Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Regarding "Read this before requesting malware removal help"  (Read 4231 times)

0 Members and 1 Guest are viewing this topic.

fkmckenzie

    Topic Starter


    Greenhorn

    Regarding "Read this before requesting malware removal help"
    « on: February 05, 2010, 12:12:45 PM »
    Hi, I have followed everything that you have said to do and can now upload the logs. I can't think of anything that brought the virus on so don't have any additional details for you. When performing the SuperAntiSpyware search, I had to cancel the first search so now have two logs. I have uploaded both of them and the log from the most recent search has been uploaded second. Also, I cannot do a system restore and it asks me to contact the domain administrator. Is there any way of being able to perform a system restore again?
    Thanks very much.

    [Saving space, attachment deleted by admin]

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Regarding "Read this before requesting malware removal help"
    « Reply #1 on: February 05, 2010, 01:02:32 PM »
    Welcome to CH.

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    • O15 - Trusted Zone: http://*.buy-internet-security10.com
    • O15 - Trusted Zone: http://*.buy-internetsecurity10.com
    • O15 - Trusted Zone: http://*.is-soft-download.com
    • O15 - Trusted Zone: http://*.is-software-download.com
    • O15 - Trusted Zone: http://*.is-software-download25.com
    • O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)
    • O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Download Lop S&D by Eric_71 and save it to your desktop. Lop S&D will only run on Windows XP and Windows Vista

    Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D.

    Double click LopSD.exe - If you are using Windows Vista or Windows 7, right-click on the LopSD icon and select Run as administrator to perform this scan.

    * Choose the language by typing of the corresponding letter and press Enter
    * Click OK at the informative window.
    * Type 2 to choose Option 2 (Delete with Hosts File Restore), then press Enter
    * Wait until the end of the scan.
    * A report will be generated, post the contents of it in your next reply, along with a HijackThis log.

    fkmckenzie

      Topic Starter


      Greenhorn

      Re: Regarding "Read this before requesting malware removal help"
      « Reply #2 on: February 05, 2010, 03:16:20 PM »
      Hey, here is a copy of he lopR log. Since I only did a system scan with HijackThis, I didn't get another log.

      Thanks

      [Saving space, attachment deleted by admin]

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Regarding "Read this before requesting malware removal help"
      « Reply #3 on: February 05, 2010, 03:21:55 PM »
      Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

      Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

      * XP users Double click on dds to run it.
      * If your antivirus or firewall try to block DDS then please allow it to run.
      * When finished DDS will open two (2) logs.

      1) DDS.txt
      2) Attach.txt

      * Save both logs to your desktop.
      * Please copy and paste the entire contents of both logs in your next reply.

      Note: DDS will instruct you to post the Attach.txt log as an attachment.
      Please just post it as you would any other log by copy and pasting it into the reply.

      fkmckenzie

        Topic Starter


        Greenhorn

        Re: Regarding "Read this before requesting malware removal help"
        « Reply #4 on: February 05, 2010, 03:26:58 PM »
        Hi, here are the next two posts. Thanks

        [Saving space, attachment deleted by admin]

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Regarding "Read this before requesting malware removal help"
        « Reply #5 on: February 05, 2010, 03:48:43 PM »
        Note: You got this infection from installing the sponsored software with Messenger Plus! Live.

        Quote
        C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27\How to use keygen.txt
        C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27\Keygen.exe

        Please remove Driver magician V 3.27 and any other cracked software. I can't continue helping if it is not removed.

        ----------

        Go to Add or Remove Programs and uninstall:

        • J2SE Runtime Environment 5.0 Update 6
        • Messenger Plus! Live & Sponsor (CiD)
        .
        Note: You can reinstall Messenger Plus but DO NOT choose to install the sponsored software!

        ----------

        If you already have ComboFix be sure to delete it and download a new copy.

        Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

        Link #1
        Link #2

        **Note:  It is important that it is saved directly to your Desktop

        DO NOT run it yet!

        Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

        Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

        Delete these files/folders, as follows:

        1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
        It must be Notepad, not Wordpad.
        2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

        Code: [Select]
        KillAll::

        DDS::
        TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
        TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
        uRun: [sefjhf98jfoidsfoishgoiusgdgfgd] c:\docume~1\fraser_2\locals~1\temp\zf0qkdnkgh.exe
        uRun: [smss32.exe] c:\windows\system32\smss32.exe
        IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

        File::
        C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
        C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
        c:\docume~1\fraser_2\locals~1\temp\zf0qkdnkgh.exe
        c:\windows\system32\smss32.exe
        c:\windows\system32\IS15.exe
        c:\windows\system32\helper32.dll
        c:\windows\system32\winlogon32.exe
        C:\horj.exe
        C:\kkalf.exe

        Folder::
        c:\docume~1\fraser_2\applic~1\SystemProc
        C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27
        c:\program files\messenger
        C:\s


        3. Go to the Notepad window and click Edit > Paste
        4. Then click File > Save
        5. Name the file CFScript.txt - Save the file to your Desktop
        6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



        ComboFix will begin to execute, just follow the prompts.
        After reboot (in case it asks to reboot), it will produce a log for you.
        Post that log (Combofix.txt) in your next reply.

        Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

        fkmckenzie

          Topic Starter


          Greenhorn

          Re: Regarding "Read this before requesting malware removal help"
          « Reply #6 on: February 05, 2010, 04:32:23 PM »
          Hi there, here is the combofix log.
          Thanks

          [Saving space, attachment deleted by admin]

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Regarding "Read this before requesting malware removal help"
          « Reply #7 on: February 05, 2010, 04:44:44 PM »
          Download the below attached CFScript.txt and save it to your desktop (click on the Attached File underneath this post)

          * If you are using Internet Explorer when the "File download" pop up comes click Save and choose desktop  in the list of selections in that window and then click Save.
          * If you are using Firefox choose Save to disk then click OK and choose desktop in the list of selections in that window and then click Save.

          Close all open Web Browsers!
           
          Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below.



          This will start ComboFix. ComboFix may ask to reboot the computer when it is finished, please allow it to do so.

          A new log will be created, post the contents of Combofix.txt in your next reply.
           
          Note: these instructions and script were created specifically for this user. If you are not this user do NOT follow these instructions or use this script as it could damage the workings of your system.

          [Saving space, attachment deleted by admin]

          fkmckenzie

            Topic Starter


            Greenhorn

            Re: Regarding "Read this before requesting malware removal help"
            « Reply #8 on: February 05, 2010, 05:21:36 PM »
            Here is the latest log. Thanks. I need to go now so I shall continue tomorrow. Thanks for all your help so far.

            [Saving space, attachment deleted by admin]

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Regarding "Read this before requesting malware removal help"
            « Reply #9 on: February 05, 2010, 05:35:08 PM »
            I need to go now so I shall continue tomorrow. Thanks for all your help so far.

            No problem. I'll be around.

            * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
            * Now type Combofix /Uninstall in the runbox
            * Make sure there's a space between Combofix and /Uninstall
            * Then hit Enter

            * The above procedure will:
            * Delete the following:
            * ComboFix and its associated files and folders.
            * Reset the clock settings.
            * Hide file extensions, if required.
            * Hide System/Hidden files, if required.
            * Set a new, clean Restore Point.

            ----------

            Clean out your temporary internet files and temp files.

            Download TFC by OldTimer to your desktop.

            Double-click TFC.exe to run it.

            Note: If you are running on Vista, right-click on the file and choose Run As Administrator

            TFC will close all programs when run, so make sure you have saved all your work before you begin.

            * Click the Start button to begin the cleaning process.
            * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. 
            * Please let TFC run uninterrupted until it is finished.

            Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

            ----------

            ESET Online Scan

            Scan your computer with the ESET FREE Online Virus Scan

            * Click the ESET Online Scanner button.

            * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
            * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
            * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
            * Place a check mark next to YES, I accept the Terms of Use.

            * Click the Start button.
            * Accept any security warnings from your browser.
            * Leave the check mark next to Remove found threats and place a check next to Scan archives.
            * Click the Start button.
            * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
            * When the scan completes, click List of found threats.
            * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
            * Click the <<Back button then click Finish.

            In your next reply please include the ESET Online Scan Log

            fkmckenzie

              Topic Starter


              Greenhorn

              Re: Regarding "Read this before requesting malware removal help"
              « Reply #10 on: February 06, 2010, 09:02:42 AM »
              Hi, here is the ESETScan log for you.

              [Saving space, attachment deleted by admin]

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Regarding "Read this before requesting malware removal help"
              « Reply #11 on: February 06, 2010, 10:44:20 AM »
              If there are no other malware issues we can finish up now.

              Use the Secunia Software Inspector to check for out of date software.

              * Click Start Now
              * Check the box next to Enable thorough system inspection.
              * Click Start
              * Allow the scan to finish and scroll down to see if any updates are needed.
              * Update anything listed.

              ----------

              Go to Microsoft Windows Update and get all critical updates.

              ----------

              If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

              ----------

              I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

              I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

              SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
              * Using SpywareBlaster to protect your computer from Spyware and Malware
              * If you don't know what ActiveX controls are, see here

              Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

              Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

              Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

              fkmckenzie

                Topic Starter


                Greenhorn

                Re: Regarding "Read this before requesting malware removal help"
                « Reply #12 on: February 06, 2010, 11:09:45 AM »
                Thanks a lot. You have been a great help to me

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Regarding "Read this before requesting malware removal help"
                « Reply #13 on: February 06, 2010, 11:11:33 AM »
                Your welcome. :)