Attempted to Read and Run first but...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by redoakflower, Aug 6, 2009.

  1. redoakflower

    redoakflower Private E-2

    . . .only Root Repeal and MG worked "as intended." I am attaching those two logs.
    I'm very limited in my understanding of computers, but I'll try my best to explain what's going on with mine. Here goes...


    • SUPER AntiSpyware would not download, giving me:
      I clicked "ignore" the first time and attempted to use SAS both with the normal start and the alternate, but neither worked.

    • Malwarebytes appeared to download and run but vanished after a few seconds. At the end of the download and before running (automatically, of course, as I had checked the 'run on dl' box) the following error popped up:

    • Combofix seemed to be running fine, but after completing all the 'stages' the computer crashed to a blue screen. I tried it a second time with another blue screen. I'm not sure what information is pertinent from the bluescreen stop error information, but they were different. The first one said something about catchme.sys and PAGE_FAULT_IN_NONPAGED_AREA. The second time it was BAD_POOL_CALLER.

    I figured I would continue on through the list and see if I could pull any information and I was thrilled that, at least, the last two programs worked.

    Finally, there are some combofix text files and other various odd programs in a folder labeled QooBox. Is that normal or another way this pernicious infection is keeping me from using my computer?!

    Please help guide me through this, and I'll never let my kids on my computer again (well, at least not without watching them like a hawk)!!

    Thank you,

    Amy
     
  2. redoakflower

    redoakflower Private E-2

    I attached the logs, but do not see them now in my original post.
     

    Attached Files:

  3. redoakflower

    redoakflower Private E-2

    Ran Read and Run

    I wish I could locate an edit option.

    I ran combofix in safe mode and it worked so I was then able to run the ReadMe in the correct order (except for SAS, which still hangs up in download).

    Attached are the new logs.


    ------

    I put another 512 card in my computer once it was cleaned, but I still cannot access the internet via my browser (which was my first sign I had a problem). I can, however, play games and such (and get my LOTRO fix :-D).

    Should I just download IE again, or is there still something nasty hiding in secret files waiting to pounce when I least expect it?

    Thank you all SO much for all the help!


    Edit: Hey! I can edit this post, but there is no button on the first two posts (maybe I've come up in the world).
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    Did you agree to the Trend Micro Hijack this license agreement as I am not seeing a log from hiijackthis.

    Could you please do the following whilst I review the rest of your logs:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and attach the log that it generates into your next reply.

    Thanks
    Kes13!
     
  5. redoakflower

    redoakflower Private E-2

    When I tried to run it I got an error:


    FYI: This is the same error I was getting for Internet Explorer when I tried to use it (thank heavens for FireFox). When I tried to remove IE from my computer, I couldn't find it in the Add/Remove programs, nor could I delete its file.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2. Please go to Add/Remove Programs and uninstall the following older version of Java:

    • Java 2 Runtime Environment, SE v1.4.2_03

    3. Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\atamifet.dll
    c:\windows\ijegutag.dll
    c:\windows\owerohugewuxi.dll
    c:\windows\agepiwamikuxiyay.dll
    c:\windows\osogakus.dll
    c:\windows\arorucatofo.dll
    c:\windows\Grisihaf.dat
    C:\1557958094
    C:\WINDOWS\initages.dll
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Pqeluqiyukeb]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\temp

    5. Now we need to replace a missing file, to do this please see the below:

    Running SFC Scannow


    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited by a moderator: Aug 15, 2009
  7. redoakflower

    redoakflower Private E-2

    Thank you so much, Kes!

    Attached are the logs.

    I ran into a little problem when running the SFC scan, since I couldn't locate my Windows CD (I found my user manual and all sorts of paperwork, but I must have put the discs someplace "safe"). When it asked for me to install the CD, I would click cancel and it would continue scanning. I 'skipped' 13 files in this way. (I wonder if Microsoft or Dell would send a replacement disk if I send them my product key - I do have that at least!)

    Again, thank you so much for the help.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Your logs look clean. Let me know if any problems remain and if not I shall give you the final steps in my next post. :)
     
  9. redoakflower

    redoakflower Private E-2

    I just want to say again how very much I appreciate your guidance. I've learned so much about how to protect my computer from Major Geeks, and I am so grateful for the clear, step-by-step instructions for the less-technically-savvy folks like me. I am thankful for knowledgeable folks like you who understand that ignorance does not equal stupidity and for your willingness to educate without arrogance. Thank you!

    Everything seems to be running as it should now, except for my Commodo won't update. I figure I'll pester the Commodo folks about that once we finish the final steps here, since it is most likely a software issue (or Amy not understanding something about the software, most likely!!).
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome :) safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds