Autorun-G worm related

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ChemMD, May 8, 2009.

  1. ChemMD

    ChemMD Private E-2

    Hi. My USB drive was infected with autorun-G worm detected by Avast. The effect was that the USB drive can not be removed either by the "Eject" command or the "safely remove" route so that I just removed it the USB drive physically. I tried to remove the worm using Malware and Avast.

    When I searched the forums I saw a thread here that describes "C:/RECYCLER..." popping up. I noticed this pop-up during the booting process after the Windows startup. This computer also takes a long time booting up. I also noted an error message about Windows Explorer.

    I followed the suggestions in your threads "READ & RUN ME FIRST" then "Windows XP Cleaning". The unusual thing I noted in the process was that The computer freezes during the re-boot after SuperAntiSpyware step, and Avast antivirus was running when ComboFix was writing the log. (I did follow the disabling the antivirus, antispyware and firewall BEFORE starting ComboFix.

    It was not clearly stated in the instructions but I enabled these BEFORE I ran MGtools. AFTER all the four scans, the boot was a bit faster, AND there was an error message from Avast looking for RPC.

    Hope you can help.

    PS. I deviated from the Windows XP Cleaning procedure in that I did not reinstall Malwarebytes as it was already installed in my desktop before I started the procedure.

    Thanks in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should start by running this: Disabling AutoRuns

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java 2 Runtime Environment Standard Edition v1.3.1
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also look for files with names like below on your removable drives and your hard disk and delete them if found. Also look on drives of other PCs that you have plugged your infected USB drives into.
    New Document.exe
    rawdata.exe
    RootFolder.com

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. ChemMD

    ChemMD Private E-2

    Thanks for the next steps. The process went smoothly as you described, except that I did not find any of the three files you mentioned to check for in this laptop and the USB drive.

    Here are the attachments you asked for.

    Am I now ready to do Step 4 of the Windows XP Cleaning Procedure?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  5. ChemMD

    ChemMD Private E-2

    Thanks for continuing to work with me in correcting my problem. I am still having problems.

    After reading your response on my logs being clean, I removed the files as described in Windows XP cleaning procedure, and performed Toggle System Restore without incident.

    While reading How to Protect Yourself from Malware, I noted a 6 minute freeze in the computer clock during the boot.

    I went to Alternative Scans (with the results) as follows:
    1. No hidden items found using SophosKit
    2. Found 3 infected objects during online scan with Kaspersky Online. The scan froze at 64% complete.
    3. I did not scan using Ad-Aware SE free edition because I was unable to download definition updates using Updates and Webupdate.
    4. No threats found using Kaspersky Virus Removal Tool (with default areas to scan).

    What should be my next step?
     
  6. ChemMD

    ChemMD Private E-2

    Hi, again. I repeated Kaspersky Online Scanner 7 scan under Safe Mode. Success! Here's the log.

    Thanks again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Outlook Express archives have to be cleaned up manually or deleted by you. That is the only way to remove junk from them.

    Make sure that you have not reinstalled MyWebSearchWB in any form. Look in Add/Remove programs and uninstall it if found. Otherwise just delete the C:\Program Files\MyWebSearchWB folder.

    Don't waste your time with Ad-Aware. Use SUPERAntiSpyware and Malwarebytes from our cleaning instructions. They are both many times better than Ad-Aware.
     
  8. ChemMD

    ChemMD Private E-2

    Thanks for you concluding tips. I ended up repeating the Malware Removal for Windows XP. I think I got all of it this time. Working on Protecting against Malware. Have to balance catching malware etc, against slowing down my laptop.

    Thanks again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds