"XP Antivirus 2012" infection, pls check logs...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by insan_art, Aug 10, 2011.

  1. insan_art

    insan_art Private First Class

    Hello again.

    This time it's my in-law's computer. They got the good old "XP Anitvirus 2012" infection and all the bugs that come with it. I had started to clean this up almost 2 weeks ago but I had to stop short and make them wait because the MG site was down and I didn't have my instructions!!! :) In the meantime, my brother-in-law came in and "fixed" the computer by monkeying with everything that he was NOT supposed to (including messing with God knows what in the registry!). So, needless to say, the infection came back.

    Got through all the Run & Read Me very smoothly. I apologize, there were a few minor details in the beginning of the procedure that slipped my mind because I didn't have your handy dandy instructions to remind me (like updating Java - which has been done now). Logs are attached.

    Everything was running very nicely when I left yesterday, to the point where I told them they could check their email quick. Apparently after that some pop-up came up and their computer froze. My dad-in-law manually turned off the system and when he turned it back on he claims there was a windows error. I told him to turn it off and I am assuming/hoping it was just a hiccup and it will boot just fine for me when I come back to finish the malware removal procedure (I hope!!!!).

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's use ComboFix.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Administrator\Local Settings\Application Data\75pg32uc86hns2rqtr4c
    C:\Documents and Settings\Administrator\Local Settings\Application Data\ts4deip404
    C:\Documents and Settings\All Users\Application Data\75pg32uc86hns2rqtr4c
    C:\Documents and Settings\All Users\Application Data\tqxn.exe
    C:\Documents and Settings\All Users\Application Data\ts4deip404
    C:\Documents and Settings\All Users\Application Data\xtmg.exe
    C:\Documents and Settings\All Users\Application Data\nnwr.exe
    C:\Documents and Settings\All Users\Application Data\auna.exe
    C:\Documents and Settings\Administrator\Templates\75pg32uc86hns2rqtr4c
    C:\Documents and Settings\Administrator\Templates\hudc.exe
    C:\Documents and Settings\Administrator\Templates\hufr.exe
    C:\Documents and Settings\Administrator\Templates\jmcm.exe
    C:\Documents and Settings\Administrator\Templates\kslk.exe
    C:\Documents and Settings\Administrator\Templates\buwc.exe
    C:\Documents and Settings\Administrator\Templates\dbfv.exe
    C:\Documents and Settings\Administrator\Templates\phit.exe
    C:\Documents and Settings\Administrator\Templates\ts4deip404
    C:\Documents and Settings\Administrator\Templates\ttot.exe
    C:\WINDOWS\system32\terdvw32.dll
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. insan_art

    insan_art Private First Class

    Hello TimW! Always nice to get a reply from you! Thanks, but, I'm afraid that the puter is not booting through! Thankfully I called yesterday before going to work on it to make sure it was booting....and it did not. :( According to my mother-in-law (and over the phone, mind you) the error screen says something like "Windows could not start because of an error in the software - report load needed DLLs for kernel...." - again, that's what I got out of her over the phone.

    So, I'm not sure what to do next. I'm pretty angry at this point because I know that my brother-in-law messed something up while he was here. But, he lives 4 hours away and I live 10 minutes away, so of course, guess who gets to deal with the problem that HE created...lol.

    I know that they do have an XP disc so we can always wipe, BUT then there is the question about what do we do with their files? I have a hard drive reader, but at the moment I don't have a junk system to connect their infected hard drive to...so, I hope that there might be something to do to help before it gets to the point of a wipe and recovery mission... :)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can only suggest that you first try doing a repair install of xp. Are you familiar with doing that? Basically, you set the bios to boot to the cd/dvd player as first boot device, insert the disc and reboot. You will get a screen asking if you want to install ( after the license agreement ) and choose yes. Then it will find your previous install and you then have the choice to do a repair install ( the second time you have the option to press R ).

    Let me know if that gets the system back up and running.
     
  5. insan_art

    insan_art Private First Class

    Ok, sorry for taking so long to get back! And thanks for reminding about a repair. I was so angry at the situation before that I missed that simple answer. :)

    So, I will admit that I don't know what I'm doing at this point. I have done a repair before but that was a few years back and it did not involve using the Recovery Console. Unless I'm doing something wrong now, so far, I get to the command prompt in Recovery Console and that's where I'm stuck. I'm not sure which of the commands to use...I would appreciate any advice! I did look up instructions for the recovery console but I didn't find them very helpful!

    Thanks!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are hitting "R" on the first option which takes you to the recovery console. You need to instead hit install, then let it find your previous installation and then hit "R" for repair.
     
  7. insan_art

    insan_art Private First Class

    Der! :) Thanks TimW! I knew it had to be something simple like that. I'll get back with you as soon as I have a chance to repair and continue on with the removal process. Have a wonderful Friday evening!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You too!! Take your time. Me not going anywhere. ;)
     
  9. insan_art

    insan_art Private First Class

    Hi TimW. I apologize for dragging this out so long and for being intentionally so deliberate with my actions. I am trying to make sure I don't mess this thing up any further!

    So, was able to start the proper repair process. Everything seemed to go ok until the repair process wanted to do the first reboot. That's where things get a little weird. This is an HP system that came with Vista and an XP downgrade. Every time I try to boot from the OS disc, it forces me to insert the "HP Restore Plus" cd to verify the install, then it wants to start the whole process over again. So, I don't know if the reboot after the initial "repair" copying of the files was supposed to go back to the repair process or what...like I said, it's been a while since I did a repair. :) Tried just rebooting normally after this and it just ends up in an endless reboot-of-death cycle unless I tell it to boot from the CD/DVD drive...during the reboot circle it does flash a blue screen right before it restarts but too fast to see it.

    So, your advice on what to do next would be greatly appreciated. I'm gearing up to repair my junk desktop just in case I have to plug in their infected hard-drive to pull their files and do a full OS reinstall. I'd rather not do that because then my in-laws are going to lose a bunch of their email (but I can definitely save everything else).

    Thank you as always for your help and patience!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds like you will have to do a full reformat and install. If you can slave the drive, copy the data and files you want to save to a CD. You should also be able to save their emails. You need to post in the software forum for further assistance with this. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds