Am I still infected? Please help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by guinnessboy, Nov 13, 2010.

  1. guinnessboy

    guinnessboy Private E-2

    Hi,

    I'm running Windows XP SP3 32bit with all the latest updates. Two nights ago my computer was infected with malware, in the form of a fake Windows Security Centre type job. This locked up most my computer, but MBAM still ran, and picked it up and removed it quickly. I followed this with a full sweep using MBAB and SAS and a few more issues were picked up and removed. Being the paranoid type, I tried to follow this up with a combofix Sweep just to make sure it was all gone (This is something I have done in the past several times, and on occasions has turned up more unwanteds). Unfortunately the second I accept the disclaimer on combofix the computer freezes, the only thing i can do is force the computer to shut down by holding the power button. This happens normally AND in safe mode, it happens with the file renamed and with its extension changes (.com & .bat.) I have trawled the web and found a handful of other people who have had the same problem with combofix, but I have yet to find a solution. I have also tried to do a GMER scan in an effort to get as much information as possible for you... unfortunately, in safe mode it flashes up a blue screen for a split second and then shuts the computer down after about 5 minutes of scanning, and in standard mode it hangs, much like combofix (force shut down required. This leads me to believe that there are some serious issues that MBAB and SAS are not picking up on (windows is also taking twice as long to start up now).

    I would be extremely grateful if someone would cast an eye of the attached logs to let me know if there's anything is still wrong, and if so, what can be done about it.

    If you need any more information/logs, let me know, and i'll get back to you as quickly as possible.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to run my instructions in normal mode please.

    Java(TM) 6 Update 20 <--- Uninstall outdated java.

    Reboot the machine.

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  4. guinnessboy

    guinnessboy Private E-2

    Hi,

    Thank you for responding. I have followed your instructions to the letter. Attached is the new MGlogs.zip you requested.
     

    Attached Files:

  5. guinnessboy

    guinnessboy Private E-2

    In my haste I also forgot to mention that the Java re-installation, from the link provided has not worked. The error message says ...."\jre-6u22-windows-i586-s.exe is not a valid Win32 application" So this is the only part that has not been carried out successfully.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\WINDOWS\TEMP
    C:\Documents and Settings\Keith\Local Settings\TEMP

    Hmm, have you tried again..? Any luck? Try this link

    How are things running now apart from the error you mentioned with Java.
     
  7. guinnessboy

    guinnessboy Private E-2

    Hi,

    Shortly after carrying out your last batch of instructions, i really started to notice the computer seemed to be taking even longer to start up (10mins before windows became even useable) and when it was started, I was also missing sound and it was generally sluggish.As the speed issues had started since GMER crashed. I decided to do a system restore as the computer was becoming unusable (just to fix) to a point just after my first scans when the malware first arrived (I have nothing from earlier as system restore has been disabled.. not by me!). This has sorted out the speed and sound issues. I have rescanned with SAS MBAM and then carried out your instructions as before. This all went okay as before, speed is still as it was pre-infection. I have also installed the latest java successfully. I have also installed Spybot (which found another one)

    I have also deleted the temp files as per your last post.

    Everything appears to be fine now and all scans come back negative ... but combofix still refuses to run??? I have even tried uninstalling avg (it is reinstalled now) to give it a chance, but it still hangs and i have to force the laptop to restart. As it worked before and it doesn't now, i'm still really concerned that there is something still at fault and i'm scared to use my computer for anything other than searching for solutions.

    I have re-attached the latest MGlog... just so you can see if i've made matters worse or not?

    Thank you again for sticking with me... I REALLY appreciate your time and effort.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. You do need to clean out this folder:
    C:\WINDOWS\temp\

    You can run CCleaner and then manually remove what ever is left.

    What issues are you still having?
     
  9. guinnessboy

    guinnessboy Private E-2

    Hi thanks for confirming that it's been cleared up. I have deleted all the temp files (excluding todays).

    My concern was that something was still preventing combofix from running, but i'm guessing there must be something, other than malware preventing it from working. I don't suppose you have ever come across this before or have any ideas as to why this is?

    Thank you again.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is rare, but it does happen, esp. with some of the newer security suites such as AVG. If you are not having any other issues, then it would be safe to say we can do the final cleanup:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds