Uncle's computers had malware, cleaned some now internet cuts out

Discussion in 'Malware Help (A Specialist Will Reply)' started by shockthetoast, Nov 18, 2012.

  1. shockthetoast

    shockthetoast Private E-2

    I'm visiting my aunt and uncle a few states away, and they were having some trouble with their admittedly ancient computer being slow, and internet being finicky. After running into some popups and redirects, i ended up running Malware Bytes, which found and removed a number of things. Unfortunately, now the internet seems broken. I can ping various sites just fine, but can't get to them through a browser. It seems to be a winsock issue. XP's network diagnostics indicates it is the winsock catalog being corrupted. I've run various tools and netsh commands to reserved that, and usually it works for maybe an hour before breaking again. I'm concerned there may still be something on there causing issues, but it could just be a result of the things I've already cleaned.

    System: old Dell system running XP Home SP3. It was running SUPERAntiSpyware Pro (which was detecting nothing but cookies), but no antivirus. It had remnants of various versions of AVG, none of which were functional but somehow were still making XP's security center think it had antivirus. (I removed those old remnants with AVG's own cleaner tool.)

    I've uploaded logs from MGtools, MalwareBytes, RogueKiller, and TDDSKiller. I also ran Hitman but it found nothing.
     

    Attached Files:

    Last edited: Nov 18, 2012
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This PC is old and has too little memory to effectively run Windows XP SP3 and when you add the use of too many protection tools to this limited resources..... well the PC will just be slower. It only has 512 MB total memory and only 143 MB free. We recommend at least 4 times this amount of memory. It should have at least 2GB if the mother board allows it. If you don't upgrade the memory, it will remain slow.

    Also is the Blue Coat K9 Web Protection required? Do young children use the PC? I only see one user account so I would not think so.

    Also you have SUPERAntiSpyware and WinPatrol on top of Microsoft Security Essentials.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} (SOE Web Installer) - http://launch.soe.com/plugin/web/SOEWebInstaller.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
    O20 - AppInit_DLLs: pbiaiy.dll, enrmbg.dll, exbzjz.dll, ydgiak.dll, dawemd.dll, oetuzu.dll, iuscjm.dll
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O20 - Winlogon Notify: iifebBrS - iifebBrS.dll (file missing)

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\WINDOWS\system32\WinCtrl32.dll
    C:\$AVG
    C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
    
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-
    [HKEY_USERS\S-1-5-21-2860856627-1763179434-710120470-1006\Software\Microsoft\Windows\CurrentVersion\run]
    "MSMSGS"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. shockthetoast

    shockthetoast Private E-2

    Thanks for the help! Sorry for the delay. Busy holiday time and all that - plus the Thanksgiving/Black Friday sales effectively killed the internet here for a couple days.

    The internet seems to be working good now (actually, better than before). I think K9 was the culprit after all. It came free from their previous ISP, and they had no clue what the password was set to... had to do some digging online to find a way to get rid of it. It slowed down the internet, but didn't break it until I removed some of the infections.

    I added Microsoft Security Essentials because they already had SUPERAntiSpyware installed (and payed for), but it isn't an antivirus. SAS claims it won't cause conflicts... I use WinPatrol mainly for the interface for managing autorun programs, and the hidden files list. It's not set to auto start, just run on demand. That and a few other programs (that I was just using to check some things) I've started to remove.

    Even if it wasn't the source of the internet issues, I'm very thankful you helped clean up the rest of that junk. Your help has been very appreciated!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds