HelpAssisstan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Clockwork Avatar, Feb 1, 2010.

  1. Clockwork Avatar

    Clockwork Avatar Private E-2

    I had this MBR "virus" and got rid of it with the recovery console. I then followed the steps in the sticky, except I couldn't get RootRepeal to run (it'd show the "initializing" window and hang there using 50% CPU). Here are the logs, I'm hoping I'm all clear. Thanks in advance.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!



    I am currently reviewing the logs you were able to get and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below fixes and advice are specific to this member's problem and should be used for issue(s) on this machine only.

    Hello, Clockwork Avatar, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up this account's Desktop immediately leaving only links.[ C:\Documents and Settings\ANDY\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    *Comment: Giving all users of this pc "Adminstrator Accounts" is bound to lead to problems.

    You are getting very low on your hard drive's Free Space:
    * Please tell me about these files -
    Code:
    "C:\Documents and Settings\"
    helpas~1.ha~  Feb  1 2010        8192  "HELPAS~1.HA~"
    helpas~1.log  Feb  1 2010        1024  "HELPAS~1.HA~.LOG"
    helpas~2.ha~  Feb  1 2010        8192  "HELPAS~2.HA~"
    helpas~2.log  Feb  1 2010        1024  "HELPAS~2.HA~.LOG"
    helpas~3.ha~  Feb  1 2010      262144  "HELPAS~3.HA~"
    helpas~3.log  Feb  1 2010        1024  "HELPAS~3.HA~.LOG"                                         
                                                                                  
    "C:\Documents and Settings\ANDY\"
    126410~1.gif  Jan 22 2010      397379  "1264108306259.gif"
    126412~1.gif  Jan 22 2010     3092760  "1264129935277.gif"
    126412~2.gif  Jan 22 2010      630584  "1264125284852.gif"
    126414~1.jpg  Jan 22 2010      113864  "1264142692633.jpg"
    126466~1.pdf  Jan 28 2010     1558767  "1264668774114.pdf"
    633799~1.jpg  Nov 12 2009       56098  "633799063495399430-patrickstar.jpg"
    633867~1.jpg  Nov 12 2009       59917  "633867125599462220-what.jpg"
    combofix.exe  Oct  6 2009     3327308  "ComboFix.exe" [COLOR=purple][B]<--- Why wasn't this uninstalled after its use in October?[/B][/COLOR]
    Step 1:
    Please run the below tool, re-boot, then run it again.
    McAfee Consumer Product Removal Tool


    Step 2:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Step 5:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 6:
    Now install the latest Sun Java Runtime Environment

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below log to your next reply:
    • C:\MGlogs.zip

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited: Feb 4, 2010
  4. Clockwork Avatar

    Clockwork Avatar Private E-2

    these files keep reappearing each time I start windows:

    helpas~1.ha~ Feb 1 2010 8192 "HELPAS~1.HA~"
    helpas~1.log Feb 1 2010 1024 "HELPAS~1.HA~.LOG"
    helpas~2.ha~ Feb 1 2010 8192 "HELPAS~2.HA~"
    helpas~2.log Feb 1 2010 1024 "HELPAS~2.HA~.LOG"
    helpas~3.ha~ Feb 1 2010 262144 "HELPAS~3.HA~"
    helpas~3.log Feb 1 2010 1024 "HELPAS~3.HA~.LOG"

    the rest are just pictures that I haven't renamed yet.

    as for combofix, I'm not sure why it was uninstalled, but it was installed for a reason unrelated to this site.

    MGlog inc.
     
  5. Clockwork Avatar

    Clockwork Avatar Private E-2

    MgLog
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You forgot to reply to this:
    Then I'll research your latest log and the files that keep re-appearing.

    EDIT: Are you aware of this user account?
    dr.m
     
    Last edited: Feb 4, 2010
  7. Clockwork Avatar

    Clockwork Avatar Private E-2

    oh sorry yea, merged successfully.

    Thanks :D !
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please read my edit to my post #6.
     
  9. Clockwork Avatar

    Clockwork Avatar Private E-2

    No i wasn't aware, that account doesn't show up.

    On a side note, System Restore and windows Update keep turning themselves back on.

    System restore keeps setting itself to use 12% of my HDD
    Windows updates switches to automatic when I have it set to inform me, but not auto-download.
     
    Last edited: Feb 4, 2010
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    My mistake - that account doesn't exist now. Your problems with System Restore and Windows Update will be dealt with in time.

    Right now, let's do some tidying.

    Step 1:
    First - Navigate to C:\Qoobox and delete all SnapShot.dat files.

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the C:\MGlogs.zip fie to your next reply.

    * Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited: Feb 7, 2010
  11. Clockwork Avatar

    Clockwork Avatar Private E-2

    Here are those logs. Thanks for all your help.
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Clcokwork Avatar

    Again I'll remind you - giving all users "Admininstrator Accounts" is just asking for trouble, because too many users can make changes that will effect every other account on this pc.

    Question: What can you tell me about these -
    • C:\ACB.exe
    • c:\documents and settings\ANDY\ohya


    Step 1:
    Using the following link, please download and run twice with a re-boot in between -
    AVG Remover(32bit)
    (avgremover.exe)


    http://www.avg.com/us-en/download-tools


    Step 2:
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Step 3:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the C:\MGlogs.zip and C:TDSSKillerlog.txt logs to your next reply.

    * Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  13. Clockwork Avatar

    Clockwork Avatar Private E-2

    1) I don't have control over who is allowed an Admin account
    2) ACB.exe was a school project, deleted it
    3) ohya is a flash game.

    here are those logs.
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds