SUPERAntiSpyware log file (step 2 of Win XP Cleaning procedure)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chuckrrm, Apr 14, 2008.

  1. chuckrrm

    chuckrrm Private E-2

    Hi thanks for your attention.

    my problem it's that when i enter my pc or my documents or explorer the AVG antivirus pops up a window saying that a trojan horse generic10.het was found on system32/comre.dll

    i'm in step 2 of windows cleaning procedure so i've already made the SUPERAntiSpyware scan and here is my log file so please tell me if it's ok to delete all of this files in quarantine.

    thanks you are a very professional people.
     

    Attached Files:

    Last edited by a moderator: Apr 15, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can delete them from quarantine ....but you need to finish the instructions and attach the other requested logs. :)
     
  3. chuckrrm

    chuckrrm Private E-2

    thanks! ;)
    ok here is the log file of the Malwarebytes Anti-Malware scan.

    Malwarebytes' Anti-Malware 1.11
     

    Attached Files:

    Last edited by a moderator: Apr 15, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. chuckrrm

    chuckrrm Private E-2

    well i made finally the last 2 steps and here is the log's files.
    thanks for your help! ;)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Make sure this is cleaned:
    C:\Documents and Settings\Ruben\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  7. chuckrrm

    chuckrrm Private E-2

    thanks! things are going well, no more messages from the antivirus warning me of a thread when i open my pc or the internet explorer.

    so can i delate all the files on quarantine from superantispyware? or i should leave them.

    here are the log files from Avenger and MGlogs. ;)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Okay there are a few stubborn items hanging on that we need to get removed. Let's try a different approach.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Continue by downloading a tool we will need: Process Explorer

    Extract it to its own folder somewhere that you will be able to locate it later.


    Now Run Process Explorer

    In the top section of the Process Explorer screen double click on explorer.exe to bring up the explorer.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of the comre.dll file (if found) and then click the kill button. After you have killed all instances of comre.dll under explorer.exe click ok. (If you do not find this DLL, just continue on.)

    Now just exit Process Explorer.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  9. chuckrrm

    chuckrrm Private E-2

    apparently things are going well. i made everything step by step and the process explorer couldn't find the comre.dll so i made the analyse and only fixed the comre.dll file also i double clicked the registry file on my desktop and ran the avenger. but when i rebooted my pc the avenger log file says that those files are access denied.:confused

    and this folder C:\Documents and Settings\Ruben\Local Settings\Temp\ isn't clear at all i cannot delate all the files because it says that they are in use.

    here are the log files.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The little bugger is being difficult...reboot into safe mode then do my previous fix after making sure ALL anti-virus and spyware programs are disabled.

    The go back to normal mode and see if you can locate:C:\WINDOWS\system32\comre.dll
    using windows explorer.

    Now Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Attach a new MGLogs.zip
     
  11. chuckrrm

    chuckrrm Private E-2

    hi, i made everything in safe mode but the comre.dll file doesn't appear on the process explorer. it seems that this bug doesn't want to disappear.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...let's see if this will remove it:

    Please download and run Counterspy.

    Then attach the log.
     
  13. chuckrrm

    chuckrrm Private E-2

    here is the log file of counterspy.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That may have wiped enough to be able to remove that file now...run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
    But first run the Avenger fix from my previous post.
     
  15. chuckrrm

    chuckrrm Private E-2

    bad news the avenger log says the same "access denied". should i delete all the files from quarantine of the counterspy then do the process again? :confused
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm wondering if we have a stuck permission ....download and run Prevx1. First use windows explorer to find the file and right click it / properties / and see if there is a permissions tab.

    You may uninstall Counterspy.
     
  17. chuckrrm

    chuckrrm Private E-2

    there isn´t a permission tab. i´ve already execute the prevx 2.0 and it says that my pc is running safe and secure with no issues.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I think we are safe to say you are clean. I've found conflicting info on that file, so I would be inclined to leave it and see if you have any problems. You can always come back to this thread if you do have issues.

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  19. chuckrrm

    chuckrrm Private E-2

    thanks very much! ;)

    well my pc seems to work fine and there is no more problems at the moment. one more thing. can i delate this applications?

    cccleaner.
    Malwarebytes' Anti-Malware.
    Prevx2 (this at the start comes a popup telling me that the license has expired)
    ProcessExplorer
    Spybot - Search & Destroy
    SUPERAntiSpyware
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can uninstall all of them if you want ....though I find them to be useful when the need arises.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds