Xp Security 2011 Infected Safe Mode

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tigersnake, Apr 9, 2011.

  1. tigersnake

    tigersnake Private E-2

    Hi, love this site. This is my first time asking for help though.
    I am running:
    Dell Optiplex GX150
    Intel Celeron 1200mhz
    Windows XP Pro
    I have now booted with an ultimate boot disc for windows from cd. I downloaded using the boot cd all the Rkills, exehelper, Malwarebytes, SuperAntiSpyware, and MGtools.
    I saved them to drive c then rebooted into Safe Mode. Once one of the Rkills worked I could run Malwarebytes. I may have made a mistake, I did not have Malwarebytes remove the infected items, then I ran SuperAntiSpyware. I ran Malwarebytes again afterwords and it found far less infected files, I have both logs from MB. Here are the logs. I only put the first MB log.

    Thanks for your time and help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are almost 1000 database versions out of date with Malwarebytes. Can you download the updates and run a new scan? Be sure to fix what it finds and then save the new log and attach it.

    Can you also boot in normal boot mode now to get a new MGtools log?

    What malware problems are you currently having?
     
  3. tigersnake

    tigersnake Private E-2

    Hi, thanks for the help.
    I am only able to get online with the boot disc. I can access the drive through
    Xplorer2, then i download the programs and save them to drive C, then I reboot into safe mode ( I can't get into any user accounts or access anything in normal boot). The malware is XP Security 2011.
    Can I install MB on the Drive B created by the boot disc and update the install and run it from there. Thanks TS
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you run ComboFix now as instructed in the READ & RUN ME FIRST cleaning procedure? You will need to disable ( or uninstall if necessary ) Avast, McAfee Security Scan and Online Armor to run ComboFix.

    Whether you can run ComboFix or not, continue with the below.

    Do you really need this >> Retrogamer ?
    Did the problems begin after this was installed? It installed some adware/malware on your PC. I recommend uninstalling it.

    Uninstall Uninstall Drop Down Deals 1.10.01


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} (GameTap Player) -
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. tigersnake

    tigersnake Private E-2

    Looks like Retrogamer and Drop down deals were part of the problem. System restore was also infected. I ran MB and SAS in safe mode again with updates, but combo fix would not run.
    I am now booted to normal user log in, where I ran MB and SAS again. Things are running ok so far. I will run Combo fix now then MG tools then Avenger with the info you sent.
    I did not understand what these were:
    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} (GameTap Player) -
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - .

    Thanks for all the help.....:major TS
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are things for you to fix with analyse.exe as stated in my instructions. ;)

    Attach the new logs when you complete my previous instructions.
     
  7. tigersnake

    tigersnake Private E-2

    Thanks again. I will be out of town for a few days I will post results then, sorry for the delay. TS
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just attach the follow up logs as soon as you finish.
     
  9. tigersnake

    tigersnake Private E-2

    Yea! I'm back. Sorry for the delay, as they say when it rains it pours.
    I will run combo fix and others and post those logs over the next couple
    of days. Thanks for your help and patience..........TS
     
  10. tigersnake

    tigersnake Private E-2

    Here are the logs. Thanks.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. tigersnake

    tigersnake Private E-2

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    On behalf of Chaslang, you are welcome. safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds