Malware procedures followed Logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by mlydell, Feb 17, 2009.

  1. mlydell

    mlydell Private First Class

    I started out with BSOD problems and posted a thread (http://forums.majorgeeks.com/showthread.php?t=182186) which helped me resolve those issues, or so I thought. Then this morning AVG started spitting out all sorts of trojan warnings. (I don't know if these two events are related, but wanted to include the info in case it helps....)

    I also was using COMODO but have had problems getting it configured so that I can access all the computers on the network - I need to for work purposes get to others on the network...

    As I was going through the malware removal process, when it came to ComboFix I couldn't get AVG to shut down. I even disabled it in MSCONFIG and rebooted and it was still there. (COmboFix was giving me warning and it was showing up in the Task Manager. So I uninstalled COMODO and AVG, ran the final scans. I've reinstalled AVG, and moved to Online Armor for my firewall.

    Attached are the logs. Please let me know if you see anything I need to do next.

    Because there was malware found in the different scans, I've toggled my System Restore.
     

    Attached Files:

  2. mlydell

    mlydell Private First Class

    Here are the rest of the logs. I've also attached the log from Spybot in case anything in there helps.

    It seems like a lot of infections but all of the same general kind.

    Thanks!

    UPDATE:

    I'm trying to reinstall AVG, and I get the following error:

    Local machine: installation failed
    Installation:
    Error: Action failed for file avgtdix.sys: starting service....
    Error 0x80070014

    Not sure what this means. I'll reboot and try again.
     

    Attached Files:

    Last edited: Feb 17, 2009
  3. mlydell

    mlydell Private First Class

    UPDATE2

    Rebooted and tried to install AVG again. Got following warnings:

    Local machine: installation failed
    Installation:
    Error: Action failed for file avgtdix.sys: starting service....
    Error 0x80070014
    Rollback:
    Warning: Action failed for directory Log: removing directory....
    Error 0x80070091
    Warning: Action failed for directory avg8: removing directory....
    Error 0x80070091

    What does this mean?
     
  4. mlydell

    mlydell Private First Class

    I rebooted into Safe Mode today and it let me install AVG. Do I need to have AVG run a scan, or did the scans I did per your procedure catch all that can be seen?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You ran a very old version of MGTools...please go back to the Read and Run First instructions and download the latest version.

    I also need the logs from:
    SAS
    MBAM
    ComboFix
     
  6. mlydell

    mlydell Private First Class

    New log attached - sorry about that - I didn't realize I was running the older copy...

    The other logs are attached to my first post.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in the logs.....could you tell me exactly what is being reported. Also please go back to msconfig and set it for normal startup. Then reboot.
     
  8. mlydell

    mlydell Private First Class

    I'm not getting any specific reports right now, but before I ran all this I had SEVERAL trojan virus reports that AVG found which started my malware cleaning process. I also attached a .pdf of the Spybot report which found some trojan's as well.

    Are you saying that the programs are saying they never found anything or that there isn't anything on here now?

    My system seems to be running slow, and OUtlook is especially slow. so I'm trying t make sure that everything is clean

    As for MSCONFIG, I thought that was in normal mode. The ones that were disables were startup items that are no longer installed. I had disabled them through CCleaner. I went ahead and deleted them, so now my MSCONFIG only contains items that load.

    I'll reboot. Are there any other logs you need to look at?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I mean to say that the scans appeared to have taken care of the malware....but if AVG is reporting something, I need to know exactly what it is. Your slowness could me non-malware related.
     
  10. mlydell

    mlydell Private First Class

    Sorry for the confusion - AVG was finding items which was what started this whole process. There haven't been any items found by AVG since then - I was posting the logs to make sure everything looks clean...
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  12. mlydell

    mlydell Private First Class

    OK, I didn't read closely enough I see. I didn't install Combo on my desktop. I downloaded the .exe file there, but I don't know where it installed to.

    The .exe file is still on the desktop. I don't see a combo file under C, but there is a QooBox folder that looks like it has stuff in it that was quarrantined.

    Do I delete those folders?
    Do I delete the combo exe file?
    Are there other folders I need to locate or is there a registry entry I need to get rid of.

    All the other stuff I can take care of.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that were created.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds