2nd computer cleanup

Discussion in 'Malware Help (A Specialist Will Reply)' started by cuddlepuppy, Jan 29, 2009.

  1. cuddlepuppy

    cuddlepuppy Private E-2

    Here is the logs for the 2nd computer
     

    Attached Files:

  2. cuddlepuppy

    cuddlepuppy Private E-2

    MGlog
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any anti-virus program installed on this computer?

    If you haven't yet been warned, you should not allow all users to have admin. privileges!

    What are these:
    Code:
    "C:\"
    (1)APR~1      Jan 24 2009              "(1)A ProgInstall"
    (1)ATEMP      Jan 22 2009              "(1)Atemp
    
    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please use add/remove programs to uninstall:
    My Way Search Assistant
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Drivers::
    cdiskdun
    
    File::
    c:\docume~1\David\LOCALS~1\Temp\cdiskdun.sys
    c:\windows\system32\mlJAQjjG.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\Fun Web Products\Settings]
    
    [-HKEY_LOCAL_MACHINE\software\Fun Web Products\ScreenSaver]
    
    [-HKEY_USERS\S-1-5-20\Software\Fun Web Products\ScreenSaver]
    
    [-HKEY_USERS\S-1-5-20_Classes\Software\Fun Web Products\ScreenSaver]
    
    [-HKEY_USERS\.Default\Software\Fun Web Products\ScreenSaver]
    
    [-HKEY_USERS\LocalService\Software\Fun Web Products\ScreenSaver]
    
    [-HKEY_USERS\LocalService_Classes\Software\Fun Web Products\ScreenSaver]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. cuddlepuppy

    cuddlepuppy Private E-2

    You wrote: [ * ]

    [Why am I not seeing any anti-virus program installed on this computer?]
    I would like them to use Avast and will have them do that "First Thing" when I drop the computer off to them.

    [If you haven't yet been warned, you should not allow all users to have admin. privileges!]
    Both computers were set up this way, I will set all acounts as restricted with a seperate Admin only found in safe mode. Just haven't done it to this one yet. I was shocked to see all admin accounts as you are.

    [What are these:]
    [Code:]
    ["C:\"]
    [(1)APR~1 Jan 24 2009 "(1)A ProgInstall"]
    [(1)ATEMP Jan 22 2009 "(1)Atemp]
    These are temp folders I created to hold "Read&Run" programs and logs.

    And something you couldn't see, was a 50 fragmented HD while being 75% full. In games alone I removed 8g's, personal files 9.5g's and CCleaner removed another 9.6g's of dung.

    I await your reply to this, in case I need the AV installed befor I can go further. I'll get WinMess and My Way Search Assistant, Viewpoint Media Player done.

    Thanks for this wonderful help.
     
  5. cuddlepuppy

    cuddlepuppy Private E-2

    where is "My Way Search Assistant"? I do not seem to find it.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It may already be removed, but it was in the add/remove list.

    I still need the logs.

    And yes, you need to install Avast ( if that is your choice ) now.
     
  7. cuddlepuppy

    cuddlepuppy Private E-2

    Ok, here we go.
    And boy do I need to do some education with this family.:major
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you do. :)

    Now download Registry Search (see the link titled RegSearch Download Link )

    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independen) and click Ok... option, enter the below string (use copy and past)
      • cdiskdun
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
     
  9. cuddlepuppy

    cuddlepuppy Private E-2

    Regsearch log
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Drivers::
    CDISKDUN
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CDISKDUN]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CDISKDUN\0000\LogConf]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cdiskdun\Security]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CDISKDUN]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CDISKDUN\0000\LogConf]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CDISKDUN\0000\Control]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cdiskdun\Security]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cdiskdun\Enum]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cdiskdun\Enum]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_CDISKDUN]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_CDISKDUN\0000\LogConf]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\cdiskdun\Security]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CDISKDUN]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CDISKDUN\0000]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CDISKDUN\0000\LogConf]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CDISKDUN\0000\Control]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdiskdun]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdiskdun\Security]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdiskdun\Enum]
    
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdiskdun\Enum]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot and re-run regsearch and attach the new log along with the Combo log.
     
  11. cuddlepuppy

    cuddlepuppy Private E-2

    OK here's the new logs
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like we got the driver but not all the reg. keys. Let's try this:

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Reboot and re-run regsearch( but add Fun Web Products to the search) and attach that log and the Avenger log.
     
  13. cuddlepuppy

    cuddlepuppy Private E-2

    Ok Avenger and RegEdit logs

    Just on a side note, did you have an answer on my other forum computer
    "Malware Cleanup"
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Much better. Now lets just do a reg. patch for the rest.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me how things are running.

    If I am helping you on your other thread....I will be getting to it soon.
     
  15. cuddlepuppy

    cuddlepuppy Private E-2

    I got a success message, so OK there. new MG log is attached.
     

    Attached Files:

    Last edited: Feb 4, 2009
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good....just to check, re-run Combo and attach a new log and hopefully we can send you on your way. :)
     
  17. cuddlepuppy

    cuddlepuppy Private E-2

    You all have been very helpful, Thank You
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what this is:
    C:\(1)Atemp --> if not, delete it.


    Download and Install Registrar Lite.

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further

    [HKEY_USERS\.Default\Software\Fun Web Products\ScreenSaver]

    [HKEY_USERS\LocalService\Software\Fun Web Products\ScreenSaver]

    [HKEY_USERS\LocalService_Classes\Software\Fun Web Products\ScreenSaver]

    [HKEY_USERS\S-1-5-20\Software\Fun Web Products\ScreenSaver]

    [HKEY_USERS\S-1-5-20_Classes\Software\Fun Web Products\ScreenSaver]


    To take ownership of the key do the following:

    * Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    * Click-on Security in the Menu
    * Select Take Ownership
    * Now right click on the registry key and select delete
    * Repeat for all three registry keys
    * Tell me the results. Any errors?
     
  19. cuddlepuppy

    cuddlepuppy Private E-2

    All went fine, no errors. Took ownership and deleted just fine.

    Do you need any logs? and please remind me what programs you have had me use, I may keep or should delete.

    (1) a temp is a folder I am useing for this fixing stuff, I'll delete when done.
     
    Last edited: Feb 6, 2009
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.......this will answer your questions:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds