Logs attached and still problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DollieTx, Mar 3, 2010.

  1. DollieTx

    DollieTx Private E-2

    My problem started last night. Ran the tests needed, that it wld let me run. Here are the logs.

    I'm new at this so let me know if I did something wrong. Thank you.
     

    Attached Files:

  2. DollieTx

    DollieTx Private E-2

    I posted the wrong MGlogs file. Sorry, so will post when needed.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You attached the right MGLogs.zip, you just didn't make the agreement to run HJT when it popped up.

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    RenV::
    C:\Documents and Settings\Me\rundll32 .exe
    c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
    c:\program files\AIM6\aim6 .exe
    c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
    c:\program files\AWS\WeatherBug\weather     .exe
    c:\program files\AWS\WeatherBug\weather    .exe
    c:\program files\AWS\WeatherBug\weather   .exe
    c:\program files\AWS\WeatherBug\weather  .exe
    c:\program files\AWS\WeatherBug\weather .exe
    c:\program files\Carbonite\Carbonite Backup\carboniteui .exe
    c:\program files\Common Files\Java\Java Update\jusched .exe
    c:\program files\Common Files\Nero\Lib\nmindexstoresvr .exe
    c:\program files\CyberLink\PowerDVD\pdvdserv .exe
    c:\program files\CyberLink\PowerDVD\Language\language .exe
    c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
    c:\program files\Malwarebytes' Anti-Malware\mb .exe
    c:\program files\Siber Systems\AI RoboForm\robotaskbaricon .exe
    c:\program files\SUPERAntiSpyware\superantispyware .exe
    c:\program files\VIA\VIAudioi\HDADeck\hdeck .exe
    
    AtJob::
    
    File::
    c:\windows\_VOIDxtfgntrfio
    C:\Documents and Settings\Me\rundll32.exe
    c:\windows\system32\luwuvozo.dll.tmp
    c:\windows\system32\selekide.dll
    c:\windows\system32\tomewope.dll
    c:\windows\system32\watajupu.dll.tmp
    c:\windows\system32\wavuzela.dll.tmp
    c:\windows\system32\zuvusibo.dll
    c:\windows\system32\fuyisajo.dll
    c:\windows\system32\tomewope.dll
    C:\WINDOWS\system32\zuyapiyo
    
    Folder::
    c:\windows\_VOIDxtfgntrfio
    C:\Documents and Settings\Me\Local Settings\Application Data\s3C7F
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5f5ca3cc-d031-4034-a1e3-b5969ecfdd99}]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "mifonafih"=-
    "SunJavaUpdateSched"=-
    "sodafawutu"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds