Had large infection that I may have cleaned

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bad Panda, Jun 27, 2008.

  1. Bad Panda

    Bad Panda Private E-2

    This PC has had a huge infection of spyware and viruses. The viruses are showing up clear, but spybot has showed up with Minibug 2 or 3 times. I think it's gone now, but I'd like to have the logs double checked. The system is performing well, but why chance it?
    I'll submit the other files in a 2nd post.
    Thanks in advance!
     

    Attached Files:

  2. Bad Panda

    Bad Panda Private E-2

    Here are the other files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just have a little more cleaning to do and then our final instructions.


    Uninstall the below old version of Sun Java:
    Java 2 Runtime Environment, SE v1.4.1_02

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [Antivirus] C:\Program Files\AAV\aav.exe
    O8 - Extra context menu item: &Search - ?p=ZCxdm565LBUS

    After clicking Fix, exit HJT.

    Now delete the below file:
    C:\WINDOWS\system32\ieupdates.exe.tmp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now if you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below
     
  4. Bad Panda

    Bad Panda Private E-2

    Had a problem uninstalling the old version of Java. I received the following error:
    "Please insert disk 1 that contains the file data2.cab." Then a line to the following directory: c:\program files\installshield installation information\{efce5837-fc21-11d6-9d24-00010240ce95} I have no idea what disk 1 is. Any suggestions?

    I'm continuing with the other steps. Thanks!
     
  5. Bad Panda

    Bad Panda Private E-2

    Other steps successful and registry update went fine. Java removal is still a problem.
    Thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is probably referring to some disks that were shipped with your PC. The InstallShield application was part of your base install and was being used for doing updates. If you do not have the CD, you will not be able to uninstall it using Add/Remove programs. You could try using the below to uninstall it. It may or may not work:

    Your Uninstaller! 2008
     
  7. Bad Panda

    Bad Panda Private E-2

    Interesting program this uninstaller, but it didn't even SEE the old Java version. Hopefully it isn't affecting anything.
    Thank you very much Chaslang. As always, you were very helpful.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    The just use the below.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If the above gives you a success message, you can then delete the fixME.reg patch.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds