Completed XP Cleaning Procedure - Logs Attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by johnboy777, May 14, 2010.

  1. johnboy777

    johnboy777 Private E-2

    Thank you for your help. Three days ago my computer started redirecting all search engine results. The computer is also noticeably slower of late.

    I completed the entire read and run me process, with the exception of combofix. I repeatedly tried to run combofix, however it would lock up the computer. It would show a green progress bar which would fully progress, but then not ever move beyond that. I would be forced to power off / on the computer.

    Thanks again to those so generous with their time.

    Best,
    John B.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. This is seen on your desktop, what is it? Combofix renamed?
    2. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    3. Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    4. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    7. How is the computer running now?
     
  3. johnboy777

    johnboy777 Private E-2

    Kestrel13! Thank you!

    1. Yes, ASDF123.exe is combofix renamed.

    2. Ran TheAvenger as directed. Upon reboot I got a dialog box titled "Windows- No Disk" Contents of the message were "Exception Processing Message C0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c" I clicked Continue. Avenger Log Attached.

    3. Successfully edited the registry.

    4. Ran TDSSKiller. It found an infection but never gave me the option to delete. Log Attached.

    5. Deleted all temp files (and folders) other than 5/15/10

    6. Ran MGTool/getlogs.bat. Log attached.

    7. Searches are still being redirected. Perfomance seems a bit better, but hard to say.

    Thank you again for your kind help.

    John
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, seems it could not find a backup copy of the file that is infected, and neither can I. Let's dig a little deeper...

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      iaStor.sys
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  5. johnboy777

    johnboy777 Private E-2

    System Look log attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahhh, now I have what I was looking for. :)


    FILE COPY

    Please do the following:

    1. Click on the Start button, then click on Run...

    2. In the empty "Open:" box provided, type cmd and press Enter
    • This will launch a Command Prompt window (looks like DOS).
    3. Copy the entire bold text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).


    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.

    5. Press Enter.

    6. When successful, you should get the below message within the Command Prompt:

    • "1 file(s) copied"
    7. NOTE: If you didn't get this message, stop and tell me first. Executing any following instructions (with avenger) are dependent upon this file being successfully copied.

    8. Exit the Command Prompt window.



    AVENGER

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how the machine is behaving.
     
  7. johnboy777

    johnboy777 Private E-2

    Machine locked up on reboot from avenger. Had to power it off. Second reboot successful, and !No more redirects in IE!

    MGlogs.zip attached.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. OK, now run TDSSKiller again as per my previous instructions.

    2.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. johnboy777

    johnboy777 Private E-2

    Completed as instructed
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, looking better. Now I want you to rename ASDF123.exe (combofix) to kestrel.com. Try in safe mode if normal mode still gives you grief. Attach the C:\combofix.txt into your next reply if successful.
     
  11. johnboy777

    johnboy777 Private E-2

    I used Safe Mode (without networking) so was unable to have Combofix install MS Recovery Console. Should I install it manually?

    Log attached.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not to worry about that now, although you can do so if you like as if you ever run into trouble in fuuture it could help.

    Your logs look clean. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. johnboy777

    johnboy777 Private E-2

    Kestrel13!, thank you! :celebrate I am more appreciative than you know for your generosity with your time and knowledge.

    I completed the final steps, got rid of McAfee, and installed Avast A/V, Comodo Firewall, and the recommended items from the "Protecting yourself from Malware" page.

    One thought crossed my mind...everything we did was in one of two user accounts on my machine. Do I need to run any scans in the other user account? It is not one I ever use, but it is on the machine.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you like you can run the scans on the other account, it wouldn't hurt to do so. Attach logs here into this thread with the title 2nd user account. :)
     
  15. johnboy777

    johnboy777 Private E-2

    Dear Kestrel,

    Over the last few weeks I have thought many times about how much I appreciate your help and generosity with your expertise. You helped me as a complete stranger with no chance to gain a thing from doing so. I appreciate your kindness.

    Best regards,
    John
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It is so nice to see a sincere thanks such as this one from yourself. :) Glad you are running okay still, and I very much appreciate the recognition.

    Kes13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds