Hey Mr. Chas..

Discussion in 'Malware Help (A Specialist Will Reply)' started by AlwaysInfected, Mar 19, 2008.

  1. AlwaysInfected

    AlwaysInfected Private First Class

  2. AlwaysInfected

    AlwaysInfected Private First Class

    I just ran CF the old way, double clicked n let it run.

    I dont have any major issues to my knowledge, Iv'e been getting issues with MSN Messenger, I believe it was due to DL'n smileys from a msn smiley site n when i went to DL n install to the messenger AVG detected 2 trojans...

    The continuing issue iv'e been having is that when MSN messenger goes to open, the interface doesnt load. The icon just rapidly blinks in the tray n then in the task manager it will load like 5 msnmessenger processes. I don't get any pop up errors tho.

    My resolve has been to keep it uninstalled. But I need to get it back on n working properly because it's someone elses in the hous's main messenger.

    Disregard this as a bump I am just updating with logs n hopes that u may find the solution, thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You are not following the instructions. Especially the ones that are currently given in the READ ME.

    You have comboFix.exe.exe on your Desktop and currently it should be named cf.exe per the READ ME and the instructions obviously changed to use cf.exe instead of combofix.exe from the run box. But since you named it incorrectly with two .EXE's instead of one, even the old instructions would not work. You must make sure you are always using the current online version of the READ ME which you apparently are not doing since you did the ComboFix part wrong. Also you did not uninstall Viewpoint Media per step 1 of the READ ME and you did not download install and run SUPERAntispyware which was required before running ComboFix. Thus you need to start over and get the correct process run and attach new logs including the SUPERAntispyware log.
     
  4. AlwaysInfected

    AlwaysInfected Private First Class

    I dunno how u figure i have Combofix.exe.exe when clearly it says Cf.exe unless you are telling me that the .exe after the "CF" is unecessary which is something that I was unaware of....:confused

    Anyhow I will do it all over this time n correctly. Do you know if i even need Viewpoint media player? Whats its purpose?
    Thanks for your time n patience...
    Bless,
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is a direct quote from your newfiles.txt log (inside the MGlogs.zip file) and this was run after ComboFix. This is where I got the info from
    Code:
                                                                                  
    Locating all files in C:\Documents and Settings\Owner\Desktop                                   
    "C:\Documents and Settings\Owner\Desktop\"
    ad-awa~1.lnk  Jan 24 2008         861  "Ad-Aware SE Professional.lnk"
    bizzy_~1.mp3  Aug 30 2007     5529536  "bizzy_bone___trae-thug__til_i_die-rgf.mp3"
    BOOKS         Feb 24 2008              "books"
    ccleaner.lnk  Jan 27 2008        1548  "CCleaner.lnk"
    combof~1.exe  Mar 19 2008     1599141  "[B][COLOR=darkred]comboFix.exe.exe[/COLOR][/B]"
    error.jpg     Mar 19 2008      131316  "error.JPG"
    joe-bu~1.mp3  Mar 19 2008     4533895  "joe-budden_-_touch_and_go.mp3"
    MYTUNEZ       Oct 21 2007              "MyTunez"
    NEWFOL~1      Mar 14 2008              "New Folder"
    pauloa~1.mp3  Mar 17 2008    10110976  "Paul Oakenfold - Legacy (Junkie XL Remix).mp3"
    SECURI~1      Jan 24 2008              "Security Appz"
    spywar~1.lnk  Jan 27 2008         690  "SpywareBlaster.lnk"
    thumbs.db     Mar 17 2008       91648  "Thumbs.db"
    Out of tens of thousands of people whose PCs we fix, only one said they ever used Viewpoint and that was rarely. Read the info in the READ & RUN ME link in step 1. Specifically this link Uninstall Malware via Add/Remove Programs see the info on Viewpoint.
     
  6. AlwaysInfected

    AlwaysInfected Private First Class

    Aight man. I finally got everything done n properly this morning off a cold startup before any other activity online. Thanks for your patience. I deleted the old ComboFix.exe, DL'd a fresh new one n this time everything ran accordingly with no issues.

    Here is my 3 logs in order of use... Super, Combo, N MG...:major
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have Messenger Plus! Liveinstalled which we indicate in the READ ME should be uninstalled. This program is the cause of tens of thousands of PCs getting infected with LOP and/or Virtumonde which you may have picked up from it too. You should uninstall this application immediately.


    I also advise against using things like below
    Absolute Poker
    Full Tilt Poker
    PartyGaming
    PokerStars
    UltimateBet

    Is the below from something you installed?
    C:\Documents and Settings\Owner\Application Data\ooVoo Details


    Now we need to use ComboFix to remove some files and registry keys.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. AlwaysInfected

    AlwaysInfected Private First Class

    Whatup Chas. Thanks for your time n instructions. Far as Poker Software goes. I know that atleast from my 3-4 year experience that FullTilt Poker is a safe n secure software. Now PartyPoker Not so much. Heres why...

    Im in Europe and so some sites don't offer to U.S players anymore like PartyPoker. Now like i said Iv'e only used FTpoker before along with many other friends n people I know all with no issues what so ever either with the software or any kind of spaming or advertising its a clean application.

    What i did notice with PartyPoker when i DL'd it here in Europe was that when i went to DL it so i could play it (Since Im currently in Europe n had access) was that I could not install it due to AVG detecting a DLL trojan horse of some sort. So i called Support n they assured me that it wasnt a virus n that i needed to turn off AVG as it interfered with the DL n let it go through n that i wouldnt have any issues... Somehow it seemed ok but that whole situation never sat well with me regardless even when reassured by PartyPoker Telephone support numerous times....

    Anyhow I assumed the issue i mighta had is what u mentioned is the probable cause. I had installed messenger Plus. I actually never use MSN mEss as i don't like it. It's a bulky, heavy juss uncessarily extension filled app that never liked. I use Aim. loads n utilizes alot easier n simpler. I can tab all my chats vs having multiple chat boxes with MSN. My mom is the one who uses MSN Mess so i gotta keep an eye on her use...

    So yes messenger plus is now gone, could u tell by my logs if it actually infected me with the above mentioned Malware? Lop or virtumonde? I haven't had any other issues on the computer with error messages or anything besides the messenger n at that its when it tried to load automatically it would rapidly blink in the task bar... Should be ok now that plus is gone...

    Oh n yes my mom deciding (god knows why) to install another Messenger called ooVoo) I got home n was like "why? you already have MSN why risk DL'ng something u know nothing about because someone told you it was cool?"
    Things like this get me furious.. lol. I had uninstalled the messenger but apparently u can still see something lingering behind? what do i do? Go to the program files folders n remove any other files related to it?

    Will give u those new logs asap as well as a short review.
    Sorry for the essay...
     
  9. AlwaysInfected

    AlwaysInfected Private First Class

    Here are my new logs..

    PS. I believe ESET is NOD32 Files. I don't have it installed but it may have been from previous use.

    If you noticed that i have a Security Appz folder. I keep half a dozen ready to install apps such as Nod32, Spy S&D etc for back incase of a serious malware issue.:D
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which is why we always question these programs. Let's cleanup.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Owner\My Documents\PartyPoker\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Owner\My Documents\PartyPoker\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)

    After clicking Fix, exit HJT.


    It looks okay other than what we were cleaning.


    So are you saying that you already uninstalled ooVoo? If so, just delete the folder I mentioned and any other folders from it.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know but since it was not installed, I was cleaning up the left overs.

    You should never install an additional antivirus program while another is installed.


    You did not say how things are working. Your logs are clean other than the PartyPoker stuff already given.
     
  12. AlwaysInfected

    AlwaysInfected Private First Class

    No i meant that I keep those apps ready to go but i know that u cannot run 2 AV apps at once much less live ones like AVG n Nod32, I just have them for backup if i needed to uninstall one to work others.

    N Yes ooVoo is long gone. MSN Mess seems to be working cleaner now...
     
  13. AlwaysInfected

    AlwaysInfected Private First Class

    Ok sir, I think we covered everything. When u get a moment just followup with the proper uninstall proceedurs n thank you much.

    PS. How come (I noticed this again since the last time) whenever i run these apps i get a "Thumbs" hidden file issue? Like i get that transparent file icon put on my desktop from some where in my hidden files folders. The icon with the 2 green n orange turning teeth thingsy lol.

    ALso i noticed in my Limewire shared folder i got files i never had before which is transparent icons for Album cover art for everysong in the folder :confused lol

    Must be something to do with that thumbs icon.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you enable viewing of hidden files and folders (which is done during the READ ME) you will see things that are normally hidden. And if you have thumbnails turned on, you will see them too. If this bothers you, double click on the C:\MGtools\hide.reg file and allow it to be added to your registry. This will return things to Windows defaults.

    If you are not having any other malware problems, it is time to do our final steps:
    1. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN
      • Now type cf /u in the runbox and click OK.
      • Note: The space between the cf and the /U, it must be there.
    2. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
     
  15. AlwaysInfected

    AlwaysInfected Private First Class

    Once again Chas your time and work is extremely appreciated! What you do here is a blessing to us all!
    Thanks a mill!

    N yes things are running a bit smoother in general now period!
    Thanks again!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds