3rd machine

Discussion in 'Malware Help (A Specialist Will Reply)' started by cjon, Dec 14, 2008.

  1. cjon

    cjon Private E-2

    Good evening. Thanks for all your previous help.
    I've started on my 3rd machine. I replaced the motherboard on this machine as the result of storm damage. I started out to clean it up before I gave it back and thought I had it pretty well done. I ran my last Spybot scan and got a single hit for a Vundo registry file that Spybot couldn't remove, even after reboot. MBAM also detected it and failed to remove it. I created a regedit4 file, ran it, and that failed as well. I created a CFscript.txt file and dropped it into combofix. Combofix also failed, but it detected several things that I hadn't seen before. So, I backed out and started over. Attached are my logs. 2 things to note: I have now removed viewpoint. I thought I did before, but I guess I missed it, and there is an Antispyware (from Antispyware.com) listing in Add-Remove programs errors out when I try to remove it that way. Last log in the 2nd posting.

    CJon
     

    Attached Files:

  2. cjon

    cjon Private E-2

    SAS log attached.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    Thanks for your patience
    Kestrel13!
     
  4. cjon

    cjon Private E-2

    Kestrel,
    I fixed it myself. Go on to somebody else.
    Thanks anyway.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am sorry to have kept you waiting so long, but I do have a fix waiting for you right here. I am still in training as you may be aware and so your patience is much appreciated.
    Would you like to wait for a set of instructions for your machine that we have?

    Kes
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please go to virustotal and upload the following file:

    Virus Total


    and report back to us what the results of the online scan are.



    1) Please now disable the Guest Account if this hasn't already been done so through User Accounts

    2) Now go to Add or Remove Programs and uninstall the following softwares:

    • Java(TM) 6 Update 2
    • Ad-Aware SE Personal <---This software is old and ineffective....it can be uninstalled


    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t <---NOTE: this is NOT malware. It relates to Dr Watson which is a program error debugger for Windows, but there is no need for it to be running at start-up so include it in our fix.

    it is not a wise idea to place sites into your Trusted Zone, I would advise you to include to fix these two 015 entries.

    O15 - Trusted Zone: http://www.badaboo.free.fr
    O15 - Trusted Zone: http://www.nranews.com

    O23 - Service: The Shield Deluxe 2008 (AVP) - ALWIL Software - (no file)

    After clicking Fix exit HJT.

    4) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    File::
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\SET636.tmp
    C:\windows\system32\SET2E1.tmp
    c:\windows\system32\SET4EE.tmp
    C:\windows\SET55F.tmp
    C:\Documents and Settings\Fred\Local Settings\TEMP\7zS1F3.tmp
    
    
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint 
    C:\Program Files\AntiSpywareApp 
    
    
    FileLook::
    c:\windows\system32\LiveScan.exe 
    
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5) Now Run Ccleaner!

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Also don't forget to report back what the online scan comes up with.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. cjon

    cjon Private E-2

    Kestrel,
    My apologies for the tardy reply. By the time I got your last post, I had completed most of what you suggested and returned the computer to its owner. I tried to get him to send the livescan file, but he isn't interested. I'll see if I can get over to his house and do it myself over the Christmas break.

    In the meantime, thanks for your help. Have a great holiday season.
    CJon
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome cjon. Thanks for letting us know!
    Seasons Greetings to you and yours :wave

    Kestrel13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds