Malware Double check

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by scott ej, Feb 5, 2009.

Thread Status:
Not open for further replies.
  1. scott ej

    scott ej Private E-2

    Guys,

    Tried removing Malware on my own but got stuck trying to remove the virtumonde bug. Did the Read & Run First instructions. I think I got every thing but would like to double check. Could someone review my logs and let me know if all is well.

    Will add remain log on next post.

    Thanks,

    Scott ej
     

    Attached Files:

  2. scott ej

    scott ej Private E-2

    Last of the logs. Looking forward to wrapping this up. At it for 2 days. Can't wait to move to the final steps of Read & Run First.

    Helpful Eyes Greatly appreciated.

    Scott ej
     

    Attached Files:

  3. scott ej

    scott ej Private E-2

    Malware log checked

    I think I may have posted this incorrectly the first time.
    Followed the Read and Run first procedures. Would like someone to take a look at my logs to see if i did everything correctly. Have attached 3 logs will send the fourth when told to do so.

    All help appreciated.


    Scott
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below software:
    Spybot - Search & Destroy 1.4 <-- old version and new version is already installed
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Your J drive is infected. I assume it is a removable device. It will infect any PC you plug it into. You need to plug this removable device in now before starting the below so that it can attempt to clean it up.


    You are way out of date with your version of SUPERAntiSpyware. Just to be safe, let's get the new version installed and run new scan.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the new SUPERAntiSpyware log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. scott ej

    scott ej Private E-2

    Chaslang,

    Thanks for taking a look at this for me. Unfortunately I have made a major goof. This being my first post I assumed (in error) after 2 days no one was going to look at it because I had frelled up my second post. I would have been glad to wait 4,5,6 days if I knew someone was looking. This is the first time I have checked email this week.

    The machine belongs to an 80 year old friend and I have returned it hoping all was well. Obviously not. If the J removable drive is infected then all 5 machines I own (putting together a lab in prep for Microsoft tests') are compromised.

    I have a laptop that is clean that I can let her use until I resolve her problem. I will be glad to rerun the read me procedures incorporating all of the steps that I missed with the J drive inserted. Then do the SUPERAntiSpywear and remaining listed procedures if you can still give me a hand. I will check email twice a day every day. Awaiting instructions on how you want me to proceed.

    Will SUPERAntiSpyware by itself remove the infection on the J drive?

    Scott ej
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually my response was only 31 hrs and 4 minutes after your last post. Significantly less than even two days which is quite fast these days considering that malware is infecting PCs at rates greater than 10 to 20 times faster than it did even a year ago.

    Quite possibly yes. They may or may not be and the only way to know for sure is to check. But the removable drive was for sure.


    You can setup SAS to scan all drives but it may or may not find and remove this infection. The steps with ComboFix where trying to fix what I saw in the logs.
     
  7. scott ej

    scott ej Private E-2

    chaslang,

    Thanks for the reply. I have no problem with your response time. You are doing this on a volunteer bases. Your time is valuable and greatly appreciated. As a first time poster I noticed that the majority of people who posted after me were respond to within 24 hours and some within an hour or so of there post. An extremely small minority, myself included,

    ---We few. We unhappy few. We band of losers.--

    must have phrased our questions incorrectly, used an inappropriate word or did something else wrong. As a result of whatever we did we were not going to get a response. In my case there was the double whammy of also messing up the second post. I now understated the drill. A response will come. Some faster than others for whatever reason.

    I will follow your instructions and send back the info.
     
  8. scott ej

    scott ej Private E-2

    chaslang,

    What An Adventure!!! Followed instructions up to run combofix. Problems from that point forward. Combofix gave me warning that cmdagnet.exe was running and could cause problems with system. Stopped and did a Acroness backup just in case. Tried to kill the cmdagnet process via task manager. It said I didn't have permission to do so. Then tried Process Explored to shut down cmdagnet. No go. Eventually went to Services and set comodo help service to disable and rebooted machine. After boot then cutting off comodo. Was able to run combofix. Got the same warning but could see nothing running. Decided to go for it because I had an image. The rest of the procedure ran and files are attached.

    After much trial and error got through it. Should my procedure have been....

    Download new SUPER AntiSpywear along with updates. Do not run.
    Copy Regedit4 to notepad.
    Copy Killall to notepad. Save as CFscript.
    Download new copy of MGtools.
    Disconnect internnet.
    Shut down firewall (mine was comodo) and any real time antivirus.
    Start all procedures starting with SUPERAnitvirus scan.

    So, Attached are the files. How did I do?

    S
     

    Attached Files:

  9. scott ej

    scott ej Private E-2

    chaslang,

    Also see a lot of the attached. Been letting it through assuming it was part of the repair procedures.
    S
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install Comdo???? You are not supposed to be installing anything we do not ask you to install. See the up front important notes in the READ & RUN ME. In addition, you violated the one antivirus program and possibly one firewall rules now too which is also in those up front notes. You now have both Verizon Internet Security Suite and Comodo Internet Security Suite installed. Before doing anything else, you must uninstall one of these and then reboot. You may have potentially messed up security center by doing this. And in addtion, these may have blocked ComboFix from running properly.

    If the J drive was not inserted, it defeats part of the purpose of running ComboFix which was attempting to clean the J drive.

    No! My instructions said to run a full scan of your system and attach the log. The order in which instructions are written is how the need to be run.

    Not requested.

    Not requested at this time and you don't need to shut them down while running SAS. You do need to shut them down while running ComboFix as originally stated on the website instructions for using ComboFix.

    I think the above answers this.

    Manually delete the below folders, some of which are due to failed attempts at running ComboFix because of the security suites:
    C:\32788R22FWJFW.4.tmp
    C:\32788R22FWJFW.3.tmp
    C:\32788R22FWJFW.2.tmp
    C:\32788R22FWJFW.1.tmp
    C:\32788R22FWJFW.0.tmp
    C:\Program Files\Viewpoint
    C:\Documents and Settings\All Users\Application Data\Viewpoint
    C:\Program Files\Common Files\Symantec SharedC:\Documents and Settings\Amanda\Application Data\Viewpoint

    Also manually delete the below file:
    C:\WINDOWS\003153_.tmp

    Did you create the below task?
    C:\WINDOWS\Tasks\shutdown.job


    What program if any are you using to control startups? You have many many things trapped in MSconfig registry keys and we do not want anything being run that uses the MSconfig registry keys. This includes using MSconfig.exe itself and programs like CCleaner which use this registry keys and fail to mark the MSconfig state keys properly.

    We cannot continue until you address the above and then you will need to download and use the new version of MGtools to get a new MGlogs.zip file and attach it.
     
  11. scott ej

    scott ej Private E-2

    I did not add Comodo. As I mentioned at the start the machine was not mine. I had returned it to the owner based on my misunderstanding of how the forum worked. They added the firewall. Because the original scan had the J drive in place I made sure it was there before beginning to work on the machine. I have been using CCleaner to control startups. I do not use MSconfig to do this. But I did go to MSconfig to turn on normal startup before working on the machine. If there is a better program to do this whith please let me know. In retrospect I should have:
    1: Closed this thread because the PC was out of my possession.
    2: Started from scratch with a new thread.
    Sorry to have wasted your time. Let’s close this thread as resolved. I will return the PC to the owner with instructions to take it to a professional for resolution.
    I am now on board with the program. I will now start dealing with my personal machines. The J drive was my thumb drive and I will nuke and pave it. Again, sorry to have wasted your time. I will do better next time around.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They added a full security suite not a firewall. One of them must be uninstalled immediately.

    You should not be using CCleaner either as stated in step 1 of the READ & RUN ME which also explains to you what to do.

    So be it.

    They can also just come here themselves. ;)
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds