Unable to visit avg.com, possible malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sugarsugar, Jun 27, 2011.

  1. sugarsugar

    sugarsugar Private E-2

    Hi!
    It seems I have may caught something. It started with a hidden process running called ezsidmv.dat which I killed with Winpatrol's "delete on reboot".
    Now I am unable to update AVG and access avg.com. I have now uninstalled AVG as combofix cannot run with AVG installed.
    My logs are attached below (I am unable to run RootRepeal as I'm running 64bit win7)
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Relates to Skype! You should be very careful about deleting files that you know nothing about. Anything else you removed?

    You have many remnants of Comodo (it is not actually installed) and avg is not currently even installed either.
    Correct? If so we can proceed with the fix that I have ready for you. Perhaps it is the comodo remnants, some of which are still running, which is hindering avg.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    c:\users\abestco\AppData\Roaming\GetValue.vbs
    c:\users\abestco\AppData\Roaming\SetValue.bat
    c:\program files (x86)\js3250.dll
    c:\windows\system32\DRIVERS\cmdguard.sys
    c:\windows\system32\DRIVERS\cmdhlp.sys
    SecCenter::
    {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
    {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
    Folder::
    c:\program files\COMODO
    c:\programdata\Comodo
    C:\Users\abestco\Local Settings\TEMP\Comodo
    Driver::
    cmdHlp
    cmdGuard
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "COMODO Internet Security"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. sugarsugar

    sugarsugar Private E-2

    Hi!

    I also forgot to mention that my computer keeps connecting to
    216.156.147.32.ptr.us.xo.net and/or 216.156.149.48.ptr.us.xo.net via svchost.exe and aim.exe.

    Comodo is actually installed and runs on startup, and yes AVG is currently uninstalled.

    I won't proceed with the instructions you gave until you give the ok, since I do have Comodo installed.
    Thanks for the help in advance!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    They are installed now? You did not uninstall them in order to run any of the scans?

    Strange... the reason I asked is because I am not seeing either in your add/remove programs listing at the end of the newfiles.log or in the GetunKeys.log. :confused I think they both might be broken. Do NOT follow Tim's post #3.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    c:\users\abestco\AppData\Roaming\GetValue.vbs
    c:\users\abestco\AppData\Roaming\SetValue.bat
    c:\program files (x86)\js3250.dll
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Jun 28, 2011
  6. sugarsugar

    sugarsugar Private E-2

    Hi!

    I'm not sure if I did this correctly but attached below are my logs. Only Comodo is currently installed, because when I ran combofix, it asked me to uninstall AVG.

    I am still unable to access sites such as avg.com/sophos.com/f-secure.com with BOTH firefox and chrome.
    And also, when I try to access the above sites, I get connections such as these:
    Code:
    firefox.exe	2976	TCP	fantasy	49464	216.156.149.122.ptr.us.xo.net	http	SYN_SENT										
    firefox.exe	2976	TCP	fantasy	49465	216.156.149.89.ptr.us.xo.net	http	SYN_SENT
    
    However, I am able to ping avg.com through command prompt.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try again.
     
  8. sugarsugar

    sugarsugar Private E-2

    I ran Combofix again, making sure to double check my CFscript.txt file, but it seems similar to last time.

    While running C:\MGtools\GetLogs.bat, Firefox popped up and crashed. It took a few tries for Firefox to actually get up and running.

    Also attached is a screenshot of something Comodo caught (This has only been happening in the past 2 days).
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes and this is legit, it's something you should allow.

    Tencent QQ <--- Uninstall this.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    c:\users\abestco\AppData\Roaming\GetValue.vbs
    c:\users\abestco\AppData\Roaming\SetValue.bat
    c:\program files (x86)\js3250.dll
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  10. sugarsugar

    sugarsugar Private E-2

    OTM log is below:
    Code:
    ========== FILES ==========
    c:\users\abestco\AppData\Roaming\GetValue.vbs moved successfully.
    c:\users\abestco\AppData\Roaming\SetValue.bat moved successfully.
    LoadLibrary failed for c:\program files (x86)\js3250.dll
    c:\program files (x86)\js3250.dll moved successfully.
    ========== COMMANDS ==========
     
    OTM by OldTimer - Version 3.1.18.0 log created on 07022011_024825
    When I ran OTM, I had an error which I have screenshot and attached below.
    Also, now I am unable to run Firefox, as it says "The program can't start because js3250.dll is missing from your computer. Try reinstalling the program to fix this problem."
    I am still unable to connect to sites like avg.com/sophos.com (it doesn't seem to be internet problems as I am able to visit avg.com on another computer).
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The firefox file was mistakenly included because of the location you have it in. Why was it not in its own Mozilla Firefox folder and instead just inside the Program Files folder? It should not have been here.

    To restore the file:

    Navigate to C:\OTM\Moved Files folder to dequarantine it. Find the js3250.dll open up the other randomly named folder, there should be a C:\Program Files folder. Locate the file we need to restore and you can right click and COPY then navigate back to the location that you had it in, which is: (HERE!!! C:\Program Files (x86)\js3250.dll because this is how you have things all out of order) The file should be intact again. Reboot, now see if Firefox works.

    Sorry for my mistake but it was the location the file was in which put me off kilter.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds