also @ TechSpot: Codemasters announces £125,000 special edition of GRID 2

Oh no, here we go again

Discussion in 'Virus and Malware Removal' started by bkfuhrer, Mar 27, 2010.

  1. Broni Malware Annihilator Posts: 39,391   +177

    So, is IE the only issue as of now?
    Give me fresh HJT log, please.
  2. bkfuhrer Newcomer, in training Posts: 76

    I think so....

    Attached Files:

  3. Broni Malware Annihilator Posts: 39,391   +177

    Disable TeaTimer, as it'll interfere with the cleaning process:
    Right click Spybot's TeaTimer System Tray Icon.
    Click Exit Spybot-S&D Resident.
    TeaTimer closes.
    NOTE. If on re-boot, Spybot inquires about registry change(s), allow it.

    Alternatively, I suggest, you uninstall Spybot since it's a tool of the past.

    =======================================================================

    Print this post out, since you won't have an access to it, at some point.

    1. Open HijackThis.

    2. Close all windows, except for HijackThis.

    3. Put checkmarks next to the following HijackThis entries:

    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - Global Startup: Digital Line Detect.lnk = ?



    4. You should also checkmark following entries (these are unnecessary startups; no actual programs will be removed):

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    5. Click on Fix checked button.

    6. Restart computer.


    When done...


    Your computer is clean [IMG]

    1. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista and 7:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    2. Restart computer.

    3. Turn System Restore on.

    4. Make sure, Windows Updates are current.

    5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run defrag at your convenience.

    8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    9. Please, let me know, how is your computer doing.
  4. bkfuhrer Newcomer, in training Posts: 76

    I uninstalled Spybot, followed HJT instructions, System restore and I already have WOT.
    A few questions:
    I still do not have the recovery console downloaded. I have the extractor on my desktop still, should I try once again to install in into Combo Fix? I ask because this isn't my first visit here and this issue comes up every time we try to do a fix...
    What about Internet Explorer? Should I continue to try to update it or is that pointless now that firefox is stable again?
    Threatfire still crashes when I try to scan...
  5. bkfuhrer Newcomer, in training Posts: 76

    I also use Smart defrag but it wont open for me...
  6. Broni Malware Annihilator Posts: 39,391   +177

    I suggest, you uninstall ThreatFire.
    I used to use, but I found out, it may cause problems sometimes.

    Regarding recovery console...if you have Windows CD, you're fine. If you don't, let me know.
    How about Windows updates? Are they current?
    How did you try to install IE7? By a standalone download?
     
  7. bkfuhrer Newcomer, in training Posts: 76

    Okay,Threatfire is a goner then.
    Windows updates are fine, it was the only thing I was allowed to do online for awhile other than use my email... until I discovered the trick of pushing away the error box...
    I downloaded IE7 onto my desktop and then tried to install...
    Shall I dump Smart defrag also?
  8. Broni Malware Annihilator Posts: 39,391   +177

    I use SmartDefrag myself.
    You may try to reinstall it.

    See, if you can install standalone IE8.
  9. bkfuhrer Newcomer, in training Posts: 76

    I reinstalled SmartDefrag but it still wont open...
    "The application failed to initialize properly (0xc0000005) Click on OK to terminate the application."
    My next project will be to try IE8...
  10. bkfuhrer Newcomer, in training Posts: 76

    IE8 is a failure also :(
    I wonder why?
  11. Broni Malware Annihilator Posts: 39,391   +177

    Try to install IE8 in Safe Mode.
  12. bkfuhrer Newcomer, in training Posts: 76

    I followed method A from the page here http://support.microsoft.com/kb/949220#LetMeFixItMyselfAlways
    Do you think that will do it?
    Incidentally, the virus was found in one of the SP2 folders-

    The file 'C:\WINDOWS\$hf_mig$\KB936357\SP2QFE\update.sys'
    contained a virus or unwanted program 'TR/Rootkit.Gen' [trojan]
    Action(s) taken:
    The file was ignored!

    How did it get in there?
  13. Broni Malware Annihilator Posts: 39,391   +177

    We won't know until you try it :)

    What program did find that rootkit?
  14. bkfuhrer Newcomer, in training Posts: 76

    It was Avira....
  15. Broni Malware Annihilator Posts: 39,391   +177

    Well, let it fix the issue and see any more issues will arise.
  16. bkfuhrer Newcomer, in training Posts: 76

    Oh, that was the initial attack, actually. It happened a few days before I was able to browse to this site. I had it quarantine and kill soon after...
    I tried the Microsoft method A from post #52 but IE8 still fails, I will try their method D now which is start your computer in a "clean boot state"
  17. Broni Malware Annihilator Posts: 39,391   +177

    You scared sh** out of me....LOL

    As I said, you can try Safe Mode.
  18. bkfuhrer Newcomer, in training Posts: 76

    Oops, I'm sorry :p I was just checking through the Avira logs because I get curious about where these evil things lurk and how they get there...

    Well, I attempted another IE8 download in a "clean boot" state- no go.
    Tried in in Safe Mode, no go also...
    One other option Microsoft provides is - Method E: Check for any files that cannot be backed up or updated
    It looks kind of scary to me...
  19. Broni Malware Annihilator Posts: 39,391   +177

    What does EXACTLY happen, when you try to install IE8?
    Are you getting any messages?
  20. bkfuhrer Newcomer, in training Posts: 76

    After double click it begins by extracting files then the installer box comes on... There are 5 parts to the download-
    Downloading
    Checking for malicious software
    Installing IE8 (this part seems to complete, but then a red x appears next to the text)
    Installing updates
    Finishing setup
    All lines end with a green check mark except for Installing IE8 which has a red x
    Then it says the installation failed and to restart computer and double click on an icon which leads you here : http://support.microsoft.com/gp/ie8_browserDetect

    I am looking at the event viewer now, I don't really know what any of it means but there are a number of errors...