Tried to use instruction to remove malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rbasp, Apr 6, 2011.

  1. rbasp

    rbasp Private E-2

    I used the instrutions posted here to remove a infections from my computer. I beleive I was successful but when I used the Combo Fix I must have used the version with the glitch and deleted several program files (e.g. all of my office, Turbo Tax, etc.). I saw you all have been able to assist other folks with this and hope you can help me as well.

    Thanks in advance,

    Hopeful in MD....Bob
     
    Last edited: Apr 6, 2011
  2. rbasp

    rbasp Private E-2

    Sorry for not attaching the logs produced trying to remove malware. I have attached the following logs:

    Hijack This.
    SASlog.
    ComboFIx log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are using an old version of combo. Please download a current version from the Read and Run First instructions. We also need these logs:
    MBAM
    RootRepeal --- if it runs
    C:\MGLogs.zip --- from running the C:\MGTools.exe

    Also attach the C:\Qoobox folder.
     
  4. rbasp

    rbasp Private E-2

    Thanks and sorry about not catching my error. I have included the following:

    MBAM
    C:\MGLogs.zip (from running the C:\MGTools.exe)
    C:\Qoobox folder.

    RootRepeal --- Did not run. In addition to losing programs and files, my computer will not read a cd/dvd (tells me to load a disk), complete a micrsoft update, complete a search for files.

    Thanks for your help...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your add/remove list is missing in the newfiles log. Did you once have AVG Anti-Spyware Clean Driver installed? If so, it is broken.

    It looks like the scans took care of most of it. Let's just remove a few leftovers:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\32788R22FWJFW.1.tmp
    c:\documents and settings\Alexandra\Local Settings\Application Data\Xjowo.bin
    c:\documents and settings\Samantha\Local Settings\Application Data\Xjowo.bin
    C:\Program Files\Common Files\AntiVirus\SBAMSvc.exe
    C:\WINDOWS\Uwohodo.dat
    C:\WINDOWS\Xjowo.bin
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  7. rbasp

    rbasp Private E-2

    thanks. I will start the process when I get home. One more question. Last time I tried to run ComboFix the program detected my Avanquest System Suite 11 software and instructed me to disable it. I lost the desktop icons so I don't know what files to select on my c:drive to launch so I can disable it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not familiar with Avanquest System Suite 11 so I am not sure how to disable it. You might want to uninstall it until we are finished.
     
  9. rbasp

    rbasp Private E-2

    :) I was able to run the ComboFix and MGTools successfully. I have attached the ComboFIx and MGlogs logs. Search is working. Computer runs faster so all is good there but I still have lost program files. I still haven;t recovered Microsoft Office 2007 programs, TurboTax 2010 etc. I had about probably 70+ programs that are no longer visible in start programs. Any thoughts about recovering them?
     

    Attached Files:

  10. rbasp

    rbasp Private E-2

    Just finished with TDSSKiller. No malicious objects found! :-D I have attached the log. Thanks for all you have done and your patience will doing so.
     

    Attached Files:

  11. rbasp

    rbasp Private E-2

    Just wanted to ensure you knew I still haven't recovered Microsoft Office 2007 programs, TurboTax 2010 etc. I had about probably 70+ programs and files that were apparently deleted when using the 1st version of ComboFIx I used. Any thoughts about recovering them?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is no evidence in your Qoobox log to show that Combo removed any programs. I am at a loss as to what may have happened to them. One suggestion would be to go back to a restore point before you started all this. You would have to download all the scanners again, but it may be easier to do that than to try to restore your programs. We could then remove the malware without running Combo.
     
  13. rbasp

    rbasp Private E-2

    I believe it happened when I used ComboFix the first time using the older version with the glitch. Let me check to see if I have the log for that iteration. In the meantime I will try to restore to an earlier point. Thanks.

    I included the first ComboFix file ealier in this thread (ComboFix2.txt) and have attached the second here (ComboFix3.txt) to see if that can help figure out what went wrong.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log also does not show any programs removed. Let me know if you can do a restore.
     
  15. rbasp

    rbasp Private E-2

    Unfortunately no I can't. Restore function is not found. I can see the restore points just don't know how to use one without the function. I was informed by my significant other that the computer had a chckdsk dialoge start show up and ran. Could this have been the cause? Is there a way to use the restore points? Thanks..
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post that question in the software forum. They can help you try to do a system restore. You may need to use the Recovery Console to do that. If you are successful, come back to this thread so we can check for any restored malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds