2008 Antivirus

Discussion in 'Malware Help (A Specialist Will Reply)' started by DRUMMERBUM, Sep 16, 2008.

  1. DRUMMERBUM

    DRUMMERBUM Private E-2

    As far as I can see it, I have 2 options.

    A) throw the computer off the roof
    B) throw myself off the roof along with the computer

    I followed the xp cleanup instructions (except didn't do windows recovery tool etc.) and i gained control of my internet connection again. The desktop is just a regular screen. 2 question and 3 comments.

    1)When i ran Combo fix it rebooted the computer because it said there was a rootkit running, but then it launched and ran when the computer started back up. Is this an issue based on logs, and should I rescan with some of the rootkit resources on this forum?

    2)Based on my logs (if they're clean...or at least functional), are there certain steps to clean the 5 removal programs off my cpu that are specific to this computer? Or should I just add/remove programs and use their uninstall feature.

    3) Why the hell people post on this forum without even making anything that could even be misconstrued as following the cleaning steps is beyond me...you guys should just autodelete their post, and keep doing it until they actually follow instructions/stickys.

    4) The bluescreen that I got during super anti spyware wasn't a real blue screen of death, i just hit ctrl alt delete and it popped right back...the only reason I did this is because it found a file called something like "NotHarmfulBlueScreen.jpg" or something (which maybe you can find in the logs)...which was obviously sarcastic and just plain mean because blue screens suck.

    5) Thanks for your help and resources...you guys rock.

    And as reference, I got this little beast downloading the automatic scanner for my video card driver from nvidia.com. As soon as I downloaded the Javascript (was only their page up still) a pop up popped up that I couldn't cancel from, so ended the most unfamiliar process which killed it...but also happened to **** my computer. They must have installed the old version of Java I guess. Weird too, I own a porn store and have to look at bad stuff all day...but the thing that did me in was trying to download a driver for my video card...weird how the world works!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually you are fairly clean...just a few things to address:

    Do you know what this is, and if not, remove it:
    C:\Program Files\nseswxdu.txt

    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Drivers::
    xexntfjd
    
    File::
    C:\WINDOWS\system32\drivers\xexntfjd.sys
    
    Folder::
    C:\Temp
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.

    Be sure to tell us how things are running.

    NO....the driver we are removing is the last of it.

    If you are referring to the programs we had you download, we will address that in the final instructions after we are sure you are clean.

    LOL....if only....
     
  3. DRUMMERBUM

    DRUMMERBUM Private E-2

    Things seem to be running fine. I have a blue screen for a desktop (the good blank kind!) Everything run and logged like you asked. Hopefully I went from fairly clean to clean as hell...lemme know and thanks again!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a few more things to do:

    C:\Program Files\---> all the jpg's should be put in a folder.

    Please download LSPfix from here:
    http://www.downloads.subratam.org/lspfix.zip
    Unzip it to the desktop and run it. Then click Finish to allow LSPfix to rebuild the LSP chain.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\Documents and Settings\Owner\WINDOWS\System32\smss.exe
    C:\Program Files\support.com
    C:\net_save.dna

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  5. DRUMMERBUM

    DRUMMERBUM Private E-2

    Was not able to find C:\Documents and Settings\Owner\WINDOWS\System32\smss.exe...did a search for smss.exe as well and wasn't able to find anything. Other 2 files I was able to find and delete not a problem. Attached is the current log from MG tools. Thanks!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Much better...:).

    Now let's clean up some:

    Please find and delete: C:\Temp

    Now download and install:
    Java Runtime 6

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message. then it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:

     
  7. DRUMMERBUM

    DRUMMERBUM Private E-2

    It failed to initialize properly. Whats the deal with this part of the code...I've never had (or do i ever play to) install kazaa on this box? Just curious.

    [-HKEY_CURRENT_USER\Software\Kazaa]

    ~James
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is crap that ComboFix leaves on your system .....did you copy just what was inside the quote box? Did you save it as All FIles and name it properly?

    Try it again and let me know.
     
  9. DRUMMERBUM

    DRUMMERBUM Private E-2

    Got it, done done and done. Tim thanks for your help man, keep up doing what your doing here. Also, love the over clocking guide, I'm a gamer so there's a huuuuuge difference!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds