How do I know if infection is removed? Logs attached.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Alana in Canada, Feb 10, 2011.

  1. Alana in Canada

    Alana in Canada Private E-2

    Fact: I am not a geek!

    I don't know what you need to know, so I'm going to tell you everything I can think of. Sorry.

    Let me say, first, YOU ROCK! I am so, so grateful to be able to get help. Seriously. Thank you.

    History:

    Last week of January, I had various problems with the computer and flailed about helplessly until the computer seized with a screen saying "Palladium" wanted to scan the computer. I took it to a local shop and they apparently removed it.

    When I got it home, the computer immediately began having problems with a bogus homepage (wihich I fixed with help from my ISP provider). I also I began to experience google hijacking.

    Someone told me about your site. (Hooray!)

    I followed all the procedures laid out in the google hijack thread Feb 5th and 6th. Problem cleared up: THANK YOU!!

    But.

    While surfing, I kept running into a problem--AVG would detect a virus called Trojan Gen(dot)20 (I'm pretty sure that's what it said. I'm not entirely sure as I cannot find the piece of paper I wrote it down on. Oh well. Probably doesn't matter EXCEPT... I don't have the log for Super Anti-Spyware. I ran it, it found 17 infections (including Mywebsearch, (which I thought I had removed during the hijacking clearing procedures) and Palladium (for which I paid $100 to have removed!) among others. More about this below.)

    I would tell AVG to "quarantine" the item, it would tell me it could not --"Item not found" or some such thing. Computer was functional, but very slow on the internet (so I uninstalled IE and reinstalled IE8).

    Today I executed the RUN and README Malware File here on the forum.

    I did all the houskeeping tasks as directed.

    After step 4, I received to following error message which continued to plague me throughout the process:

    Windows no disk. Exception processing message C0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c

    When it came to the WindowsXP Malware Removal/Cleaning Procedures, here is what happened.

    1) Disabled teatime on spybot, as directed.
    2) Ran superAntispyware
    as mentioned, it worked really well. However, when I tried to access the program after re-boot (as directed) I received a message telling me I had had to uninstall the existing version prior to reinstalling. It then asked me if I wanted to uninstall. I pressed "cancel" and carried on.
    3) I ran malware bytes.
    4) I ran combofix after a false start.
    5) I ran rootrepeal 2x. The first time it said it could not find drive Q. I've attached the log for the first run. I can atach the log for the second run, if necessary.
    6) Ran MGTools.

    I have MalwareBytes logs from the 4th, 5th, 6th and 9th of February as well, if you need them.

    Hope that helps.

    I've uninstalled AVG, by the by, and I do not plan to reinstall it. (I did that in order to run combofix). I'll get something else from your download page.

    May I proceed to Step4, Toggle Systems Restore?

    Once again, thank you so much for everything.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh my. Sorry to hear that. :(

    Please give the avg removal tool a run.

    AVG Remover(32bit) 2011
    (avg_remover_stf_x86_2011_1165.exe)


    Uninstall all of the below listed Java, as they are outdated.

    • J2SE Runtime Environment 5.0 Update 10
    • J2SE Runtime Environment 5.0 Update 11
    • J2SE Runtime Environment 5.0 Update 9
    • Java 2 Runtime Environment, SE v1.4.2_11
    • Java(TM) 6 Update 14
    • Java(TM) 6 Update 2
    • Java(TM) 6 Update 3
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7
    • Java(TM) SE Runtime Environment 6 Update 1
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O15 - Trusted Zone: *.clonewarsadventures.com
    • O15 - Trusted Zone: *.freerealms.com
    • O15 - Trusted Zone: *.soe.com
    • O15 - Trusted Zone: *.sony.com
    • O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    ioxuoase
    ywlljn
    File::
    c:\windows\System32\drivers\ukybpcrb.sys 
    c:\windows\Hyivuyozewah.bin
    c:\windows\Ryakuvifukif.dat
    C:\WINDOWS\system32\svchost.exe.exp.log
    C:\WINDOWS\system32\shortcut_ex.dat
    C:\Documents and Settings\All Users\Application Data\812iTVW.dat
    C:\Documents and Settings\MDG User\Templates\DownloadInfo.initmp
    Folder::
    c:\documents and settings\All Users\Application Data\lJkEbOp08400
    RenV::
    c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
    c:\program files\AVG\AVG10\avgtray .exe
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    c:\program files\Common Files\Ahead\Lib\NeroCheck .exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier .exe
    c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon .exe
    c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
    c:\program files\iTunes\iTunesHelper .exe
    c:\program files\Windows Media Player\WMPNSCFG .exe
    c:\windows\ehome\ehtray .exe
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. Alana in Canada

    Alana in Canada Private E-2

    Thank you for getting back to me so promptly Kestrel13!

    A couple of stupid questions:
    1) How do I make sure that all the anti-virus, anti-spyware programs in my machine are switched off?

    2) To run MGTools--should I do it from my C drive as before--or download the above?

    Right now, it appears that things are fine. I was away from the computer for a bit, but according to my son, all was well (no annoying "You have a virus" messages popping up--they had been occurring about every 1/2hour). Perhaps that had to do with AVG, I don't know.

    Looking forward to your reply and I'll do what I can meantime. Thanks again!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do the best you can to disable them.

    You should run it exactly as I have laid out in my instructions.
    But they are not fine. There is still crap on your system.
    You're welcome.
     
  6. Alana in Canada

    Alana in Canada Private E-2

    Hi Kestrel13!
    Thanks for your reply.

    I've done my best to follow your instructions. I had some difficulty with running combofix. The first time I ran it it stalled on the screen which told me to wait for the log report. (While pop-ups were asking me if it was OK to various and such and such, I inadevertantly re-enabled the firewall.)

    I ran combofix the second time without difficulties.

    When it came to copying and pasting MBRCheck to notepad, I did it several times. I even ran it more than once: NOTHING was showing up in the actual notepad screen. Later, I discovered that I had multiple MBRCheck notepad files on my desk-top, all properly filled in. I am attaching the first one. (I can attach the others if needed)

    Let's hope everything is cleared up now. :)
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Little bit more to do. In combofix's last run it repaired an infected system file.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\$AVG
    c:\documents and settings\MDG User\Application Data\AVG
    RenV::
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "AvgUninstallURL"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. Alana in Canada

    Alana in Canada Private E-2

    Good day, Kestrel13!

    OK.

    I had to run Combofix 3x--the last time was finally sucessful, I believe, because I uninstalled PC Tools Firewall.

    However, I seem to have a lot of logs in my system and they are confusing me. I hope the one I have attached is the correct one. I did a file search and I have quite a few Combofix quarantine log files as well. What should I do with these? Can I delete all the logs on my system so that when I generate the new ones --I know without a doubt--they are the ones we want?

    I have several questions about properly restoring my computer once we are finished--but I will save them until we know everything is safe.

    Thanks again for your help!
    Hope you are having a good day.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry about the late reply. Busy weekend. Combofix keeps reporting an infected file which it said it repaired but I think we will try replacing it another way.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    RenV::
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    Fcopy::
    C:\WINDOWS\ServicePackFiles\i386\userinit.exe | c:\windows\system32\userinit.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Use windows explorer to find and delete this file if it exists. You may have to reinstall adobe reader.
    • c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. Alana in Canada

    Alana in Canada Private E-2

    As long as you had fun while you were busy, I'll forgive you. ;)

    Okie dokie, Let's hope we're in the home stretch now.

    When I removed the adobe file I had two of them: so I removed both of them.

    ETA: I just removed them from the recycle bin as well!

    Here are the logs.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exeThis file is still showing. Notice the space before the .exe

    Try using windows explorer to find it and delete it, and then regardless, uninstall adobe reader.

    Run Combofix again by double clicking it and attach the log.
     
  12. Alana in Canada

    Alana in Canada Private E-2

    Good Morning Kestrel13!
    I don't know why you were still getting the reading that that adobe file was still in the system. Perhaps it was because I did not reboot before creating the MGlogs?

    At any rate, I looked up "Windows Explorer" (since I didn't really understand what you meant by "use Windows Explorer to..." and from what I can figure out, that IS what I used when I removed it last night. I uninstalled Adobe Reader as you requested this morning, through >Start, >control settings, >add and remove programs. I hope that was all right.

    The system automatically re-started.

    Hope all is now well. Thanks for sticking with me. I appreciate your time and effort.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's better. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. Alana in Canada

    Alana in Canada Private E-2

    Hooray! I'm doing the happy dance.

    Few quick questions:
    1) Should I turn tea-timer (in Spybot) back on?
    2) Should I reverse "Enable viewing of hidden files sytems and file extensions"? (From the Run and Read me First Guide)--Never mind, I see that that is somehow automatically done when I remove Combofix?


    Thanks for everything!

    I'm looking forward to weorking through these final steps.
     
    Last edited: Feb 15, 2011
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Indeed! :-D
    If you want to yes. :)
    Most welcome. Surf safely. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds