XP Internet Security Virus (at a minimum)

Discussion in 'Malware Help (A Specialist Will Reply)' started by JDWCowboy, Feb 15, 2010.

  1. JDWCowboy

    JDWCowboy Private E-2

    Hello, I'm JDWCowboy and I'm having trouble with my computer. I believe there are several types of malware at work here. One is XP Internet Security. It doesn't appear to be the 2010 variety (based on the screenprints I have seen online). This shows on popups, popups on lower right icons, and intercepts whenever the internet is launched. These are present on my sons account, but not on any of the others. On the main account, there are pop-up boxes advertising all kinds of junk.

    I have Norton and regularly use Ad-aware and both of these have been run, but did not seem to find these programs. I don't know if they are new or if they have modified the programs to skip them. I could not even launch Ad-aware from my sons account. Would I need to run it from each account or would running it from one account catch issues in all accounts?

    I have followed the read and run me first, but much of this did not run.

    Step 2: remove redundant packages

    I use Norton Internet Security and could not tell if I have multiples and I believe that this is also our firewall. Can you confirm this?

    Step 3:

    3.1 Add/Remove. The only program I had was WildTangent. I have had this since I receive the computer about 4 years and is needed for several of the games provided by HP. I did not remove it.

    3.2 Updated Java and remove old versions

    3.3 I could not find the quarantine in Nortorn, so I skipped this step. The examples provided were different from mine.

    3.4 Emptied recycle bin

    3.5 Could not find Norton Nprotect folder

    3.6 Installed and ran CCleaner for all 4 accounts

    Step 4

    4.1 I have a 32 bit processor and use Windows XP

    4.2 I enabled viewing of hidden files

    4.3 I was already in normal startup mode

    Step 5

    None was removed. Only WildTangent was on the list.

    Step 6

    SuperAntiSpyware - The first time this ran. I was out of the room and came back and noticed my screen was empty (program had closed). I restarted, I got the blue screen of death, with a reference to a file with kernal in the name. I reran, got the BSOD again with a reference to a file with 'bad pool' in the name. I followed instructins and unchecked a couple of the kernal options, then reran, it found 146 items, but after about 10,000 files the computer rebooted and all was lost. I moved on.

    Malwarebyte Anti Malware - I had to run this a couple of times to get it to finish. Here is the log.

    Combofix - I also had to run this a couple of times. First time through it looked like it finished, but it rebooted before the file was written. The second time through, it appeared to run correctly.

    RootRepeal - This did not seem to run at all. It ran for 4 or 5 hours and did not show anything happening, including changing subdirectories.

    MGTools - This seemed to run OK.

    I have attempted to do all I can and hope this is enough for you to use. Please let me know if you need additional information from me. I am usually pretty good with computers, but I admit I am a little overwhelmed with this.

    Thank you for your time and expertise.

    JDWCowboy
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Other than what has already been removed, the logs for your account are basically clean. You just have a couple minor details to take care of.

    First remove MGtools.exe from your Desktop as that is not where it belongs.

    Npw run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    After clicking Fix, exit HJT.

    Now download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    You need to run the cleaning process on the user account having the problems. ;)
     
  3. JDWCowboy

    JDWCowboy Private E-2

    Thanks Chaslang,

    I had already removed MGTools.exe from my desktop.

    I ran analyse.exe out of the MGTools subdirectory. Then selected the file you mentioned and clicked fix. It created a log, but it was before the fix, so I won't attach it. If you want it or want me to run another log and attach it, I will.

    I then successfully ran HostsXpert.

    I was then a little confused about the comment at the end about different accounts on my XP account. We have 4 in our family and each has an account. Do I need to repeat this entire 'read and run first' program for each account? My Norton and Ad-aware scan well over 1M files and references files in the other accounts. I can certainly run these from those accounts too, if I need to. Please reconfirm if I need to do this.

    JDWCowboy
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In your first message you stated the below:
    Thus you were saying there are problems on your sons account. If you wish to fix problems on his account, you need to log out of your account and login as your son and run scans to find any problems that may be occurring on his user account. The same would be true for any other user account having problems but we would only work on one account at a time. Since we are finished with your account, you can now post logs for your son's.
     
  5. JDWCowboy

    JDWCowboy Private E-2

    Thanks for the help.

    Please close this thread. I will open a thread for my son's account.

    JDWCowboy
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since it is the same PC, you can just attach the logs for your son here now that we finished with your account. If it were a different PC, a new problem, or more than a week or two had passed then a new thread would be necessary.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds