I'm infected again....

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rayster, Feb 9, 2008.

  1. Rayster

    Rayster Private E-2

    Hello sir abri and sir chaslang! Its me again :D

    Well, I got infected again from my own Flash Drive which I use from our school.
    Its seems that some of the computers at school is infected by spywares.

    My Flash Drive can't be open by clicking. I can open it in Window Explorer.
    So what I did with my Flash Drive is Back-Up the Files and Format.
    And any idea how can I clean my Flash Drive? Simple scanning from Kaspersky won't clean 100%.

    I already have Kasperksy Anti-Virus, COMODO BOClean Anti-Malware and Spybot.
    Maybe I forgot the Firewall?

    And here's my new log files.. Tnx again ;)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you did forget the firewall and who knows what else from the How to protect yourself thread was not followed.

    You are back with apparently the same problem statement as last time. I suggest that you now delete all the files you backed up from your flash drive and disgard the flash drive too. Then I suggest you follow ALL steps below.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
    O4 - HKCU\..\Run: [kxva] C:\WINDOWS\system32\kxvo.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now I suggest that you get someone to properly clean the school PC's where you believe you are getting reinfected.

    Now complete 100% of the steps in the below link! If you do not complete these steps, we cannot continue to help you:

    How to Protect yourself from malware!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. Rayster

    Rayster Private E-2

    Sir Chaslang,

    Is there any other way than deleting my files from my USB Flash Drive?
    Because I got some important files there. Comodo Firewall really hog my system when I start.

    Also, how do I use this COMODO BOClean Anti-Malware? I can't seem to find any button for scanning my system. Its just seating in the system tray doing nothing.

    After 30 days of trial of Kaspersky, is there any way I can used it again? I don't want to buy it. Is there any safe way? Kaspersky is one of the best Anti-Virus out there.
    If the answer is none, what Free Anti-Virus from the list can you recommend?

    Tnx again. Here's the new log files.

    I can't find the Avenger log files, but I'm sure it deletes the files you just put.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your flash drive seems to be how you said you are getting infected and you are the one who implied you could not scan it. Did you actually try having an antivirus and antispyware program scan it?

    All protection software will impact startup time. It is a price you pay for protection. Or would you prefer to spend much of your time in forums like this trying to recover from the problems that malware has created on your PC.

    It is only a realtime protector. It is not a scanner. It's goal is to stop things from getting on your PC in the first place. Use other free scan only prorgams for scanning or use another realtime blocker that also has scanning capabilities. You don't have a lot of choices in the the Free list.

    No!

    They are listed in the How to protect yourself link already given.

    Then it did not run properly and you may still be infected. Shut down all protection software and try the Avenger fix again.

    Where did the below file come from:
    C:\evkq381.com

    You should delete this file.

    Also you have two other new infected files you need to delete. Delete the below
    Code:
    C:\WINDOWS\system32\
    fool0.dll     Feb 10 2008       69632  "fool0.dll"
    ieso0.dll     Feb 10 2008       66048  "ieso0.dll"
     
  5. Rayster

    Rayster Private E-2

    I think it is ok now. ;)

    Its fine now. As long as I start my pc and wait a minute until it is stable.

    Ah thats why. Now I understand

    I guess when my Anti-Virus expires I should get a Free Version.

    Like you said, there isn't 100% Anti-Virus out there, so I guess I should choose what suits me.:)

    I just run the Avenger again, but this time after I click the "Stop Light" Button it disappears and didn't prompt my pc to restart.
    This one is ok.

    Done.


    Sir, right now my pc is running fine. I just uninstall my COMODO BOClean and replace by AVG Anti-Spyware Trial. It does detect some minor cookies and spywares from my pc.

    Here's my collection team against viruses/viri:

    COMODO Personal Firewall
    Spybot Search and Destroy
    Kaspersky Anti-Virus Trial
    AVG Anti-Spyware Trial

    After the Trial Version of AVG Anti-Spyware I think I should stick back to COMODO BOClean Anti-Malware.

    But from the list sir of Free Anti-Virus, which do you think is the best that suits my pc? The one that is not resource hunger and can detect viruses like Kaspersky?

    I need recommendation because I'm confused to choose.

    Sorry for being hard headed and careless about my pc, its just accidents sometimes happen. Beyond my control.
    This time I will take your advice seriously so that I will not suffer anymore.

    Thanks for the reply sir and here's my new log files. ;)
     

    Attached Files:

    Last edited: Feb 12, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are you referring to when you said
    Hopefully not the C:\evkq381.com file as it was one of the files related to your infection. It came along with the kxvo.exe file. They typically are seen together with the same date, time, and file sizes. Like this:
    Try AVG Antivirus.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  7. Rayster

    Rayster Private E-2

    Sorry for the late reply sir.

    And thank you for the fast reply. Really appreciate it :D
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds