Google Redirect infection, plus other malware suspected [Solved], and most diagnostics not producing output |
![]() ![]() |
Google Redirect infection, plus other malware suspected [Solved], and most diagnostics not producing output |
Nov 11 2009, 03:11 PM
Post
#16
|
|
![]() GeekU Senior Posts: 1,241 OS: XP Home |
Hello. Let's see where we are:
Step One Start OTS again.
Step Two We recently removed an infection from your system, that will may have stripped a few files of their permissions. We can fix it, but it may take some trial and error for you to find the right files. When I say 'that will not run,' I mean that they give off the error message "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." You mentioned MalwareBytes' giving off the error message. You should be able to find the executables in C:\Program Files\MalwareBytes' Anti-Malware Please download Inherit, by sUBs.
Step Three Please re-open Malwarebytes' Anti-Malware.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Step Four To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link. Close ALL OTHER PROGRAMS, and open OTS.
Please attach the log in your next post. It's usually located on the Desktop. To attach a file, do the following:
Logs&Info Remember to post back the following logs:
|
|
|
Nov 11 2009, 05:08 PM
Post
#17
|
|
|
Member ![]() ![]() Posts: 14 From: Watford, United Kingdom OS: Windows XP |
Hi again and thanks for sticking with me on this.
So first in answer to your questions: 1. CA Antivirus is still not updating. It can download the datafile fine, but then fails. 2. Google results seem to be fine now, but it was an intermittant thing so it's difficult to be certain 3. Programs that were failing are now running. (e.g MBAM, as you will see below) 4. No error messages at all, MS Windows seems much happier 5. No problems with fake alerts or anything similar So.... here's the logs. First the OTS Fix: ---------------------------------------------------------------------------- All Processes Killed [Registry - Safe List] Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\rundll32.exe not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WAB deleted successfully. C:\Documents and Settings\TheMortimers\Application Data\Macromedia\Common\490c603819.exe moved successfully. [Custom Scans] DllUnregisterServer procedure not found in C:\WINDOWS\system32\logevent.dll C:\WINDOWS\system32\logevent.dll moved successfully. [Custom Items] ========== FILES ========== C:\WINDOWS\System32\oqrk.pso moved successfully. [Empty Temp Folders] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Josie ->Temp folder emptied: 5832837 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 17410024 bytes ->FireFox cache emptied: 87264164 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 499933 bytes User: Owner User: Saffron ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: TheMortimers ->Temp folder emptied: 20359296 bytes ->Temporary Internet Files folder emptied: 70501988 bytes ->Java cache emptied: 13689540 bytes ->FireFox cache emptied: 32062832 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes RecycleBin emptied: 214735 bytes Total Files Cleaned = 236.42 mb < End of fix log > OTS by OldTimer - Version 3.1.4.0 fix logfile created on 11112009_224715 Files\Folders moved on Reboot... Registry entries deleted on Reboot... ---------------------------------------------------------------------------- Now the Malwarebytes AM log: ---------------------------------------------------------------------------- Malwarebytes' Anti-Malware 1.41 Database version: 2775 Windows 5.1.2600 Service Pack 3 11/11/2009 22:30:45 mbam-log-2009-11-11 (22-30-45).txt Scan type: Quick Scan Objects scanned: 115001 Time elapsed: 6 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 8 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rundll32.exe (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux1 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux2 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi1 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi2 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer1 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer2 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave1 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave2 (Hijack.Sound) -> Bad: (C:\DOCUME~1\THEMOR~1\APPLIC~1\MACROM~1\Common\490c60381.dll) Good: (wdmaud.drv) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\TheMortimers\Application Data\Macromedia\Common\490c60381.dll (Hijack.Sound) -> Delete on reboot. C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.sys) -> Delete on reboot. C:\WINDOWS\system32\wship6.dll (Trojan.Agent) -> Delete on reboot. ---------------------------------------------------------------------------- Finally, the log for the OTS scan is attached to this post. Many thanks Soupy
Attached File(s)
|
|
|
Nov 12 2009, 07:16 PM
Post
#18
|
|
![]() GeekU Senior Posts: 1,241 OS: XP Home |
Hello... What do you mean by "it fails." Any messages? I'm not familiar with CA Antivirus.
Step One Download TFC to your desktop
Step Two
Step Three Using Internet Explorer or Firefox, visit Kaspersky Online Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take quite a long time to download.
![]() Logs&Info Remember to post back the following logs:
|
|
|
Nov 13 2009, 05:06 PM
Post
#19
|
|
|
Member ![]() ![]() Posts: 14 From: Watford, United Kingdom OS: Windows XP |
Hi -
Thanks for your continued assistance. I've run through the steps above and here is the output from Kapersky: -------- begin included file -------- -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Friday, November 13, 2009 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, November 13, 2009 16:40:03 Records in database: 3204511 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ G:\ Scan statistics: Objects scanned: 149774 Threats found: 6 Infected objects found: 5 Suspicious objects found: 1 Scan duration: 02:23:53 File name / Threat / Threats count C:\Documents and Settings\TheMortimers\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Trojan-Downloader.Win32.Small.aafc 1 C:\Program Files\Mozilla Firefox\a.exe Infected: Trojan-Spy.Win32.Zbot.hsr 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\nvata.sys.vir Infected: Rootkit.Win32.TDSS.u 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\svchost.exe.vir Infected: Hoax.Win32.Renos.vcjk 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\net.net.vir Suspicious: Packed.Win32.PECompact 1 C:\_OTS\MovedFiles\11112009_224715\C_WINDOWS\system32\oqrk.pso Infected: Trojan-GameThief.Win32.OnLineGames.bmxm 1 Selected area has been scanned. -------- end included file --------- My CA Anti-Virus is still not playing ball, but I'm not too worried about that. For now I just want to get the machine clean, then if we can't fix it here then I'll go to the CA Forum and someone there will be able to get it working for me I'm sure. For the record the messages I get are: Package installation has been deferred: AV Dat Patch Update and An error occurred during the update process. Please try again later. Ta Soupy |
|
|
Nov 14 2009, 11:08 AM
Post
#20
|
|
![]() GeekU Senior Posts: 1,241 OS: XP Home |
Hello.
This is quite an old bug, but there's no harm in making sure. Check the CA quarantine, anything in there? If you see any "wextract.exe", restore them. Start OTS again.
|
|
|
Nov 14 2009, 03:24 PM
Post
#21
|
|
|
Member ![]() ![]() Posts: 14 From: Watford, United Kingdom OS: Windows XP |
Hi again - Here's the latest OTS log, as requested.
----- begin ----- All Processes Killed [Custom Items] ========== FILES ========== C:\Program Files\Mozilla Firefox\a.exe moved successfully. C:\WINDOWS\system32\drivers\beep.sys moved successfully. File/Folder C:\Documents and Settings\TheMortimers\Application Data\Macromedia\Common\490c60381.dll not found. DllUnregisterServer procedure not found in C:\WINDOWS\system32\wship6.dll C:\WINDOWS\system32\wship6.dll moved successfully. [Empty Temp Folders] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Josie ->Temp folder emptied: 6003030 bytes ->Temporary Internet Files folder emptied: 4080236 bytes ->Java cache emptied: 1860243 bytes ->FireFox cache emptied: 84255283 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Owner User: Saffron ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: TheMortimers ->Temp folder emptied: 96764199 bytes ->Temporary Internet Files folder emptied: 15639738 bytes ->Java cache emptied: 13817519 bytes ->FireFox cache emptied: 32800799 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes RecycleBin emptied: 563776 bytes Total Files Cleaned = 243.97 mb < End of fix log > OTS by OldTimer - Version 3.1.4.0 fix logfile created on 11142009_210321 Files\Folders moved on Reboot... Registry entries deleted on Reboot... ----- end ----- Oh and there is nothing listed in the CA quarantine area. Thanks Soupy |
|
|
Nov 15 2009, 04:50 PM
Post
#22
|
|
![]() GeekU Senior Posts: 1,241 OS: XP Home |
Hey! That last log looks clean!
Now let's do some cleaning up and learn how to protect ourselves from future infection! For CA Antivirus, you could try an uninstall\reinstall. However, it may be worth taking it over to the CA Forums first. ComboFix /Uninstall The following will implement some cleanup procedures as well as reset System Restore points: Click Start > Run, Copy/Paste the following bolded text into the Run box and click OK: ComboFix /Uninstall ![]() Tools Used This is so that should you ever be re-infected, you will download updated versions. It will also remove the quarantined Malware from your computer.
Windows Updates You should visit the Windows Update site about once a month. If you're feeling lazy you can turn on Automatic Updates which will do most of the work for you. (ask me how) Go to update.microsoft.com using Internet Explorer. Click High Priority Updates and then check all of the updates and then click the Download botten. A windows should pop up giving the status of each update. Restart if asked to. Prevention Tools
====================================================== If you are wondering how you got infected in the first place please visit this cool page called: How did I get infected in the first place? Glad I could help, piano9playa5 |
|
|
Nov 17 2009, 12:21 PM
Post
#23
|
|
|
Member ![]() ![]() Posts: 14 From: Watford, United Kingdom OS: Windows XP |
I really appreciate the time you've spent sorting this all out for me.
All the best, Soupy |
|
|
Nov 17 2009, 05:24 PM
Post
#24
|
|
![]() GeekU Senior Posts: 1,241 OS: XP Home |
No Problem.
|
|
|
Nov 18 2009, 02:45 PM
Post
#25
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
13 / 391 | 10th June 2009 - 07:00 PM Eidola started - last by sage5 |
|||||
![]() |
12 / 389 | 20th July 2009 - 01:24 PM pdxhandyman started - last by Rorschach112 |
|||||
![]() |
10 / 185 | 21st September 2009 - 02:29 PM Crozza started - last by Transience |
|||||
![]() |
19 / 181 | 3rd November 2009 - 11:07 AM jrwp started - last by Rorschach112 |
|||||
|
Time is now: 21st November 2009 - 04:31 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising