Persistent Malware/Viral Infection -- Help!

McAfee appears to be completely gone. The utilities you linked to have nothing to remove. C’est la vie, I say.

Should I run another freefixer scan with the refreshed system?

Edit: Scratch that a few things were removed. What now?

Well, I don’t think so… To be honest, what is freefixer scan?

Install avast, doesn’t it? ???

Update: Newest scan found Win32:Trojan-gen. Computer still displaying symptoms of infection. :frowning:

Did you run a boot time scan…??
If you’re on a 32bit system, please do so…!
asyn

I suggest:

  1. Clean your temporary files.
  2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
  3. Use MBAM (or SUPERantispyware or even Spyware Terminator) to scan for spywares and trojans. If any infection is detected, it is better and safer to send the infected file(s) to quarantine (Chest), rather than simply deleting them.
  4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
  5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
  6. Clean your Hosts file (replacing it) with HostsMan tool.
  7. Disable System Restore and then reenable it again.
  8. Immunize your system with SpywareBlaster.
  9. Check if you have insecure applications with Secunia Software Inspector.

Hi I have attached the freefixer log with suggestions,

pol

Polonus,

I have done as you suggested and removed the files you pointed out. I am hesitant to say “so far, so good” out of fear that it might be premature, so I will let you all know whether the problem has been fixed in a day or two. :slight_smile:

No go :frowning:

I am still displaying all the symptoms of infection. Rogue pop-ups and hijacked google links. I already ran a boot scan last night and it found nothing.

I’ve attached an updated freefixer log. For some reason the forum won’t let me upload the hijackthis log.

In the mean time, I have no idea what an anti-rootkit application is. Is it safe to delete all that stuff? It came up with over 500 entries. And… what’s a Hosts file? How do I disable system restore? I’m sorry if these are all stupid questions… it seems like I really don’t know anything about computer security :frowning:

I guess, you need Essexboy to help clean your machine…!
Pondus, can you please point him to this thread…!?? :wink:
asyn

Hi lets have a look

http://www.geekstogo.com/misc/guide_icons/gmer.png
GMER Rootkit Scanner - Download - Homepage
[] Download GMER
[
] Extract the contents of the zipped file to desktop.
[*] Double click GMER.exe.

http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif

[*] If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan…
[*] In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED
[] IAT/EAT
[
] Drives/Partition other than Systemdrive (typically C:)
[*] Show All (don’t miss this one)

http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg

Click the image to enlarge it

[*] Then click the Scan button & wait for it to finish.
[*] Once done click on the [Save…] button, and in the File name area, type in “ark.txt”
[*]Save the log where you can easily find it, such as your desktop.
CautionRootkit scans often produce false positives. Do NOT take any action on any “<— ROOKIT” entries
Please copy and paste the report into your Post.

THEN

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select Scan all users
[*]Under the Custom Scan box paste this in


netsvcs
drivers32 /all
%SYSTEMDRIVE%*.*
%systemroot%\system32\Spool\prtprocs\w32x86*.dll
%systemroot%*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32*.dll /lockedfiles
%systemroot%\Tasks*.job /lockedfiles
%systemroot%\System32\config*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

Regrettably, I bring bad news, Essexboy. GMER gave me a catastrophic blue screen memory dump both times I tried to use it so I gave up. As for OTL, after getting an “Access Violation at address 0040295B in module ‘OTL.exe’. Read of address 001E9000” I got the logs. They’re attached.

Thank you for your help!

Here’s the other. Forum file size cap prevented me from including it in the previous post.

Unfortunately GMER does that sometimes, usually when you have a cd emulator onboard

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL
O4 - HKU\.DEFAULT..\Run: [khbwmxim] C:\Documents and Settings\NetworkService\Local Settings\Application Data\pleawapgw\bstamwstssd.exe File not found
O4 - HKU\S-1-5-18..\Run: [khbwmxim] C:\Documents and Settings\NetworkService\Local Settings\Application Data\pleawapgw\bstamwstssd.exe File not found
[2010/05/06 15:01:14 | 000,231,935 | ---- | M] () -- C:\WINDOWS\jgzr.dat

:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

.

THEN

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[*]Double click on ComboFix.exe & follow the prompts.

[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.

http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

New OTL Log

Combofix log. Amazing that they keep finding things…

Can you confirm that all is working OK now

Chrome works again! And I’ve performed several Google searches… no hijacked links. And, I haven’t had any rogue pop ups!!! Okay, give me a day, let me use the computer for a bit and I’ll let you know! :slight_smile:

OK once you are happy then run the following cleanup procedure

I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following


:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS] 
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

SPRING CLEAN

Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
[*]SpywareBlaster to help prevent spyware from installing in the first place.

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave:

Okay, I’m back. First let me say not to worry, everything is alright, I just wanted to give an update. I apologize for not getting back sooner; it wasn’t that I’m not appreciative, I’ve just been incredibly busy over the last week.

The computer works. After a week’s worth of use, I’ve had no problems.

I wanted to thank you all so very much for your help. I’m extremely grateful for all the help you each have provided. Essexboy, I am pretty much indebted to you. Thank you so much for everything you’ve done to help me out. I know there is no material compensation I can provide to you to show you just how appreciative I am, so I hope my thanks will do.

Thanks again!

My pleasure - just keep safe now