combofix messed up computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by NoGeekMe, Dec 15, 2007.

  1. NoGeekMe

    NoGeekMe Private E-2

    I inherited a P4, 80g hard drive, 1g memory, running Xp SP2 Home, Norton AV, XP's firewall and I use Firefox.

    Yesterday folks on the Software Forum helped with a fix for XP's firewall, which mysteriously was being controlled by a group policy, which was causing the on/off buttons to be disabled and preventing me from turning it off to install a better firewall.

    The site with a fix for the issue also stated that many viruses can disable Window's firewall settings and recommended a thorough scan.

    Norton AV updates and runs nightly and has found nothing. I ran Spybot a few days ago and though it found nothing new I noted that it was set to ignore four issues and I didn't know what action, if any, to take:

    %JavaDir%\QTJava.zip ---missing shared DLL
    install.exe ---wrong app path
    MsoHtmEd.exe ---wrong app path
    winnt32.exe ---wrong app path

    I began running Read and Run Me First, but combofix created all sorts of problems - - couldn't get online, couldn't find my LAN connection, couldn't access help or system restore, appearance was strange, everything but Dell support was gone from systray, etc. I stumbled across the qoobox folder and was able to restore the registry with erdnt.exe.

    I didn't know if I should attach the combofix log.

    Recent strange behavior: few days ago thought I'd downloaded two Firefox extensions but could only find one of them the next day. That night I switched windows while running Spybot and a Firefox window was open and the extension I hadn't been able to find was visible and running. A second or two later the window closed. When I opened Firefox the extension again wasn't there.

    Also, after combofix ran I got a message stating I'm running counterfeit Windows. It isn't counterfeit but was wondering if I should wait until current issues are resolved before revalidating with Microsoft?


    Thanks for your help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is true and it is another reason for not using the Windows firewall. The first reason for not using it is that it is not a full bidirectional firewall and thus does not provide proper protection.

    Did ComboFix actually finish running? If so, yes attach the C:\ComboFix.txt log file.

    I'm not sure exactly what is going on here. It would be advisable to skip ComboFix and run the other steps in the READ ME with AVG Antispyware and MGtools and then attach those two logs.
     
  3. NoGeekMe

    NoGeekMe Private E-2

    Okee dokee - - thanks for reply.

    Starting the other steps. Will post those logs when done.

    Yes, combofix had finished running. Here's that log, though wasn't sure if you still wanted it at this point.

    Thanks again!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange! According to the ComboFix log, it did not fix/delete anything. Thus I'm not sure what problems you actually were having after running it.
     
  5. NoGeekMe

    NoGeekMe Private E-2

    Wow! I assure you, the computer was a mess and lots of things had changed when combofix was done, and erdnt.exe changed it back.

    I've run AVG and it found rootkit.small AND acted strange.

    I'd followed the instructions from Windows XP Cleaning Procedures yet AVG didn't want to quarantine and it didn't create a report.

    I was able to override its desire to delete everything it found, so it just deleted the cookies and quarantined the other items.

    There's no report, even though under 'settings' 'create a report after every scan' is selected and the checkbox is unchecked (and besides, it found bad guys).

    Should I just proceed with MGtools?

    Aside from cookies, this is what AVG found:

    rootkit.small
    Not-A-Virus.Sniffer.Win32.WpePro.a
    Adware.Balloon
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All it did was add a service to the registry to allow it to work properly. The erdnt program just put things back the way the were.


    Where did it find it? I need to know the full path and file name info.


    Yes get the MGtools log.
     
  7. NoGeekMe

    NoGeekMe Private E-2

    They've been moved to quarantine and AVG didn't create a log. How do I get the full path and filename info?

    I haven't closed AVG, was afraid of losing info that might be there that I don't know how to get.
     
  8. NoGeekMe

    NoGeekMe Private E-2

    Sorry, found the info!

    C:\Documents and Settings\Sam\Desktop\WpeSpy.dll
    Infected with: Not-A-Virus.Sniffer.Win32.WpePro.a



    C:\Documents and Settings\Sam\Desktop\WPE PRO.exe
    Infected with: Not-A-Virus.Sniffer.Win32.WpePro.a

    C:\WINDOWS\SYSTEM32\ascbalon.dll
    Infected with: Adware.Balloon

    C:\WINDOWS\SYSTEM32\ascbalo3N.dll
    Infected with: Adware.Balloon

    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP555\A0107668.sys
    Infected with: Rootkit.Small
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need to attach the log from running MGtools.exe as requested.
     
  10. NoGeekMe

    NoGeekMe Private E-2

    Yep. Finished just now. Unsure if I ran it correctly. Got error message type 1 and kept getting it after installing the fix and re-running each batch file - - eventually each file ran despite playing 'wack-a-mole' with the error message.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The rootkit detection was probably not even real but it is only in System Restore which will be cleaned up when we do our final steps.

    You need to get the fix for error message 1 installed correctly. Did you install the files into C:\Windows\system32 ? Neither GetRunKey.bat or ShowNew.bat are running properly.
     
  12. NoGeekMe

    NoGeekMe Private E-2

    Yes, installed into c:\Windows\system32. Will try running again ...
     
  13. NoGeekMe

    NoGeekMe Private E-2

    Here's the new log from MGtools. First time around I think I hadn't installed the fix, just downloaded it ... doh!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not appear to have any malware problems. But I do have a question and a few things for you to do.

    What is the below file and why are you saving EXE files in the C:\Program Files folder? You should not save them here.
    Code:
    "C:\Program Files\"
    medic6.exe    Dec  7 2007     7028144  "medic6.exe"

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Spybot - Search & Destroy 1.3 <-- this version has not been used in about 3 years. Uninstall it and install what was given in the READ ME.


    Are you currently having any malware problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds