Need help, completed cleaning procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cyberjuda, Feb 18, 2009.

  1. cyberjuda

    cyberjuda Private E-2

    The problem started when I opened an attachment from someone who I thought i trusted. The problems have not stopped since then. I went through the whole procedure and installed/ran everything and am attaching the logs. The problem i am currently having is that after logging in i get lots of Data Execution Prevention error and have to start explorer manually by running Task manager. Thanks a lot in advance
     

    Attached Files:

  2. cyberjuda

    cyberjuda Private E-2

    Last of the logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a new form of malware which we are seeing more of.....unfortunately it infects system files ( and the backups in your i386 folder) so that if we tried to remove them, your system would be unbootable. I am going to give you a few things to remove that may allow you to then copy your data and files to a cd before you reformat and reinstall your OS.

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. cyberjuda

    cyberjuda Private E-2

    Sorry i forgot to mention this before but on running mgtools I got the Process DLL error and then tried installing NET framework but it does not install. The donetfix just extracts the file and then disappears. I tried multiple times without any success.

    New logs attached.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's not a problem.....we are just trying to get the obvious malware removed so you can save your data and files before you reformat. :(

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  6. cyberjuda

    cyberjuda Private E-2

    Wait did you say reformat? :cry
    Oh well that was what i was afraid of. Attaching new files.
    Thanks and I really do appreciate your help. :)
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.....sniff, sniff...:cry I did say reformat. Look at your combo log. That indicates just two system files that are infected and from what we have seen, this means that none of your system files are trustworthy. We could have you replace them from your xp cd, but there are just too many to make that an alternative.

    So copy your data and files to a cd.......then reformat. :(

    You could try doing a system restore to a point way before this infection....and then run the scans again to see if that worked.
     
  8. cyberjuda

    cyberjuda Private E-2

    Oh well. I suppose I'll reformat since the restore option doesn't work. Will reformatting C partition work or do i have to reformat the whole hard disk?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to just reformat the C drive which is where windows is located. After the reinstall to that drive, run the tools again so we can be certain.
     
  10. cyberjuda

    cyberjuda Private E-2

    ok thanks a lot. It's getting late here. Will do it on the weekend and hopefully post here a clean log.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.....we'll be here. :(
     
  12. cyberjuda

    cyberjuda Private E-2

    Well I reinstalled windows and ran the read me first guide on the forum up till malwarebytes check and found no errors :D. Do you still recommend running combofix and MGtools or are they not necessary? Secondly I am using AVG free as antivirus protection. Would you recommend keeping Superantispyware or is AVG enough?

    Thanks again for all your help!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would recommend keeping both SAS and MBAM and run them on occasion as backup scanners. If you partitioned, make sure you include them in the scans. You can remove MGTools.exe, MGTools folder and the MGLogs.zip as well as ComboFix.

    You are welcome.....and I hope you do not run into this problem again. :)
     
  14. cyberjuda

    cyberjuda Private E-2

    I spoke too soon. :( Reinstalled windows once again and attaching the logs.
     

    Attached Files:

  15. cyberjuda

    cyberjuda Private E-2

    MGTools log.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you mean by you "installed windows again"? Did you do a repair install or did you reformat the hard drive and install? DOing a repair installation when you have malware ( which you don't) will not remove the malware.

    Your logs are clean....MBAM found one item, which is typical depending on your surfing habits. And it is why we suggest you keep it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds