still infected?

Discussion in 'Malware Help (A Specialist Will Reply)' started by losin the will, Dec 20, 2008.

  1. losin the will

    losin the will Private E-2

    Apologies in advance for my lack of computer knowledge & sorry for the vagueness during parts of my post as i am relying partly on memory.

    My computer appears to have been infected by a virus & i have had difficulty finding any specific removal tools via the net until i came across this website.

    The only other reference that i found has been listed in a support forum here. Please read the following link... http://forums.majorgeeks.com/showthread.php?t=176798

    Its the exact same problem other than my security alert message is telling me that the virus is Win32.Zafi.b. I initially tried running an AVG scan & this found 3 trojans identical to the previous members post. It did not find Win32.Zafi.b. I downloaded 2 removal tools to attempt to get rid of the Win32.Zafi.b virus, one being bit defender(the other i can't remember) & they said that the infection was not there.

    At this point i began to think that it was not infected with this virus after all & the security alert was bogus. Whenever i tried to access the net it the AVG resident shield popped up detecting the c.abuu, c.abut & c.abus trojan's. It also at a later date found a trojan ending in 12.XUC which i have also failed to find any reference to.

    The security alert also popped up whenever the computer was booted. When i went into msconfig & changed to normal start up as advised by here it all stopped & i've neither seen the security alert nor the resident shield with the trojan warnings ever since.

    One thing that i did notice prior to doing this on selective start up was a file that i think was called systre.exe although i couldn't be sure it was exactly that due to only a vague suspicion something was lurking there at the time(it was before i found this site). I googled this file & it would appear that it is indeed a nasty piece of work.

    Anyway... I've followed the advice on here & ran the scans so here are the logs.

    My computer does not appear to be running anything other than normally now but having a tiny fraction of computer knowledge what i would like to know is whether or not my computer is still infected at all. I am now scared to use email or conduct any financial dealings until it's got the all clear.

    After i ran the scans i was curious as to whether this systre.exe file was still there but when i try to run msconfig my computer now says "WINDOWS CANNOT FIND MSCONFIG". Is this as a result of something i have done in following the instructions or the virus preventing me access?

    Many thanks
     

    Attached Files:

  2. losin the will

    losin the will Private E-2

    here is the final mgtools log
     

    Attached Files:

  3. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Run regedit and go to:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSCONFIG.EXE

    the value should be

    C:\WINDOWS\pcHealth\helpctr\binaries\msconfig.exe

    If not, just add that line in. (see screen shot)
     

    Attached Files:

  4. losin the will

    losin the will Private E-2

    Thanks for the response.

    I'm on a different pc at the moment & so will try your advice later.

    Since posting i also discovered the advice on not using msconfig to control start up so i'll look for another method to change start up as since i have reverted msconfig to normal start up i've got lots of unneccessary items loading when i boot.

    Since either developing the virus or subsequently following the READ ME & RUN ME FIRST advice my laptop now no longer recognises through MY COMPUTER my card reader or USB flash drive when connected. I can access them through disk management & having read other advice on the net i think that if i rename the drive from E: to F: then i can access them once more through MY COMPUTER but is there a better solution as this seems to me like treating the symptoms rather than finding the cause?

    Also i think possibly due to the length of time it now takes to boot with having too many unneccessary items loading at start up, if i try to access the drive via MY COMPUTER it just freezes & crashes my system. It also did the same thing if i tried to go to CONTROL PANEL. I've never ever had any such previous problems in over 2 years that i've owned it. If i access MY COMPUTER or CONTROL PANEL without anything first inserted into the USB port then it doesn't crash. This does not seem to me normal behaviour at all. I don't know if any of this is due to my laptop still being infected or something i've subsequently done via READ ME & RUN ME FIRST (the logs that i posted mean nothing to me so i've no idea if they're clear or not?)

    Other than this my laptop appears to be behaving as normal & if anything seems to have speed up, possibly due to running ccleaner i imagine?

    Any further advice would be gratefully appreciated?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are all basically clean. I will give you some instructions below to help alleviate some of your startup issues. These are not malware, they are just not necessary. Anything remaining after this, you will have to decide whether you need it or not.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2_03

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    After clicking Fix, exit HJT.

    Now reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now download and run the current version of MGtools.exe



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. losin the will

    losin the will Private E-2

    Thanks Chaslang,

    I've done everything that you asked apart from downloading the latest MG tools. The link that you provided is invalid.

    Everything appears to now be working correctly. The problem with running My Computer or Control Panel doesn't occur if i right click to open them so that is what i've been doing.

    The problem with MSCONFIG is still there though. The file is there correctly as Corporal Punishment asked but it will not run from the command prompt.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You waited too long and that link expired. The program updates frequently.

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    After running the new version of MGtools, see if you can run MSconfig.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds