Viruses, Pop ups, ReDirects Taking me Over

Discussion in 'Malware Help (A Specialist Will Reply)' started by wildflowergal, Jul 28, 2012.

  1. wildflowergal

    wildflowergal Private E-2

    Well I seem to have fallen through the cracks. I work from home and these viruses have been taking me over for the last few days. I realize you all have lives and there were so many things I did wrong at first. And I have more issues then first thought.

    Problems are 3 different trojans, zero access, redircts on google all the time, and dll file pop ups saying missing this or that & a crazy anti virus thing was popping up all over the place. I did the malware bites on that one and it went away, yikes!

    So sorry if I seen a little anxious. I have all the logs attached, I think. So anyone who can help me, it will be very much appreciated and I will donate too.

    It all started when I was on a new video to mp3 conversion site and used it. That address is ...... and it filled me up with troubles. It was about 4 or 5 days ago. The re-directs started a couple of weeks ago. I did the cclean up and defogger etc... and it's still doing it. Thank you Deborah
     

    Attached Files:

    Last edited by a moderator: Jul 28, 2012
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop and run it. Do not do anything while it runs. Attach the log when it is finished.

    Once completed, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. wildflowergal

    wildflowergal Private E-2

    Ok here's the logs. Thank you
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)


    Now:
    Fixlist.txt
    Save fixlist.txt to your flash drive.

    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * Fixlist log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. wildflowergal

    wildflowergal Private E-2

    As you can see from the pictures I took of the screen, my Fujitsu win 7, does not have the "System Recovery Options menu item” "Command Prompt" is there another way to get to it? I tried it over and over and could only get it from the desktop windows search box, but not in the Recovery environment :0(

    One other thing i wanted to say sorry for was, before I knew better, I did what you guys call bumped and then read the info on that. So I felt so bad and just waited. Because I appreciate your time and efforts a lot. So thank you. I will just keep at it till it is fixed and wait patiently :)

     

    Attached Files:

    Last edited: Jul 29, 2012
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. wildflowergal

    wildflowergal Private E-2

    Your awesome, thank you. Well I didn't do it yet, but now I have hope :0)
     
  8. wildflowergal

    wildflowergal Private E-2

    Re: Viruses, Pop ups, ReDirects OTL logs

    Hi Tim, here's the logs...
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. wildflowergal

    wildflowergal Private E-2

    Had already killed those 2 files in RogueKiller, I'm sorry that came from bumpping, which I realized was a mistake. So I attached both files for your review & hitmanpro. A lot of Zero access files came up in hitmanpro. Nothing else has been done though. Thank you for the help, Deborah :(
     

    Attached Files:

    Last edited by a moderator: Jul 30, 2012
  11. wildflowergal

    wildflowergal Private E-2

    So here's the RK log now.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what issues you are still having, if any.
     
  13. wildflowergal

    wildflowergal Private E-2

    Yes there was some stuff on the RK log and hitmanpro. I have to go to the airport and pick up my daughter, but will check when I get back. LAX about 1.5 hours away. Thank you so much. Your vary nice. I did do an AVG scan and it quarintined a trojan. What should I run when I get back? Thank you again, I would love to learn how to help people like this.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you return, Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  15. wildflowergal

    wildflowergal Private E-2

    I don't seem to be getting the Trojan pop ups anymore. However, I would like to know if there's any other junk I can get rid of and then do the steps to keep it clean. I have Super anti spyware and malware bites at this point and have always used them on a regular basis. I got the virus attack when I used a video to mp3 converter one time. My MGlogs log is attached and thank you so much for your help, once again :)

     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All looks good.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds