virus removal WinXP

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cfarns, Aug 28, 2014.

  1. cfarns

    cfarns Private E-2

    Ran across an odd popup error message this evening. Something to the effect of "Windows cannot access the requested file while you are offline", with options "Connect" and "Work Offline" and a variant on the Internet Explorer icon. I've been using the "x" to decline the popup, and found at least 1 virus upon further research.

    - AVG 2014 identified "JS/Heur" and "Worm/Generic2.QG". Quarantined and removed.

    - I found additional suspicious files in the folder housing the infected files (Documents and Settings\Craig\Local Settings\Temporary Internet Files\), and tried to delete. Three persistent files, one an executable called "forum.php?view=otherspl" listing an address of "http://gtaredw.com/qfzvzzvy/"[file name]. Google search suggests it's malicious, no surprise.

    - I followed the instructions on the Read Me post, and have included the output files as attachments. RogueKiller directed me to the webpage about SSDT hooks, but TDSSKiller did not have any hits. The persistent files remain.

    Any assistance in evaluating how to clean up the machine would be greatly appreciated. Popup is less frequent, but still here.

    Thanks,
    CFW
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing any malware in your logs. So let's just do this:

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Documents and Settings\Craig\Local Settings\Temp\*.*
    C:\WINDOWS\Temp\*.*
    C:\Documents and Settings\Craig\Local Settings\Temporary Internet Files\*.*
    
    :Commands
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  3. cfarns

    cfarns Private E-2

    Thank you so much for your response! I will run this tonight and post another update.

    best,
    CFW
     
  4. cfarns

    cfarns Private E-2

    Ok, I ran the code in OTM. The output log is attached. I was not able to capture the green text after the code finished due to a forced reboot in the middle - hopefully the log file has what you need. I was going to check the OTM output in the program, but it appears to no longer be on my desktop after the reboot. Not sure if that's how it's supposed to work.

    I've also attached a screenshot of the files that still live in Temporary Internet Files after this attempted move. I didn't see them listed in the OTM log.

    If it looks like everything is ok, maybe I'm just being paranoid post-virus. Please let me know.

    thanks,
    CFW
     

    Attached Files:

  5. cfarns

    cfarns Private E-2

    The disappearing OTM file confused me, but I then figured out that my antivirus (AVG 2014) was quietly deleting it for me. Thanks.

    I re-ran OTM, with the full reboot, and the log is attached. This one is probably more useful.

    Also, I'm not seeing the popup anymore, so fingers crossed that this is all fine except in my head... :)

    cheers,
    CFW
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how things go.......then I will give the final clean up.
     
  7. cfarns

    cfarns Private E-2

    Looks like things are going fine since last week. Thanks again for your help!! You guys are an amazing resource.

    CFW
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds