.exe malware problem hopefully solved

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peeksnit, Mar 3, 2012.

  1. Peeksnit

    Peeksnit Private E-2

    Hopefully problem solved. My son's pc was not able to find exe files and when I found them without the .exe extension I could only open as administrator (which I was anyway). Everything is running smoothly after completing the README steps and eventually running the first two apps....Superantispyware (no change) then Malwarebytes which identified a problem with malware that was affecting .exe. I am looking for your guidance as to whether I should continue since the problems seems to have been resolved.

    I now see I am supposed to continue on but need to call it quits for the day. I have attached both logs as instructed and anxiously await your response in case you feel I am good to go.


    As always....GREATLY appreciate MajorGeeks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need the rest of the logs from ComboFix, RootRepeal and MGtools to properly inform you of your status. Nothing was found in the two logs you attached.
     
  3. Peeksnit

    Peeksnit Private E-2

    I posted the wrong log for MB. Here is the original that hopefully identifies the problem that was listed after the run. I originally attached the log from a subsequent MB run.

    Glad to march on if that is what it takes and thanks for your quick reply.

    tdi
     

    Attached Files:

  4. Peeksnit

    Peeksnit Private E-2

    Here are the final 2 logs for ComboFix and MGTools. I have 32 bit so did not run RootRepeal.

    Also please note my last post had the original MalWare Bytes log indicating what was found. Original post included second log after ran again and clean.

    As always, greatly appreciate your help.

    Tdi aka Peeksnit
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You meant you have 64 bit. ;)

    You are in pretty good shape. Just a few minor things to fix.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix, exit HJT.

    Then delete the below two files
    C:\Users\Braden Inskeep\AppData\Roaming\Microsoft\Windows\Templates\jmg5b4x3xvhi
    C:\ProgramData\jmg5b4x3xvhi

    Also I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing. For example, the below are file I suggest moving off your Desktop.
    Code:
    ----a-w            76,819 2010-10-23 21:42:17  C:\Users\Braden Inskeep\Desktop\angryhitchu.wma
    ----a-w            36,409 2010-10-23 21:40:40  C:\Users\Braden Inskeep\Desktop\ANNNNGRY.wma
    ----a-w            31,919 2010-10-23 21:41:36  C:\Users\Braden Inskeep\Desktop\annnnnnnnngry.wma
    ----a-w           328,259 2010-10-23 21:59:24  C:\Users\Braden Inskeep\Desktop\Chem song.wma
    ----a-w               312 2010-07-29 12:25:25  C:\Users\Braden Inskeep\Desktop\Curse Client.appref-ms
    ----a-w           112,739 2010-10-23 22:11:06  C:\Users\Braden Inskeep\Desktop\deedeeddedeedw.wma
    ----a-w           278,869 2010-10-23 21:53:12  C:\Users\Braden Inskeep\Desktop\END of ze show.wma
    ----a-w        15,792,320 2012-03-02 20:04:51  C:\Users\Braden Inskeep\Desktop\Firefox Setup 10.0.2.exe
    ----a-w            75,548 2010-10-24 15:29:19  C:\Users\Braden Inskeep\Desktop\Mole movie!.wlmp
    ----a-w     2,611,185,578 2011-10-06 23:21:56  C:\Users\Braden Inskeep\Desktop\MSSetupv101.exe
    ----a-w     2,101,017,712 2010-08-23 20:52:44  C:\Users\Braden Inskeep\Desktop\MSSetupv89.exe
    ----a-w       127,622,152 2012-03-03 18:20:29  C:\Users\Braden Inskeep\Desktop\N360-ESD-19-5-1-2-EN.exe
    ----a-w           332,749 2010-10-23 21:58:18  C:\Users\Braden Inskeep\Desktop\RECK ASTLEY.wma
    ----a-w         4,036,040 2010-12-07 22:47:40  C:\Users\Braden Inskeep\Desktop\sp48758.exe
    ----a-w            10,179 2010-08-12 00:57:22  C:\Users\Braden Inskeep\Desktop\The apple falls not.docx


    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. Peeksnit

    Peeksnit Private E-2

    I could not locate C:\Users\Braden Inskeep\AppData\Roaming\Microsoft\Windows\Templates\jmg5b4x3xvhi

    Again many thanks for your help and son is moving to cleanup desktop.


    tdi
     
  7. Peeksnit

    Peeksnit Private E-2

    I used the string to uninstall combofix and did not work. Tried it several times to make sure I had the string entered correctly. I saved it to desktop originally but wondering if I did something wrong. It is sitting in "downloads" folder.

    Thoughts on how to uninstall from here?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the instructions, Combofix.exe must me directly in the Desktop folder not a subfolder. Since you put it a "downloads" folder, it is therefore not on your Desktop which is why the command cannot find it. Either insert the downloads folder into the uninstall command or put the ComboFix.exe file directly on your Desktop as requested. ;)
     
  9. Peeksnit

    Peeksnit Private E-2

    Will do. I tried to save to desktop before reading on in instructions and thought I had in fact gotten it where it was supposed to be but apparently did not. Should have checked final destination. It appeared to be on desktop but was in fact in downloads as you noted.

    Anyway, appreciate your continued support on this site.

    :-o
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  11. Peeksnit

    Peeksnit Private E-2

    Having trouble uninstalling combo fix installed (accidentally) on downloads"....any suggestions? Son going to college Sunday and no more access to pc. Is there a problem if I keep in on pc?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just delete it and any folders related to it which includes the C:\QooBox folder if found.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds