yep, another thread about IE and wave muting

Discussion in 'Malware Help (A Specialist Will Reply)' started by kkoala2112, Jul 15, 2010.

  1. kkoala2112

    kkoala2112 Private E-2

    Hi, I run Windows XP 32 bit
    I ran into this problem first when my computer would hang on a black screen, after the BIOS loaded. It looked like the boot sector was gone. I found a way around it by selecting a boot device and manually choosing the CD drive as the boot device. Ive tried changing the order of the boot devices but that doesnt work.

    After I finally got my computer to fully boot I found that I got a virus! Youve probably read this a thousand times but here how my computer is acting strangely. IE runs and I hear it in the background but its nowhere to be seen, and the volume mutes it self periodically randomly. Also at time I hear random ads, but do not see any of them.

    I followed the readme but have had no luck in fixing the problem....
     

    Attached Files:

  2. kkoala2112

    kkoala2112 Private E-2

    my MGtools log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe

    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.

    Now use windows explorer to find and delete:
    C:\WINDOWS\Temp\100.dat
     
  4. kkoala2112

    kkoala2112 Private E-2

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: b19ee33a0168d5f0bb9afbe12e2bc035
    \\.\H: -> \\.\PhysicalDrive2
    MD5: b19ee33a0168d5f0bb9afbe12e2bc035
    \\.\K: -> \\.\PhysicalDrive1
    MD5: b19ee33a0168d5f0bb9afbe12e2bc035

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 Unknown boot code
    149 GB \\.\PhysicalDrive2 Unknown boot code
    465 GB \\.\PhysicalDrive1 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Press any key to quit...
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.


    Now - please do the following:

    • Click Start, Run then copy and paste the below into the Run box and click OK.

    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0

    • Now reboot your PC and after reboot continue with the below instructions.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • C:\MGlogs.zip


    Make sure you tell me how things are working now!
     
  6. kkoala2112

    kkoala2112 Private E-2

    Hey well that seemed to fix it! Thanks soo much! :cool
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are still showing the infection, but that may be because you did not follow step 6 in the Read and Run First instructions to disable your disc emulation software. Please do that now and then get me a new MGLogs.zip.
     
  8. kkoala2112

    kkoala2112 Private E-2

    oh sorry. thanks for all the help sooo far. I hope its gone!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rats.

    Please also download MBRCheck to your desktop

    * Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    * It will show a Black screen with some information that will contain either the below line if no problem is found:
    o Done! Press ENTER to exit...
    * Or you will see more information like below if a problem is found:
    o Found non-standard or infected MBR.
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    * Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    * MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    * Attach this log to your next message.
     
  10. kkoala2112

    kkoala2112 Private E-2

    oh wow now im worried..
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are your H and K drives? Are these bootable drives?
     
  12. kkoala2112

    kkoala2112 Private E-2

    They are separate hard drives i use to store my media files. How can I tell if they are bootable drives? Also how bad is this problem?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is possible that they will reinfect the one we just fixed. So, you need to run the same procedure for each drive.

    First the H drive ..> physical drive2
    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 2 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now do it again for the K drive. --> Physical drive 1and again choosing the default xp MBR.
     
  14. kkoala2112

    kkoala2112 Private E-2

    ok did everything. hope this completely fixes the problem
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run it the second time for the K: drive? If so, please re-run the MBRCheck.exe and attach that log.
     
  16. kkoala2112

    kkoala2112 Private E-2

    yeah, i did it to both drives. soo now all drives have the MBR code


    MBRCheck, version 1.1.1
    (c) 2010, AD

    \\.\C: --> \\.\PhysicalDrive0
    \\.\H: --> \\.\PhysicalDrive2
    \\.\K: --> \\.\PhysicalDrive1

    Size Device Name MBR Status
    --------------------------------------------
    149 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    149 GB \\.\PhysicalDrive2 Windows XP MBR code detected
    465 GB \\.\PhysicalDrive1 Windows XP MBR code detected


    Done! Press ENTER to exit...
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet. Are you having any other issues? ;)
     
  18. kkoala2112

    kkoala2112 Private E-2

    nope! everything seems okay. thanks for alll the help!
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome!! :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  20. kkoala2112

    kkoala2112 Private E-2

    hey...umm sorry to revive a dead thread, but it came back. I dont know how!! I noticed that IE is no longer running under SYSTEM but rather my account. The wave hasnt muted itself at all, but I suspect that it will.... well I was just wondering if I should just repeat the process that you made for me, to get rid of this....hopefully for good
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to go back and re-run all the scans and attach those logs. I will take another look to see what may have happened. :major
     
  22. kkoala2112

    kkoala2112 Private E-2

    here you go..
     

    Attached Files:

  23. kkoala2112

    kkoala2112 Private E-2

    .....
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks to me like you got infected again by downloading keygens:
    K:\DOCUMENTS\DOWNLOADS\NETGATE REGISTRY CLEANER 1.0.6 + KEYGEN

    I will check your logs tomorrow when I get back on.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  25. kkoala2112

    kkoala2112 Private E-2

    Are you sure that was it? keygens always get picked as a virus. well anyways I deleted the files and that program.
    heres the log

    MBRCheck, version 1.1.1

    (c) 2010, AD



    \\.\C: --> \\.\PhysicalDrive0

    \\.\H: --> \\.\PhysicalDrive2

    \\.\K: --> \\.\PhysicalDrive1



    Size Device Name MBR Status

    --------------------------------------------

    149 GB \\.\PhysicalDrive0 Unknown MBR code

    149 GB \\.\PhysicalDrive2 Unknown MBR code

    465 GB \\.\PhysicalDrive1 Unknown MBR code





    Found non-standard or infected MBR.

    Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    Options:

    [1] Dump the MBR of a physical disk to file.

    [2] Restore the MBR of a physical disk with a standard boot code.

    [3] Exit.



    Enter your choice:
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now repeat that process for physical drives 1 and 2.

    Now please re-run MBRCheck.exe and attach that log also.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  27. kkoala2112

    kkoala2112 Private E-2

    here!
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. You just need to use windows explorer to find and delete these files:
    C:\WINDOWS\Cgehoh.dat
    C:\WINDOWS\Vqugakoroxaziv.bin
    C:\WINDOWS\Temp\100.dat
    C:\Documents and Settings\Owner\Local Settings\temp\35xc9.tmp

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds