question on "Windows XP Cleaning Procedure"

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tony Baloney, Sep 5, 2008.

  1. Tony Baloney

    Tony Baloney Private E-2

    "Windows XP cleaning Procedure" Chaslang writes, “Important: Rename the downloaded mbam-setup.exe file to mb.exe to help work around certain malware that will block it from being run.” Did he mean mbam.exe instead of mbam-setup.exe because there is nothing in the folder called “mbam-setup.exe”?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I was referring to the installation program that you downloaded. It is named mbam-setup.exe and that is what often needs to be renamed to mb.exe to allow it to be installed in the presence of certain malware. The file you are referring to is the installed program file name which is C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    Sometimes it is also necessary to rename the program files too when malware blocks them from running. If you do rename the C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe file, you would also have to update shortcuts to be able to run the program when you click on the shortcut.
     
  3. Tony Baloney

    Tony Baloney Private E-2

    But I don't understand where is the interface in which I would edit the name of the setup file. When I download from majorgeeks there is a sequence of scripts invoked and I don't see a point at which to edit the setup file. I have already downloaded this product. Should I remove it and try to figure out how to change the name of the setup file?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First if you are not having a problem running the installer then you will not have to even worry about. ( since you message implies you already installed it then it does not matter any more ). However when you download files you can rename them as they are downloaded. This is standard Windows operating procedure. It is nothing fancy. It is allowed by your browsers. If you don't do that, you can also just right click on the file after downloading and then select Rename. Again standard Windows procedures.
     
  5. Tony Baloney

    Tony Baloney Private E-2

    I unsuccessfully tried to download combofix.exe. I get an error message "You cannot rename ComboFix as ComboFix[1]. Please use another name, preferably made up of alphanumeric characters." I am mystified. What should I do?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to rename combofix. Just download it and save it to your Desktop. If for some reason it is showing up as combofix[1].exe or similar just change the name to combofix.exe
     
  7. Tony Baloney

    Tony Baloney Private E-2

    Hi,
    In the ComboFix tutorial which you linked to the "Windows XP Cleaning Procedure" page, they want us to install the Windows Recovery Console. The link they provide to get the Windows recovery console if the user does not have disk backup is http://support.microsoft.com/kb/310994 but when I go there everything expects me to have a floppy disk drive. I only have a CD drive. It seems that ComboFix will not run unless it can install the Windows Recovery Console into the User's Computer. But I am having trouble getting the Console. What should I do? Tony
     
  8. Tony Baloney

    Tony Baloney Private E-2

    malware removal logs (part 1)

    Here are the logs for the malware removal routine. During the combofix run I could not figure out how to get spybot out of memory. I think I changed its settings so it wasn't resident and rebooted but it still showed up. I will send another message with the rest of the logs. Tony
     

    Attached Files:

  9. Tony Baloney

    Tony Baloney Private E-2

    malware removal logs (part 2)

    Here is the remaining log. T.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: malware removal logs (part 1)

    It was explained in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    It was still running in your logs so do exactly what the above indicates and then reboot your PC.

    Uninstall the below old versions of Sun Java as requested in step 1 of the READ & RUN ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/se...0000049.000000bb&c=00000082.00000096.000001da

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. Tony Baloney

    Tony Baloney Private E-2

    Hi,
    I was confused in manipulating Spybot's switches because when you first open tools, in the pane on the right, there is a number check boxes among which is one for Resident, and that's what I thought you wanted me to edit. As a newcomer I found this confusing. Maybe in your "How to disable Spybot's TeaTimer" you might specify that Resident is in the left pane. Thank you for your help. Tony
     
  12. Tony Baloney

    Tony Baloney Private E-2

    Re: malware removal logs (part 1)

    OK, everything went fine until I ran combofix. First, my antivirus and firewall were running. Combofix stopped after Armorall Firewall stopped it a few times. I turned off Avast and Firewall and rebooted. I didn't realize that they automatically started upon restart so when I put the text file on the combofix icon again the firewall bothered it again. But combofix looked like it was running and went through a number of the stages and my eyes were not on the screen but my system rebooted. Upon restart combofix was still going (with Armourall still bothering it). Then Combofix ended. I looked in the root directory and just found a fragment of a log. I didn't see anything in your post about dealing with security software. It said turn off all browsers. Is security software considered a browser. I think maybe you're assuming too much about my knowledge. The script file I put together from your last post is gone, so maybe ComboFix executed those deletions.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the suggestion. I went a step further and added some snapshots. Take a look at it now. ;)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: malware removal logs (part 1)

    Yes it was mentioned twice. Once in the READ & RUN ME where we had you download ComboFix it gave the below with important notes. Notice the Online Armor was specially mentioned as a problem.
    Then later when you intially first ran ComboFix we had you go to the bleepingcomputer official download site to follow instructions for installing and running ComboFix. On this page after the Recovery Console is installed and you are ready to run ComboFix it said:
    Now yes we could put this repeat this same information over and over again in every single fix, but then we have the hundreds of people who complain on how long the fixes are already. ;) Plus it does not matter how much detail we put into the instructions if they are not read and the instructions are not followed. Example, see below.

    Now here is even another important note (the last bullet item in the list) from the very first section of the READ & RUN ME:
    So when you first started this thread you logs showed Symantec Internet Security and its firewall. Now you are talking about Avast and Online Armor. Why did you change everything??????

    So you will find that ComboFix did not run at all due to Online Armor which is why there is no log.
     
    Last edited: Sep 10, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds