection, no.
     
  10. MikePike2580

    MikePike2580 Private E-2

    Ok. Followed those instructions. No major issues encountered. Only things were that the guest account in user accounts was already turned off and I think the avenger program must have been updated. The instructions you gave me did not match up with the program. Also, avenger was unable to find c:windows\system32\WOv1qi3S.exe so it did not delete.

    So far so good on the computer but I will keep an eye on task manager to see if any strange programs begin to run.


    thanks
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    My apologies for the avenger instructions :) But all is well, your logs are clean!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:


    Kes13!
     
  12. MikePike2580

    MikePike2580 Private E-2

    Awesome!


    Thanks. If you are ever in the Boston area I definitely owe you a bunch of beers.

    Again,

    Thanks so much
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't tempt me ...LOL

    You're very welcome! safe surfing :wave
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds