Completed scans, logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anon-7f4ca145be, Dec 22, 2008.

  1. Anon-7f4ca145be

    Anon-7f4ca145be Anonymized

    XP Home SP3, ran all scans, logs attached. Found Vungo, Virtumonde, etc.
    Operating much better but a couple of things happpened after running MSTools. 1) I wa sno longer able to log on as administrator, the password no longer worked, but I have fixed this. 2) what still happens however is that startup goes directly from boot screen to logon screen, the system options screen, the opportunity to select F8 for options no longer appears.
    2nd post with additional logs.
     

    Attached Files:

  2. Anon-7f4ca145be

    Anon-7f4ca145be Anonymized

    2nd set of logs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome to the forums. We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    Thanks for your patience
    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too




    2) Please go to Add or Remove Programs and uninstall the following software:

    • J2SE Runtime Environment 5.0 Update 13



    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - AutorunsDisabled - (no file)


    After clicking Fix exit HJT.


    4) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    File::
    c:\windows\system32\awtTLbYO.dll
    c:\windows\DCEBoot.exe
    c:\windows\system32\bdod.bin
    C:\sniffer.log
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5) Now Run Ccleaner!

    6) NOTE: There is a new version of MGTools.exe available ... you should delete the old MGTools.exe and the MGTools folder and run the new:

    7) Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. Anon-7f4ca145be

    Anon-7f4ca145be Anonymized

    Completed rerun per instructions, new logs uploaded. Two issues during scans to report: 1) the first run of MGtools did not open an HJT like windows that allowed me to fix the three items you identify, so I ranthe current version of HJT myself. The log attached is AFTER the fix. 2) during the run of Combo fix, I forgot to disable all start up files, so programs ran in the system tray, inlcuding Trend Micro, so I reran the script a 2nd time, this time after all start up programs had been disabled. Both logs are attached.

    Thanks for your help. If clean of virus/spyware now, there are two issues I would like to fix that have occurred during the cleaning process.
    1) msconfig cannot be found now, and
    2) the black screen between the boot screen and the logon screen that display the operating systems choices with a 3 second countdown no longer appears. I believe that this is tied to a Normal start up in which the check box for the Boot.ini file is unchecked, but since I can't find msconfig now I can't confirm this.
     
  6. Anon-7f4ca145be

    Anon-7f4ca145be Anonymized

    log set 1
     

    Attached Files:

  7. Anon-7f4ca145be

    Anon-7f4ca145be Anonymized

    log set 2
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    It sounds to me as though what you are referring to is the recovery console which you installed before running Combofix.


    !.... Let me know how things are running after merging the above registry patch.

    And good news...your logs are clean :)




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:




    Thanks
    Kestrel13!
     
  9. Anon-7f4ca145be

    Anon-7f4ca145be Anonymized

    Thanks for your help!

    The registry fix for msconfig worked fine (Combofix was the culprit). I have read everything and re-installed Spyware Blaster; I used to use it but it was recognized by Trend Micro during install and removed. I do keep S&D, SUPERSpyware and Malwarebytes installed on an external drive and use them as redundant scanners because I know that no virus program is 100%. I use to use Norton but had to reinstall windows twice so I changed to Trend Micro. I may have to reconsider it now also. It was disappinting that TM did not find ANY of the infected files found by the programs you recommended.

    One thing I might recommend you advise. I have Comodo Firewall running in learning mode. It interfered with a number of the tasks you asked for by asking for permissions, particularily Combofix. Also, Combofix asks that no programs run while it is preparing the log file, but if you have programs in startup, such as anti-virus, they will run. I recomment that when Normal mode is selected in msconfig, all start up programs be disabled also. So it might be wise to do the cleaning disconnected from the internet?

    I am also going to run Windows XP repair then do a Windows update before anything else.

    Thanks again for all your help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds