After Bankerfox.a: problems uploading

Discussion in 'Malware Help (A Specialist Will Reply)' started by stubborndev, Feb 19, 2010.

  1. stubborndev

    stubborndev Private E-2

    Cleaned up Bankerfox.a on Monday, then ran through the full READ ME FIRST list yesterday (and came up clean again), but I still can't attach anything in gmail OR upload photos to Flickr. BUT I can upload just fine in Facebook. Gmail gives me an error message that my proxy or firewall settings may be a problem but I'm not running from proxy and the only firewall I have is the included Windows one. I'm running XP-32b. I can't help but think may upload problem is related to the malware issue. Can anyone help, please?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Only if you attach all the requested logs from doing the Read and Run First Instructions. :)
     
  3. stubborndev

    stubborndev Private E-2

    Thanks, Tim. I will do that when I get home late tonight. Wasn't sure if I needed to or not since everything came back clean. I also un/reinstalled Java as I found that comment elsewhere on these boards but that didn't solve the issue, either. Hopefully this site will let me upload since that's my issue. ;)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I may not get to it until tomorrow, but do attach the logs you have, even if they look clean.
     
  5. stubborndev

    stubborndev Private E-2

    Logs as requested.
     

    Attached Files:

  6. stubborndev

    stubborndev Private E-2

    Second log batch.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to put ComboFix directly on your desktop, not here:
    Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe

    It should be here:
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe

    You also did not make the agreement to run HJT when it popped up. Please do so on the next run.

    Please use add/remove programs to uninstall:
    Java(TM) SE Runtime Environment 6 Update 1

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\Administrator\Local Settings\Application Data\laudrk
    c:\documents and settings\Administrator\Local Settings\Application Data\njrcpn
    c:\documents and settings\Administrator\Local Settings\Application Data\xfeyjq
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  8. stubborndev

    stubborndev Private E-2

    Well, it seems that everything that needed Java to run is now working correctly. I apologize for the delay; it's been a crazy few days. Thanks for your help! The log.txt is the combofix log. It never asked me to run HJT.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some things don't want to die!!

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds