Am I Clean Now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by dlmcmurr, Jul 23, 2010.

  1. dlmcmurr

    dlmcmurr Private E-2

    Working on a friend's WinXP Media Center PC and cleaned up a number of infections. I've run all your steps again and attached the logs from the last run. Gone to bed now and will check back tomorrow.

    Thanks,
    Dave
     

    Attached Files:

  2. dlmcmurr

    dlmcmurr Private E-2

    5th attachment
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not quite...

    Use windows explorer to locate the following file:

    C:\Qoobox\Quarantine\C\Documents and Settings\Teresa McNeely\My Documents\registry backup 2010-07-22.reg.vir

    Rename it to disinclude the .vir extension, and move it back to it's original location of:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    jmgfsqne
    
    File::
    c:\windows\system32\drivers\jmgfsqne.sys
    
    Folder::
    c:\documents and settings\Teresa McNeely\Local Settings\Application Data\kxkulkdtd
    
    DirLook::
    C:\KA
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running now please. :)
     
  4. dlmcmurr

    dlmcmurr Private E-2

    Did as requested. FYI, both times I ran ComboFix, I got an error "PEV.cfxxe encountered an error and had to close". Also, the registry backup file was one I created before I did some registry editing. I'm fine with just deleting it.

    Thanks,
    Dave
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What do you know of the contents of this folder?:

    c:\ka\KG

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\ka\KG\KG.EXE
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
     
  6. dlmcmurr

    dlmcmurr Private E-2

    I'll do the additional scan in a few days. I took it back to the owner this afternoon. Will get back with you by the weekend.

    Thanks,
    Dave
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. I will be here waiting. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds