17pholmes1001186/mrofinu1001186 impossible to get rid of =(

Discussion in 'Malware Help (A Specialist Will Reply)' started by fernan1234, Jun 30, 2008.

  1. fernan1234

    fernan1234 Private E-2

    I've done almost everything from the read and run me. I only couldn't run combofix and mgtools. Combofix simply wouldn't run, and mgtools says windows can't find getlogs.bat.

    I have attached SASlog and MBAMlog to this post.

    Is it possible to save my computer? I fear that my only option may be a reformat... Please help me, Major Geeks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please try running ComboFix in safe boot mode.

    For MGtools, did you save MGtools.exe to C:\MGtools.exe as requested. It must be save to the root folder of your Windows boot drive. Do not save it anywhere else and do not attempt to Run or Open it from the download link. You must save it to your PC. Please try again and make sure you follow the instructions exactly. If you get any error messages, see if it is one of the ones that are explained on the download page. If the error is not on the download page, give us the exact word for word message.
     
  3. fernan1234

    fernan1234 Private E-2

    OK. Both files were downloaded from the read and run first thread.

    1) combo-fix.exe will not run even on safe mode. When I try to enter the /killall command it only shows a status bar filling up and then the process shuts down and nothing happens. The same thing happens when trying to open the .exe directly.

    2) MGTools was saved to my C:/ Drive. I get two pop ups. The first one says "Windows cannot find 'GetLogs.bat'. Make sure you typed the name correctly, and try again. To search for a file, click the Start button, and then click Search." I click OK and the second message says "Failed to run GetLogs.bat, working dir = \MGtools (check to see if this file is in the EXE)".

    A folder named MGtools was created on my C drive, but none of the files in there seem to work... They give the same first error message mentioned above.

    About my problem, sometimes 17pholmes shows up in the task manager on starting windows, other times it's mrofinu, sometimes it's both. They always appear accompanied by a DIL#.tmp

    So what next? Thank you very much for your help, BTW.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window enter the below commands each follow by the enter key. The bold black are the commands. The bold purple is just comments to help you understand.

    cd \MGtools <-- there is a space after the cd. The prompt should change to C:\MGtools> to show that the cd (which is change directory worked).
    dir > c:\flist.txt <-- this will dump a file listing to a the c:\flist.txt file
    set >> c:\flist.txt <--- the 2 >> are necessary. This will append an environment listing to the end of the c:\flist.txt file.
    tasklist >> c:\flist.txt <--- this will append a running task list to the end of the c:\flist.txt file



    Attach the c:\flist.txt file here. Are you running a 32bit or 64 bit version of Windows?

    Leave the command prompt window open as my next message may have you run some additional steps using it.
     
    Last edited: Jun 30, 2008
  5. fernan1234

    fernan1234 Private E-2

    oh boy...

    ""Windows cannot find 'cmd'. Make sure you typed the name correctly, and try again. To search for a file, click the Start button, and then click Search."

    This is bad, isn't it?

    Oh and I'm using Windows 32-bit (Home Edition, SP1)


    EDIT: I just found a copy of cmd.exe I had. Here's the flist.txt
     

    Attached Files:

    Last edited: Jun 30, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did you find the copy of cmd.exe? You need to have a copy in c:\windows\system32

    If this has been missing, it would explain why MGtools would not work properly. Make sure a copy is in your system32 folder and then try using Windows Explorer and going to C:\MGtools and double clicking on GetLogs.bat If this works, it will run all the required scans for MGtools and create the c:\MGlogs.zip file for you to attach.
     
  7. fernan1234

    fernan1234 Private E-2

    Hey, chaslang. I had a copy of cmd.exe in my documents folder. I think some process that I ran before had quarentined the original file. But MGtools worked now, the .zip has been attached.

    I guess I should tell you that during this interim I ran NOD32 and it tried to clean and then quarentined pretty much every .exe in my system. They are all infected with a Win32/Virut.AV virus (a couple with Virut.AT)...one .exe has a Korgo.U worm... Also, a lot of .htm and .html files are infected with Win32/Allaple.Gen worm (in order to post here I had to restore a supposedly infected html file for firefox to launch)... And NOD32 seems to have contained mrofinu.exe and 17pholmes.cmt, which it says are probably a variant of TrojanDownloader.Agent.BLS trojan, and the DIL.tmp files, which show as probable variants of TrojanDownloader.Small.IAW trojan. An .exe with Spy.Agent.PY trojan was also found. Too bad I can't get NOD to generate a .txt with the log.

    So it looks like all my system is pretty much screwed. Is this completely cleanable? It looks like reformatting is my only option. If it is, do you have any advice to avoid getting infected again? I plan to make a back up of music, picture and movie files, a few word files and some .zip and .rar files. I'm sure as hell staying away from executables and other system files. I guess scanning the files that I intend to keep with NOD would be a good idea, huh?

    And again, thanks for all the support.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now this explains why you could not run MGtools and why cmd.exe was missing. This new information is very important and it changes what your approach should be. These infections are very nasty and as you have noted can make every executable on your PC untrustworthy. Attempting to clean all of the infected files can often result in many system files being deleted which can render your PC unbootable. Even your antivirus itself can be infected. Your only real reliable solution is to delete partitions, recreate partitions, format, and reinstall.


    See this: How to Protect yourself from malware!

    No guarantees since even NOD could be infected and could spread the infection.
     
  9. fernan1234

    fernan1234 Private E-2

    Even NOD can get infected... Well isn't that something, geez.

    OK, well thank you for all your help. I'm sorry for sort of wasting your time with the previous posts, but I certainly learned a lot. You know, I've used this computer for four years with no antivirus or anything and never had a problem until this thing came out of nowhere.

    Oh well. About that partition thing, is there a guide here that could help me to delete and create new partitions as you say? Because I have no idea how to go about that. Thanks again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just lucky I guess, but look at how bad things can be when you don't have protection. ;)

    The Software Forum is a better place to discuss this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds