Computer Hope

Software => Computer viruses and spyware => Virus and spyware removal => Topic started by: Amats on May 07, 2010, 09:23:47 PM

Title: Fighting infection
Post by: Amats on May 07, 2010, 09:23:47 PM
Processor: AMD Athlon Dual Core 64X2 2.91 GHz
RAM: 3.5 Gb
Video Card: Nvidia Geforce 8800 GTS 512mb
Service Pak 3

Never had much trouble with viruses before but about 2 months ago computer couldn't access the internet through my wireless network.  I wiped the hard drive and it worked ok then started having the same problem again.  Wiped again, worked ok had the same problem again in about a week.  I was told some years ago by a computer tech that  a router is a hardware firewall and software firewalls are not needed.  Seems that advice doesn't apply now.  I've done all the steps through copying the SuperAntiSpyware log which is pasted below.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/06/2010 at 10:49 PM

Application Version : 4.36.1006

Core Rules Database Version : 4900
Trace Rules Database Version: 2712

Scan type       : Complete Scan
Total Scan Time : 00:48:20

Memory items scanned      : 558
Memory threats detected   : 0
Registry items scanned    : 6743
Registry threats detected : 1
File items scanned        : 60299
File threats detected     : 74

System.BrokenFileAssociation
   HKCR\.exe

Adware.Tracking Cookie
   C:\Documents and Settings\Mom\Cookies\mom@247realmedia[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@2o7[1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@adbrite[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@adecn[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@advertising[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@adxpose[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@apmebf[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\mom@atdmt[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@bizrate[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@burstnet[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@collective-media[1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][3].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@doubleclick[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@fastclick[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@householdaccount[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@imrworldwide[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@insightexpressai[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@interclick[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@invitemedia[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@kanoodle[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@kontera[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@lockedonmedia[1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@media6degrees[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@mediaplex[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\mom@overture[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\mom@pointroll[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@questionmarket[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@realmedia[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@revsci[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@ru4[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@serving-sys[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@specificclick[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@specificmedia[2].txt
   C:\Documents and Settings\Mom\Cookies\mom@statcounter[2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\mom@tacoda[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@trafficmp[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@traveladvertising[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@tribalfusion[1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][3].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][4].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][5].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][6].txt
   C:\Documents and Settings\Mom\Cookies\[email protected][7].txt
   C:\Documents and Settings\Mom\Cookies\mom@yieldmanager[1].txt
   C:\Documents and Settings\Mom\Cookies\mom@zedo[2].txt
Title: Re: Fighting infection
Post by: Carol~ on May 10, 2010, 02:22:57 PM
Carol, you are not allow to post in this forum. If you want to help please read the link "Would you like to learn to fight malware". Thank you.
Title: Re: Fighting infection
Post by: SuperDave on May 10, 2010, 07:18:00 PM
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

(http://img233.imageshack.us/img233/7729/mbamicontw5.gif) Please download Malwarebytes Anti-Malware from here (http://www.malwarebytes.org/mbam/program/mbam-setup.exe).

Double Click mbam-setup.exe to install the application.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
===================================

Please download: HiJackThis (http://go.trendmicro.com/free-tools/hijackthis/HijackThisInstaller.exe) to your Desktop.
Title: Re: Fighting infection
Post by: Amats on May 10, 2010, 07:39:38 PM
I really appreciate the help Dave.  2 logs attached

[recovering disk space - old attachment deleted by admin]
Title: Re: Fighting infection
Post by: SuperDave on May 11, 2010, 08:02:00 PM
Disable/Remove Windows Messenger  (http://www.majorgeeks.com/DisableRemove_Windows_Messenger_d2327.html) to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

==========================================

Please download ComboFix (http://img7.imageshack.us/img7/4930/combofix.gif) from BleepingComputer.com (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

Alternate link: GeeksToGo.com (http://subs.geekstogo.com/ComboFix.exe)

Rename ComboFix.exe to commy.exe before you save it to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here (http://www.bleepingcomputer.com/forums/topic114351.html)
Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]
(http://img.photobucket.com/albums/v666/sUBs/Query_RC.gif)
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
(http://img.photobucket.com/albums/v666/sUBs/RC_successful.gif)

Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

If you have problems with ComboFix usage, see  How to use ComboFix (http://www.bleepingcomputer.com/combofix/how-to-use-combofix)
Please copy and paste your logs in your next reply.

Title: Re: Fighting infection
Post by: Amats on May 12, 2010, 09:40:51 PM
Combofix log attached

[recovering disk space - old attachment deleted by admin]
Title: Re: Fighting infection
Post by: SuperDave on May 13, 2010, 05:18:08 PM
Quote
I was told some years ago by a computer tech that  a router is a hardware firewall and software firewalls are not needed.
Not all routers have built-in firewalls.

Please go to Jotti's malware scan (http://virusscan.jotti.org/)

(If more than one file needs scanned they must be done separately and logs posted for each one)

* Copy the file path in the below Code box:

Code: [Select]
c:\windows\system32\drivers\kgpcpy.cfg
* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

I can't find too much that is dangerous in your logs. How is your computer working now?

I'd like us to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
 ESET OnlineScan (http://eset.com/onlinescan)
•Click the (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png) button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png)
•Click the (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png) button.
•Accept any security warnings from your browser.
•Check (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png)
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png)
•Push (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png), and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png) button.
•Push (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png)
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Title: Re: Fighting infection
Post by: Amats on May 15, 2010, 08:22:27 PM
I am still unable to connect to my wireless internet on this computer.  I ran a scan with a program called StopZilla before you started helping me and it said I had a dialer virus but it wanted $40 to eliminate it.  Didn't know if it was a scam or not.  computer is extremely slow tonight
2 files attached

[recovering disk space - old attachment deleted by admin]
Title: Re: Fighting infection
Post by: SuperDave on May 16, 2010, 01:08:52 PM
Quote
I ran a scan with a program called StopZilla before you started helping me and it said I had a dialer virus but it wanted $40 to eliminate it.

StopZilla is not a good program to have on your computer.

The txt file from Jotti's is no good. I will need the link. Please do it again and paste the link in your next reply.

The ESET scan looks good so all I need now is the link from Jotti's.

Quote
computer is extremely slow tonight.
Do you mean when you're on-line or just slow all the time? How much RAM do you have and how much free disk space?
Title: Re: Fighting infection
Post by: Amats on May 17, 2010, 07:29:50 PM
Actually, several nights ago I was running internet and programs and hit the stop button on my computer accidently which turned the computer off and ever since then its very hard to select anything with my mouse.  Do you think maybe I created an error on my hard drive or what?
Also, when I try to select the box to paste the file for the Jotti scan, a window with a bunch of drivers listed on it comes up and will not let me paste the file in the box.  I tried deleting it but it just keeps coming back.
Title: Re: Fighting infection
Post by: SuperDave on May 18, 2010, 07:44:37 AM
Quote
Do you think maybe I created an error on my hard drive or what?
You could try this. Also please ensure that all your cables are securly attached. Please let me know if this problem still continues.

Check Hard Disk For Errors:

Press Start->Run, then copy/paste the following command into the box and press OK:

Quote
cmd /c chkdsk c: |find /v "percent" >> "%userprofile%\desktop\checkhd.txt"

A blank command window will open on your desktop, then close in a few minutes. This is normal.
A file icon named checkhd.txt should appear on your Desktop. Please post the contents of this file.
===============================

Quote
when I try to select the box to paste the file for the Jotti scan, a window with a bunch of drivers listed on it comes up and will not let me paste the file in the box.  I tried deleting it but it just keeps coming back.
Don't bother with it anymore. The ESET scan came back clean.
Title: Re: Fighting infection
Post by: Amats on May 18, 2010, 05:21:33 PM
I ran ckdsk, 1 file attached.

[recovering disk space - old attachment deleted by admin]
Title: Re: Fighting infection
Post by: SuperDave on May 18, 2010, 05:38:13 PM
As stated in that report, please run chkdsk again with the F parameter. chkdsk /f
Title: Re: Fighting infection
Post by: Amats on May 19, 2010, 08:46:27 PM
Ran chkdsk F, no more problems with mouse.  Only problem that remains is I can't access my wireless internet with this computer.
Title: Re: Fighting infection
Post by: SuperDave on May 20, 2010, 11:09:09 AM
Try hard-wiring your computer to your router. If you can connect, using that method, then there is something not right with your wireless receiver. My daughter was having the same problem with her laptop. I shut it off, restarted it and the connection was there. I had the same problem with my laptop about a week later with the same solution. Sometimes, the best thing we can do for a computer is to shut it off now and then. If you're still having problems connecting, I suggest that you start a thread in one of the other forums dealing with this type of problem.
Title: Re: Fighting infection
Post by: Amats on May 20, 2010, 04:11:48 PM
Thank you for all your help!  :)
Title: Re: Fighting infection
Post by: SuperDave on May 20, 2010, 04:55:16 PM
Quote
Thank you for all your help!
You're welcome.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type commy /uninstall in the runbox
* Make sure there's a space between commy and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

=================================

Download OTC by OldTimer (http://oldtimer.geekstogo.com/OTC.exe) and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

==================================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

======================================
Use the Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

----------

I suggest using WOT - Web of Trust (http://www.mywot.com/). WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html)- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer (http://www.bleepingcomputer.com/forums/tutorial49.html) from Spyware and Malware
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. (http://www.safer-networking.org/en/spybotsd/index.html) Guide: Use Spybot's Immunize Feature (http://www.bleepingcomputer.com/tutorials/tutorial43.html#immunize) to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ (http://www.safer-networking.org/en/faq/index.html)

Check out Keeping Yourself Safe On The Web  (http://evilfantasy.wordpress.com/2008/05/20/keeping-yourself-safe-on-the-web/) for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware (http://evilfantasy.wordpress.com/2008/05/24/slow-computer-it-may-not-be-malware/) for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!