Am I clean from Windows Secrity Alert and Freeze.com?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Keyz, Nov 25, 2010.

  1. Keyz

    Keyz Private E-2

    I just got slammed with both of these earlier this evening. I had to boot into safe mode on windows 7 on my laptop to get rid of the Windows Security Alert virus, but when I restarted into normal mode, I couldn't get onto the internet thanks to Freeze.com, so I removed that via add/remove programs and then had to change my internet from using a proxy to get online. I ran all of the scans but cannot tell if I'm finally clean. The only one I had a problem with was Root Repeal. When I started it, I got a RootRepeal Error: FOPS - DeviceIoControl Error! Error Code - 0xc0000024. Extended info (0x000000dc). When I tried to run a scan on my C drive, I got this message: Could not initialize driver! Please contact author! I hit OK and got: could not scan drive C (error 0xc0000024).

    Any help is appreciated!

    Keyz
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Looks like ComboFix deleted the below files which are for your Toshiba PC
    Code:
    c:\programdata\xp
    c:\programdata\xp\EBLib.dll
    c:\programdata\xp\TPwSav.sys
    Did you make this xp folder yourself or did Toshiba do this? Either way it was a bad idea as it looks like malware since this is not a valid Windows folder and naming it xp makes it look like malware especially since you have Win 7. These will need to be restored if you need them.

    You have left overs from Norton Internet Security but are now using AVG. Norton needs to be removed. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:23012
    R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - (no file)
    R3 - URLSearchHook: (no name) - {9565115d-c7d6-46d3-bd63-b67b481a4368} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Updater For PassionUp Toolbar - {9A782146-1AEF-4ebc-9641-D4309F8A67A4} - (no file)
    O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
    O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Users\tinknkeyz\Local Settings\TEMP

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Keyz

    Keyz Private E-2

    I followed all the steps and here are the two logs you requested. I wanted to say thank you. I wasn't aware that when I uninstalled Norton that it left some traces behind. Everything seems to be running well now.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You did not address my concerns about those files ComboFix deleted that may be for your Toshiba PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds