This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Β I think I'm infected

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your log , I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


You have two anti virus running on your computer, Avast and Norton. Running more than one anti virus at the same time does not only slow down your computer but
provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall one of your anti virus before proceeding with any of the fixes.

–Next–

You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall LimeWire, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx


–Next–

What happens when you try to run GMER? Are there any error messages?

Let's try running it in safe mode, to do this:
  • Restart your computer.
  • Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
  • When a list of menu appears, scroll to Safe Mode using the arrow keys then press Enter.
  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
Run GMER again, this time click on the box beside "Files" to uncheck it then run a scan.

–Next–

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    C:\Documents and Settings\All Users\Application Data\TabQuery\tabquery125.exe
  • Click Submit. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Please post the results in your next reply.

To post in your next reply:
1. GMER log.
2. GooredFix log.
3. VirSCAN log.
I tried running GMER on safe mode, but evertime I tried scanning….the whole system would restart. Also sometimes when I start up my computer an error comes up and says "System has recovered from a serious error" It is one of the pop up where you have the choice of sending the error report or not.
Hi,

Have you disabled your antivirus and checked "Files" before having GMER scan?

Let's try this:
We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Right click [external image: Posted Image] then choose "Run as Administrator" on your desktop to run the tool.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
–Next–

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    C:\Documents and Settings\All Users\Application Data\TabQuery\tabquery125.exe
  • Click Submit. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Please post the results in your next reply.

To post in your next reply:
1. RootRepeal log.
2. GooredFix log.
3. VirSCAN log.
Hi,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log, don't attach.
Hi, It's been several days. Do you still need help on this? This thread will be closed if you don't respond within 24 hours.
Were you able to run Combofix?

Try running in safe mode then post the Combofix log.

To do this,
  • Restart your computer.
  • Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
  • When a list of menu appears, scroll to Safe Mode using the arrow keys then press Enter.
Hi,

Please don't attach the succeeding logs, post the contents. Thanks.

Delete your copy of combofix then download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop and don't run it yet

–Next–

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/I_think_I_m_…985#entry645985

Collect::
c:\windows\agawazuc.dll
c:\windows\emitafapititefe.dll
c:\windows\evuxizodul.dll
c:\windows\eniguwivi.dll
c:\windows\opuqenezuduqi.dll
c:\windows\oxineput.dll
c:\windows\otakalibi.dll
c:\windows\ozejeboyoradiyub.dll
c:\windows\abajodivo.dll
c:\windows\uxeyadepiriq.dll
c:\windows\system32\drivers\drivers\21p369.sys.sys
c:\windows\system32\drivers\Registry\Machine\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\2RGDP96.sys.sys
c:\windows\system32\drivers\ControlSet001\Control\SafeBoo.sys
c:\docume~1\Mom\LOCALS~1\Temp\mdxgthkn.sys

Folder::
c:\program files\antispywaremaster

Driver::
21p369.sys
2RGDP96.sys
SafeBoo
mdxgthkn

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

DDS::
mRun: [AntiSpywareMaster] c:\program files\antispywaremaster\asm.exe

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI