My internet browser is always being redirected. I've downloaded and tried to run AVG and MalwareBytes, but neither will run. My antivirus software, Bitdefender detects the virus, but cannot delete it or quarantine it. I need help.
I posted here before but my computer was frozen for a time and i was finally able to get it to safe mode and get it running, albeit still infected.
While I go through your log, I would very much appreciate it if you read the following.
I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.
Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.
Thanks for choosing WhatTheTech and I will be back with a fix shortly!
It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.
Do not reboot your computer after running rkill as the malware programs will start again.
Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
rkill.exe
rkill.com
rkill.scr
WiNlOgOn.exe
uSeRiNiT.exe
Do not reboot your computer after running rkill as the malware programs will start again.
Step Two
Download OTL to your Desktop from one of the following links:
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
Click on Minimal Output at the top
Download the following file scan.txt to your Desktop from HERE.
Double click inside the Custom Scan box at the bottom
A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
Select scan.txt and click Open. Writing will now appear under the Custom Scan box
Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in this thread.
Step Three
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Note: If your security software warns about Rkill, ignore & allow the download to continue.
Download RKillby Grinler from Here & save it to your Desktop.
Alternate download links: Two Three Four
Double click Rkill to run it
A command window will open then disappear upon completion, this is normal
If this does not happen… delete the file, then download & use the next link provided
If it does not work, repeat the process & attempt to use one of the remaining links until the tool runs
Do not reboot your machine until asked to do so. If no version of Rkill would run, please let me know
When finished, Notepad will open with a log file, automatically saved at C:\rkill.log
Copy/paste the contents of the rkill.log file in your next reply
Leave Rkill on the Desktop unless instructed otherwise
Note: If you get an alert that Rkill is infected, ignore it. The alert is a fake warning given by the rogue software, trying to "protect" itself from being terminated or removed. If you see such a warning, leave the warning on the screen, then run Rkill again. By not closing the warning, this sometimes allows you to bypass the malware's attempt to protect itself, so that Rkill can perform its routine.
After running RKill continue to do the following, it is important in this time you do not reboot your PC.
Step 2
Download OTL to your Desktop
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
Click on Minimal Output at the top
Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
Double click inside the Custom Scan box at the bottom
A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
Select scan.txt and click Open. Writing will now appear under the Custom Scan box
Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
Step 3
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Byron on 09/12/2010 at 20:58:35.
Services Stopped:
Processes terminated by Rkill or while it was running:
OTL logfile created on: 9/13/2010 7:47:46 AM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Byron\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 59.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 203.84 Gb Free Space | 70.98% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.79 Gb Free Space | 16.39% Space Free | Partition Type: NTFS
Drive E: | 7.47 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BYRON-PC
Current User Name: Byron
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
MOD - C:\Users\Byron\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
MOD - C:\WINDOWS\System32\UmxSbxw.dll (CA)
MOD - C:\WINDOWS\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
Hi Perk,
Please try attaching your logs to a post. To do this click "Add Reply" then under the text input field there is an area to upload and attach files.
Please attach ALL logs that I requested previously
Thanks.
Please navigate to http://tinypaste.com/ and copy/paste your log into the main text area, then click submit (bottom right). You will then be redirected to a page with a link on it. Please post that link here for me to see.
Please be sure to make a separate paste for each log.
Note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).
If you choose not to remove them, please do not use them until this computer is clean.
Step 2 - 2 Anti-Virus Programs Running!
You are operating your computer with multiple Anti-virus programs:
BitDefender
CA
It is not safe to have more than one anti-virus installed on a computer, and doing so not only does not provide better protection, it will actually cause additional problems.
Anti-virus programs hook deep into the system to provide their protection and take up an enormous amount of your computer's resources when they are actively scanning your computer.
Having multiple anti-virus programs on one computer can cause your computer to run very slow, become unstable and even crash, You must remove all but one anti-virus program now.
To do this click Start > Run then copy/paste this: control.exe appwiz.cpl and click Ok. Then remove your chosen AV's from the list presented.
Step 3
Run OTL.exe
Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL
:OTL
O4 - HKCU..\Run: [MSVirtual] File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
:Files
C:\Users\Byron\Desktop\Magic ISO Maker 5.4 with serial
C:\Users\Byron\Desktop\Business Plan Pro 2007 Premier Edition v9.06.0006 Incl Keymaker
:Commands
[purity]
[emptytemp]
[emptyflash]
[resethosts]
Then click the Run Fix button at the top
Let the program run unhindered, reboot when it is done
After rebooting, please post the OTL you are presented with on startup.
Step 4
Download the Norton Removal Tool from HERE and save it to your desktop.
Next Double click on Norton_Removal_Tool.exe to run the tool.
Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.
Step 5
Please download Malwarebytes' AntiMalware.
Double click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform Full Scan, then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the entire report in your next reply.