followed malware removal steps..gone?

Discussion in 'Malware Help (A Specialist Will Reply)' started by james6203, Feb 14, 2009.

  1. james6203

    james6203 Private E-2

    Hello-

    My wifes pc started having problems and when I ran spy bot it showed braviax infection. Removed but continued to have problems. Ran a few other programs to try and get it all cleaned up but no luck. Found your site and followed the steps.

    It appeared to have cleaned the issues up...malwarebytes and SAS showed clear. But I ran Kaspersky and got a hit for some wurldmedia files. I'll include that log as well.

    This same braviax issue infected her pc a year ago. I'm wondering if I left some trace behind that it re-infected with.

    Thanks in advance for any help you can give!

    James
     

    Attached Files:

  2. james6203

    james6203 Private E-2

    attached are two more logs...thanks
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks pretty good....let's fo this:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    c:\windows\system32\Ÿ9Ÿ9
    c:\\WINDOWS\\system32\\kxdjk.dll

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach a new log from Combo.
     
  4. james6203

    james6203 Private E-2

    Thanks for all your help!

    I copied the reg edit and got the success message...:)

    I found the y9y9 file and deleted it...:)

    I looked for the kxdjk file and cannot find it....:( Not sure why, not but it wasnt where it was supposed to be. I used the search from the start button and it didnt find it either....let me know if it could be hiding somehow...

    I ran the mgtools.exe file and have attached the zipped log....:) As I did the combo fix I noticed that you actually wanted me to run getlogs.bat...:( Should I run that now or is the log you were looking for included in the zip file I'm sending? Sorry for my confusion.

    When I ran cobo fix it told me there was an updated version but I had it run the one on my pc. Hope thats ok.

    Thanks again!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Update to the latest version of Combo....then once downloaded:

    NOTE: the file c:\windows\system32\192.168.0.103 -->remove it from the fix if you know where this came from.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    File::
    c:\windows\\system32\kxdjk.dll
    c:\windows\system32\192.168.0.103
    
    RegLockDel::
    [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D92CB6D5-4CA5-4426-8986-7B84C3B93AF7}\1.0]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{F2932214-6176-4A2D-9A77-0C79D8512D9F}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{F2932214-6176-4A2D-9A77-0C79D8512D9F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{F2932214-6176-4A2D-9A77-0C79D8512D9F}\ProxyStubClsid]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B04D7804-2128-42E3-990C-32D184464295}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B04D7804-2128-42E3-990C-32D184464295}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B04D7804-2128-42E3-990C-32D184464295}\Programmable]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B04D7804-2128-42E3-990C-32D184464295}\ProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B04D7804-2128-42E3-990C-32D184464295}\InprocServer32]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Then attach the new log from COmbo.
     
    Last edited by a moderator: Feb 16, 2009
  6. james6203

    james6203 Private E-2

    The computer is no longer starting up. It's stuck on a Windows XP page. (I think its the page that comes up right before the user icons show up). Here's all the detail of what I did.

    I deleted my combo fix and downloaded a new one from the read and run page (to get the updated version). Then copied the fix to note pad on desktop as requested. I deleted the file with the 192.168.0.103 from the fix since that is the ip adress for my network printer. Turned off Mcafee virus scan and firewall...dragged and dropped the cfscript.txt file to combo fix and it said the viruscan was still on so I cancelled out at the "do you agree page"...went back in and checked to see if mcafee was off and it was... back to desk top (no windows open) and re dragged and dropped cfscript.txt file and it took about 15-20 min or so to start counting the "completed stages"...It seemed to get through the stage count and then it shut down on its own....at start up it went to "windows xp " page and stayed there...after almost an hour I shut the pc off with the on/off button and restarted and can only get back to the "windows xp " page.

    That's where I'm at now....:cry
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your xp cd? Can you boot to F8 and try last known good config?

    Combo should not have removed any system files, unless it found one that it previously had not.

    The next thing to try if the above doesn't work is this:
    How to recover from a corrupt registry.
     
  8. james6203

    james6203 Private E-2

    This pc did not come with a backup cd. I think its on the drive somewhere.

    boot to f8 and tried last good config and got the same page.

    Its a sony pc and when I was setting it up (long time ago) it had me make a "Vaio Recovery Start up disk"...can that do me any good????
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes!!....try that. (It may give you the options to safe your data and files).
     
  10. james6203

    james6203 Private E-2

    I put the disk in and shut down..restarted .... after a minute or two of restarting (asking me to wait etc) the drive with the recovery cd opens and I get a request to "insert the recovery cd vol 1 and press ok button. The computer will restart" .. I don't recall any "recovery cds".

    The "how to recover from a corrupt registry" link says the directions are not for oem software. Thats a problem for me right?? This is the original windows that came on the pc. Is there another set of directions for me??

    Any other ideas?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not getting a boot from cd message? Or are you?

    Can you borrow a cd of the same version ( home / pro )?
     
  12. james6203

    james6203 Private E-2

    No that recovery disk is no help. Will not boot. Just asks for more recovery disks.


    I can borrow a win xp home cd. Its an oem disk.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and try it...nothing to lose at this point. :(

    Get to the recovery console and get to the
    C:\> prompt (if it comes up as C:\WINDOWS> Type: cd \ and then click enter


    Now you should have the C:\>

    Now type: CHKDSK /R and click enter.

    Now after the chkdsk has run type: FIXBOOT then click enter.



    then exit.


    See if you can boot.


    If not, try the following to try to get to system restore:
    System Restore thru Recovery.



     
  14. james6203

    james6203 Private E-2

    Before I try these steps couldnt I use the other XP disk as a start up disk and get my data ( family pics etc ) off the hard drive?
     
  15. james6203

    james6203 Private E-2

    OK .. got back to desktop using the "system restore from recovery" link article steps...had to go back a restore point from the c:

    I've got my wife backing up all the picture files we've put off backing up for 6 months or so.

    I'll leave the pc up (just in case) while I go to work and hopefully we can do some tonight ;)... I'm thinking -- delete combo fix and re-install it and run again to get you a fresh log (along with any other logs you want).

    Thanks again for all your help and hopefully we'll talk tonight-- just let me know what you need.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....and yes, do the backup of your files. Skip Combo for now and just attach the other scans to see if you restored to a point that was also infected.
     
  17. james6203

    james6203 Private E-2

    Here are the fresh logs.

    Mcafee had a problem with one of the files in combofix this evening (remadm-prolaunch!171) so I let it delete the file and then I deleted combofix from desktop and the hard drive. I simply highlighted the file and clicked delete. Let me know if I need to do more than that to properly remove combofix...Thanks
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean...so it was a good restore point. You should uninstall Viewpoint Media Player.

    As for Combo:
    you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that were created as well asC:\WINDOWS\system32\cf27838.exe .

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.

    Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry. Go to add/remove programs and uninstall HijackThis. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip. If you are running Vista, Windows XP or Windows ME, do the below:

    • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.

    After doing the above, you should work thru the below link:

     
  19. james6203

    james6203 Private E-2

    Thanks for all your help Tim! Everything seems to be up and running well.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds