Suspected Malware - failed Run & Read Me

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cpq007, Jun 7, 2010.

  1. cpq007

    cpq007 Private E-2

    Hi, and thanks in advance for any help you can provide.

    My IP was put onto the XBL and PBL list, it said I had a rustock infection.

    I ran the Run and Read me process as described.

    I had no virus detected with SAS or Malware bytes, I have attached the CombiFix log.

    RootRepeal crashes repeatedly with no explanation why, a dialogue box comes up but the contents wont appear.

    MGtools wont run, it just says "MGtools.exe is not a valid Win32 application" - or something v similar.

    So I have no clue what's going on, there are no other symptoms. Any help you can provide would be appreciated :).
     

    Attached Files:

  2. cpq007

    cpq007 Private E-2

    Also I forgot to mention my Windows Firewall turned itself off and wont re start - this is not too much of an issue in that I run Zone Alarm but obviously suspicious. I also use AVG.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Never the less, I need to see the logs anyway :)

    RootRepeal only has a 50-50 chance of running. So not to worry about that.
    I need you to try renaming it to 123.com and then try again to run it. If normal mode is not successful then please reboot into safe mode and try.
     
  4. cpq007

    cpq007 Private E-2

    Wow thanks for your quick response, I am away on business at the mo, back on Friday 11th - sorry I wasn't due to head off, but I'll update ASAP. Thanks :)
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, I will be here waiting. :)
     
  6. cpq007

    cpq007 Private E-2

    Right attached here are the SAS, Malware Bytes and MGlogs

    Thanks!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any signs of this in your logs.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Just to cover all angles let's try this|:

    Rustock.b - msguard, pe386, & lzx32 RootKit Removal

    Running GMER to detect rootkits

    Post back with the results attached. :)
     
  8. cpq007

    cpq007 Private E-2

    Thanks for this.

    I checked my IP address on the XBL list and it says I am not listed now, but I never made steps to take it off until I had this issue sorted for fear of relisting???

    OK so I did get a success message on the fixME.reg thing.

    I have also attached the logs you requested below.

    Thanks Kestrel13 :)
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's good news. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. cpq007

    cpq007 Private E-2

    Hi there, running through the list my computer couldn't find the combifix file or the mgclean.bat files. I didn't remove them.

    Also I just wanted to say thank you for your help in walking me through all of this so far, it think it's great and a sure sign that there are some good people in this world!

    cheers
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If we used ComboFix, you can delete the

    • ComboFix.exe file
    • C:\ComboFix folder
    • C:\QooBox folder
    • C:\WINDOWS\nircmd.exe
    • C:\combofix.txt
    • C:\ComboFix-quarantined-files.txt logs that was created.

    And you are welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds