Malware scans completed..attached log files to verfy cleaned

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tones_ie, Jun 30, 2008.

  1. tones_ie

    tones_ie Private E-2

    Hi guys,

    first off, wanna say thanks in advance for the help i got from the very detailed tuts om malware removal...specially here
    http://forums.majorgeeks.com/showthread.php?t=139313

    OK...so followed all steps and wanted to see if i actually did get rid of all the crud the pc had running !!

    Ran all the recommended softwares..and attached 3 logfiles... Combofix / superantispyware / MgTools


    Thanks in advance for any assistance :)

    Please advise as to what speps i need to take now :)
     

    Attached Files:

  2. tones_ie

    tones_ie Private E-2

    Opps..almost forgot...heres teh mgtools zip also....


    thanks guys
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Next time please follow instructions properly. You must not put MGtools.exe into the below folder.

    C:\Documents and Settings\Owner\Desktop\++major geeks ++\MGtools.exe

    In fact it is a bad idea to use special characters like that in folder names. It could cause some tools to fail to work. MGtools ran okay this time but please be sure to follow instructions in the future. We specified that it must be save to C:\MGtools.exe In some cases, it will not work properly unless stored there.

    We also requested that ComboFix.exe be renamed to combo-fix.exe and that it be run with a special command from the Start, Run box. You did not rename it or run it properly. With some forms of malware, this would cause combofix to fail. The success of our procedures depend on you following the instructions properly.




    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {6A5236DD-104E-4FAA-9697-6E42D5D6E954} - c:\winnt\system32\clbcatexm.dll
    O2 - BHO: (no name) - {8A38CA39-2F42-4F42-A769-63978F52BB94} - C:\WINNT\System32\dgsetupd.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKUS\S-1-5-18\..\Run: [SrvC] c:\j.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [SrvC] c:\j.exe (User 'Default user')
    O20 - Winlogon Notify: nvqhibjz - C:\WINNT\SYSTEM32\clbcatexm.dll
    O23 - Service: Print Spooler Service (ryqyaul9u64h8) - Unknown owner - C:\abc.exe (file missing)
    O23 - Service: Microsoft sdk core (sdk) - Unknown owner - C:\WINNT\lsass.exe (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. tones_ie

    tones_ie Private E-2

    Hi chaslang :)

    First off...thank you soo much for taking the time to go through the logs and create user specific fixes for my situation...TRULY appreciated.

    Not that you wanna hear excuses :) but regards not following instructions...lol I actually did..to the letter BUT the files i needed to do teh scans i copied into that major geeks folder...then followed instructions to place em where they needed to go outside of the folder...
    (heres the excuse..lol) BUT then i got called away just before i ran the scans by the kids...and it was 3 hours before i could get back to do the work..

    the major geeks folder was open and i completely forgot to run the tools from the other locations.. !!!! * sigh :)



    OKies, did as requested....all worked just fine..even the fixme.reg file..got a confirmation it was added to registry

    please see attached requested logs...


    since my initial post and ure reply, i had updated m/soft to sp3...and as i thought the pc was clean (or at least cleaner) i went and tried to install norton 360 (yea i know...its a friends pc and this is what he bought)

    anyways, it seems to install...but then when pc reboots the task bar icon for norton dosent appear...if the icon to launch norton is run from programs or desktop nothing appears...Im unsure as to whether it was because i still had some stuff to remove or an issue with sp3...

    so i uninstalled norton and then sp3 (as it stands now its fully patched up to but NOT including sp3) so im going to try and install norton again and see if it goes in ok, once im done posting here...ill let u know how that goes..

    Back to ure questions...after rebooting the pc (when everything was finished) Out of curiousity, i ran the analyse.exe one more time just to check to see if the entries u asked me to check mark and remove where infact gone..i did not do anything other than look through the entries...

    all were fixed except for the 2 below
    O23 - Service: Print Spooler Service (ryqyaul9u64h8) - Unknown owner - C:\abc.exe (file missing)
    O23 - Service: Microsoft sdk core (sdk) - Unknown owner - C:\WINNT\lsass.exe (file missing)


    Again , thanks for the assistance in the removal of these nasties...really appreciate it. Seems u must be a very patient person :)

    Ill not alter or add / remove any other software (other than norton) untill i hear from u
     

    Attached Files:

  5. tones_ie

    tones_ie Private E-2

    Not trying to bump...promise...but wanted to post and give my findings regards the Norton 360 prob....

    Ok...so i uninstalled SP3....updated all latest securtiy patches...installed norton 360

    It installed "ok" like before....and again, had no taskbar icon..this time however the desktop and program icon DID launch the control panel...

    Once loaded it told me i had a problem with my browser not being able to detect fradulent websites !!..click "fix" to sort the prob...clicking "fix" did nothinmg.

    After searching online for possible solutions i found a few others with similiar probs...their solutions didnt work for me. Even running the inbuilt support feature didnt work...it found 2 or 3 probs...and fixed 2..was unable to fix "auto protect files and folders".. !! *sigh

    So, i decided to try firefox to see if itd stop the unable to detect fraduklent website thingy......downlowed latest..installed...set as default browser....restarted pc.

    Whoilaaaa....norton loaded fully this time... no error in the console about browser unable to detect fradulent websites...ran updates fine...and even has the taskbar icon sitting in the tray :)

    So while norton was "maybe" protecting me...i wasnt sure cos of no icon verfication and was unable to load console...(till after firefox install)

    Soo....just for kicks...i uninstalled firefox and rebooted pc to see would IE spit out the dummy again about frudelent websites...It didnt ! and norton loaded fully..no errors in console...

    The only prob i see with IE now, is it will not load the toolbar plugin (IE >> View >> Toolbars >> Show Nortontoolbar) for norton no matter what i do...

    So with the only known issue being the toolbar addon..i decided to load SP3 on....


    I honestly have no idea what was wrong initially and what stopped norton from getting installed and running correctly...
    Previous spyware ? IE and Norton conflict ? Gremlins ?

    With it installed now i decided to load SP3 on and see what happened....All works as before...no errors except for the toolbar addon (can live with that)

    So yea, thought id post my "weird" findings in case it was able to help someone else...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Very bad idea. Too late now but for future reference, you should never do updates (especially major updates like this ) to Windows while a PC is infected. Quite often this will lead to a failed or partial update and open up a whole new set of problems having nothing to do with malware but with your Windows OS. And as the rest of your message notes you ran into some problems, it may or may not be related to malware.


    This may be due to the fact the ComboFix did not run properly as seen in the log. Did you notice and error messages or did any strange behavior occur.
     
  7. tones_ie

    tones_ie Private E-2

    Noted :) ill remember that for future reference...

    Nopes..didnt notice any error messages it "seems" to be running ok now...

    do u need to see any other scans? or should i start uninstalling the fix tools...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After looking at your logs let's see if we can fix the remaining items I see. Having Norton 360 installed now my cause trouble. If you see any popups warning you about scripts...etc trying to run, make sure you allow them since it will be what we are trying to fix.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Print Spooler Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Services (if you do not find them or get any errors, just continue):
      • Microsoft sdk core
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ryqyaul9u64h8 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
      • sdk
    • Now exit HJT but do not reboot when if it tells you it needs to. We will do that further down.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot please run ComboFix again using the instructions in the original READ & RUN ME step.
    ComboFix may or may not cause another reboot.

    After running ComboFix, now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\combofix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. tones_ie

    tones_ie Private E-2

    Hi :)

    Before working on pc i disabled internet and disabled norton auto protect

    Both services were stopped already..so i disabled them and received no errors deleting both services.

    combofix would not allow me to rename it to requested file name (combo-fix.exe)...error said i must use alphanumeric chars...so please note i left default name as is..

    Ran combo fix and it did reboot...just before it shut it down i got the following popup message...

    ccSvcHst.exe application error....the instruction at "0x69532c87" referenced memory at "0x00000000". the memory vould not be read

    i clicked OK to continue...

    Ran rest of requested scanners and attached logs as requested. (had to zip up combofix one..it exceed file size allowed for that file type)

    Again, thank u soo much for the help...really appreciated.

    Gotta ask, untill this week...ive never ever gone into this much dept cleaning a pc...i used to think i had a little knowledge to help friends out till i hit a wall with this one that is...but ive always just used the scanners to try fix probs..and maybe hijackthis. I suppose my question is, had i just used scanners and not done all u asked am i asking for trouble? would i have been reinfected....
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    Yes!

    You forgot to tell me how things are working. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. tones_ie

    tones_ie Private E-2

    Did all the above...and all seems to be running ok. Thanks a lot for ure time and patience helping me out.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds