Finished Scans, but RR wouldn't run

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Midnight PhoeniX, Oct 24, 2010.

  1. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    Hey Everyone,

    I decided to run the cleanup after this laptop got a hiloti.gen.g trojan. I ran all the scans except for RootRepeal because it wouldn't scan. I think it said there was an error of some sort. But here are the logs that I do have. Thanks.
     

    Attached Files:

    Last edited by a moderator: Oct 30, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Users\UserName\AppData\Local\Gvuyuj.dat
    C:\Users\UserName\AppData\Local\Vfenecatevihep.bin

    Otherwise, I am not seeing any malware in your logs. You should download and install SP1 and SP2.

    Tell me what malware issues you may still be having, if any.
     
    Last edited: Oct 30, 2010
  3. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    Thank you for your help. I deleted the two files as you said to. But when I searched for C:\Users\UserName\AppData\Local\Gvuyuj.dat, it opened the file in GomPlayer. Is that bad for it to have opened like that?

    Also, do you know if malware has anything to do with the fact that the memory keeps shrinking for no reason? I clear cache and everything, but most times I'll have like 2 gb and then it'll go down to less than 1 gb. Could that be a malware related issue?
     
    Last edited by a moderator: Oct 30, 2010
  4. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    Sorry for a double post, I can't figure out how to edit my previous post. But I'm trying to download SP1 and SP2, but the downloads won't finish. They stall halfway and just stop. Is there a way around this? I don't know what the problem is, but I think it might have to do with Road Runner.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall using Add/Remove programs:
    Java(TM) 6 Update 20
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\programdata\SPL8492.tmp
    C:\Windows\DUMP3e08.tmp
    DirLook::
    C:\ProgramData\App4rTemp
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Oct 25, 2010
  6. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    I'm sorry, but I had not done the steps you have given me because right after I turned on the laptop, McAfee had detected ComboFix as a trojan and removed the file. This hadn't happened yesterday or earlier today, so I am unsure if I should re-download ComboFix and proceed with your instructions. Please let me know if it would be okay to go ahead and download ComboFix again. Also, I had already updated Java yesterday after I realized that I had completely forgotten to update it prior to doing the READ & RUN ME.


    Here is the message McAfee had given me regarding the trojan:

    McAfee has automatically blocked and removed a Trojan.

    About this Trojan
    Detected: Artemis!3663390D2E11 (Trojan), Artemis!3663390D2E11 (Trojan)
    Location: H:\FIX\ComboFix.exe

    Trojans appear as legitimate programs but can damage valuable files, disrupt performance, and allow unauthorized access to your computer.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is why we ask that you disable your AV software before running ComboFix. Yes, download it again to your desktop, no where else and then do the fix after you have either disabled or uninstalled McAfee.
     
  8. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    Here the logs. But now I have another problem, I cannot open any file or programs on the laptop. Instead now I get a message stating:

    "Illegal operation attempted on a registry key that has been marked for deletion."

    How do I fix this problem? I can only transfer files to a usb drive, but other than that, I can't do much else and I'm afraid that restarting the laptop will cause it to not start up again. Please help if possible.
     
    Last edited by a moderator: Oct 30, 2010
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. A reboot should clear that message. Once you do that, let me know what issues you may still be having, if any.
     
  10. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    Thanks! That did help. Just one last thing, I get a message saying that some Startup programs can't be started or were blocked. Any way to fix this? Other than that, everything seems to be working fine now.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What programs and / or what is blocking it?
     
  12. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    I just took a look at it and I think it was just the Malwarebytes Anti-Malware program. I just clicked on the run program for it and now the message doesn't show up anymore. So hopefully that was the problem.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  14. Midnight PhoeniX

    Midnight PhoeniX Private E-2

    I just did everything you put down. Thank you very much for your help. I just have a small request to make, do you think you could edit the posts on this thread to remove the <snip> parts? I'm just concerned about any privacy issues. Thanks very much again!
     
    Last edited by a moderator: Oct 30, 2010
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Removed user names and logs per your request. And you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds