Help please!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chewman, Dec 6, 2009.

  1. Chewman

    Chewman Private E-2

    Hello and thanks ahead fo time for your help.

    My Daughter loves an anime program and was trying to watch it when she downloaded 2 trojans.

    win32/FakeCog
    Win32/Allureon.bt

    Window's defender caught them and supposedly removed them. But now Java Script and Adobe flash will not work.

    I performed all of the "Mallware Removal" steps @ "Read & Run Me First".

    I still have the problems with Javascript and Adobe flash.

    SuperAntiSpyware only found Tracking cookies.

    Malwarebytes: Sorry have to post the entire thing, cant get it to copy as a file.


    I am stuck. I am not a computer sauvey person. All help needs to be step by step.

    Thanks.

    Chewman
     

    Attached Files:

    Last edited by a moderator: Dec 8, 2009
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which location did it find these threats in? Do you know the exact file path?

    I am not seeing any malware in your logs other than the adware that MBAM deleted and a couple that combofix dealth with. Is Windows Defender Still reporting problems?

    IMPORTANT:

    1. You have combofix running from the wrong location:

    Running from: c:\mydownloadedprograms\ComboFix.exe

    You need to ensure that you move it now before we continue directly onto your desktop otherwise my final instructions will not work without hitch.

    2. Please go to add/remove prograns and uninstall the below if you do not require it or find it useful:

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    • C:\Documents and Settings\HP_Administrator\Local Settings\Temp
    • C:\WINDOWS\Temp

    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    c:\program files\Viewpoint
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now and answer my questions about Windows Defender!

    Thanks :)
    Kes13!
     
  3. Chewman

    Chewman Private E-2

    Thank you for your time and help. It means a lot to me.

    As for Defender: I have no logs from Defender to look at where the 2 trojans were located. I'm also not talented like you are to know what to look at or when so I have no clue either.

    I reloaded Combofix to the desktop.

    The ASK tool bar I already got rid of. From the MajorGeeks list of junk to get rid of that I found in another post.

    Followed instructions and did step by step with CFscript.txt and once I dragged and dropped on ComboFix it self started.

    Ran MGtools\GetLogs.bat file as directed to do.

    I then tried to use Internet Explorer again, and JavaScript and AdobeFlash still don't work. They will work with Firefox.

    I have deleted IE8 and reloaded it, my computer will not allow me to delete IE7. I have deleted and reloaded Javascript and Flash and that hasnt worked.

    What do I have to do to get Javascript and Flash to work again with IE? All my kids homework they do in school is based on IE and they use IE in school.

    Javascript and Flash worked fine until the Trojans were found and deleted.

    Again Thank You very much for your help!

    Logs attached.

    Chewman
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The Ask Toolbar is still installed according to your latest logs.

    Your logs are malware free.

    Is Windows Defender still reporting finding threats or once it deleted them have you had no further alerts?
     
  5. Chewman

    Chewman Private E-2

    Thank you again for your help!

    According to Add-Remove programs the Ask toolbar is gone. If it is still showing up is it viral?

    Window's Defender hasnt shown anything since it removed the trojans, but I still cant get Internet Explorer to run JavaScript (JS) or Adobe Flash (AF) even though I am malware free.

    JavaScript and AdobeFlash were the casualties of the original malware. Once the malware was removed I can not get them to work again with Internet Explorer.

    I have deleted JS and AF and reloaded them. Deleted IE8 and reloaded. Still I can not get JS and AF to work.

    Thank you for helping me get the computer malware free. Can you help me fix JS and AF now?


    Thank you again for all your help!

    Chewman
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem :)

    Good.

    Unfortunately it's not my territory :-D I assist in the malware section and haven't been in software for a while. The guys and gals in there will sort you out ;)

    No, it's nothing to worry about, we will deal with it by doing the below:


    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enabling when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Folder::
    c:\documents and settings\Keegan.TRIPP\Local Settings\Application Data\AskToolbar
    c:\documents and settings\Ethan.TRIPP\Local Settings\Application Data\AskToolbar
    c:\documents and settings\Connor.TRIPP\Local Settings\Application Data\AskToolbar
    c:\documents and settings\Mom.TRIPP\Local Settings\Application Data\AskToolbar
    c:\documents and settings\Emma.TRIPP\Local Settings\Application Data\AskToolbar
    c:\program files\Ask.com
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Then that should be that, I will give you final steps and you can start to troubleshoot your adobe & js issues out in the software forum :)
     
  7. Chewman

    Chewman Private E-2

    Thank you so much for all the help.

    Followed instructions as directed.

    Combo fix date on log is 12-06? It's the only combofix log file found on the computer after a search using combofix as the search subject.

    Logs attached.

    Thank you again!

    Chewman
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem :)


    No it would be dated whatever time you ran the script. The log you attached was not the one I needed to see. On 8th dec you had CF running from the correct location:

    Ensure that combofix is indeed on your desktop so that the final steps I am about to give you go without hitch.

    I will not need to see the combofix log from running my latest script as it was only the ask toolbar I was removing. Your logs are clean:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. Chewman

    Chewman Private E-2

    Thank you very much!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    It really means something to me that you and others are here to help us out with this!

    Chewman
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    hehe :) No problem at all

    Safe surfing
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds