Lactrain - Malware Removal Log Review (Request)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lactrain, Apr 2, 2012.

  1. lactrain

    lactrain Private E-2

    Recently been attacked … with what, I am not sure. I know I was left with a limping PC with a bunch of malfunctioning software programs. My PC is a built PC.

    First I noticed I had a redirect problem and followed the instructions from this thread Fixing Google Redirection/hijacking and other redirection problems to the best of my ability.

    Second, I completed the Read and Run Me First Malware Removal Guide, which I didn’t know about till I completed the Redirection Removal. Then I followed the directions listed in thread titled Malware Removal for my specific operating system, (XP-32bit)

    My Pc is 99.9 percent better thanks to this forum but I would like if you all could review the logs that were created.

    Note: Malwarebytes has two log files one that was created before I visited this site and read through the instructions and another after and modified its settings.

    Thank you in advance….
     
  2. lactrain

    lactrain Private E-2

    These are the logs from GooredFIx, TDSSkiller and MBRcheck per the instructions listed on the Fixing Google Redirection/Hijacking and other Redirection Problems thread
     

    Attached Files:

  3. lactrain

    lactrain Private E-2

    These are yhe logs created by ComboFix, MalwareBytes, SuperAntiSpyware, RootRepeal and MGtools per instructions from the Windows XP Malware Removal/Cleaning Procedure thread.

    Part 1 of 2
     

    Attached Files:

  4. lactrain

    lactrain Private E-2

    Part 2 of 2
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Do you have your Windows XP boot CD? We need to repair your Master Boot Record which has been modified.


    Now please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it ( if you are running Vista or Win 7, use right click and select Run As Administrator ). Did that help with your missing items?


    Uninstall the below software:
    NetAssistant

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 94.63.147.16 www.google.com
    O1 - Hosts: 94.63.147.17 www.bing.com
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [JYSiYyRGNluwQXA.exe] C:\Documents and Settings\All Users\Application Data\JYSiYyRGNluwQXA.exe
    O4 - HKCU\..\Run: [ResChanger 2005] C:\Program Files\ResChanger 2005\ResChanger2005.exe
    O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
    O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} (Java Plug-in 1.6.0_12) -
    O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} (Java Plug-in 1.6.0_15) -
    O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} (Java Plug-in 1.6.0_17) -
    O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} (Java Plug-in 1.6.0_26) -
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 2, 2012
  6. lactrain

    lactrain Private E-2

    Unfortunately I do not have the Windows XP Boot Disc ....
     
  7. lactrain

    lactrain Private E-2

    Should I complete the tasks you listed below if i do not have the boot disc?

    Are we all done considering i dont have it or is there another alternative?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. Those steps are independant of having a boot disk.

    After following those instructions and attaching the logs, see if you can do what is in the below link:

    Using ARCDC to get the Recovery Console Command Prompt
     
  9. lactrain

    lactrain Private E-2

    Installed and ran unhide.exe and and didnt experience much of a change ... I am not overly concerned with the repopulation of my start menu as I am concerned with removing potential threats. Prior to your instruction I had followed that of another (I beleive) by using a program called defogger.exe. Once that didnt work I had gone into the start menu and manualy removed all the folders that were not populated with files. So after running unhide.exe there were not many remaining folders in the start menu to repopulate....if that is what you were trying to resolve.....Sorry!

    You asked to uninstall NetAssitant but i didnt see any instruction on how to do so... it was not a selection in ad/remove programs.

    I ran MGTools/HiJackThis as you instructed. I was not able to see all all the selections you listed but removed the ones that were. Ill include an image of the selections I chose.

    I followed the directions and copied the text and dropped it into the Combifix.exe program like you instructed. The program started but seemed to have stalled. I exited all antivirus and didnt receive any errors. I just got a blue DOS screen and it remained there. I dont recall exactly what the screen said but something like "program should take 10 min but could double depending on severity" I had ran it for almost an hour before I had to back out. The only thing I noticed was the flashing cursor and an error message when I exited saying the program needed more time.


    I uploaded and ran ARCDC and was able to burn, test, and boot to my DVD rom drive successfuly.

    Len
     

    Attached Files:

    Last edited: Apr 4, 2012
  10. lactrain

    lactrain Private E-2

    My PC was running rather fast (normal) prior to creating the boot disc now it seems to be hanging when surfing and opening programs ... Malware bytes isnt kicking out warning for webpages accessing the internet like before I started the process .... I am pleased with progress.
     
  11. lactrain

    lactrain Private E-2

    Ok after a couple of restarts ... she seems to running well ....
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Now insert the ARCDC CD-ROM you just created into the CD-ROM drive, and then restart the computer.
    • If your PC is not booting from the CD, you need to change the boot order:
      • Restart your PC
      • As soon as you get an image, press the Setup key. This is usually F2, or Del. On some machines the key can also be a different one. It should, however, be stated on the screen which key is the setup key.
      • Once you enter the computer's BIOS, use the arrow keys and tab key to move between elements. Press enter to select an item to change.
      • Navigate to the tab, where you can set the boot order. It should be called Boot or Boot order
      • The tab should now show your current boot order.
        If the CD-drive is not at the top, please navigate to the CD-Rom drive with the keys arrows. Then move it to the top of the list. The keys for switching boot position are usually + to move up and - to move down. However they can be different, but they should be stated in the help, so that you can find them easily.
      • Once the CD-drive is on top of the boot order, navigate to Exit and select Exit saving changes.
    • Your PC should now boot from your CD.
      Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
    • When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
    • When prompted to choose a windows installation, type 1 and press enter.
    • When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.
    • Now a command prompt will open and you should see the below:
    C:\WINDOWS>

    Type fixmbr and press enter. If you get a warning about non-standard or corrupt MBR, just continue UNLESS you use drive encryption!

    Type exit and press enter to restart your computer. Boot into normal Windows.

    Re-Run MBRcheck and attach a new log.
     
  13. lactrain

    lactrain Private E-2

    Mission accomplished ....
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great. Are you having anymore malware problems?
     
  15. lactrain

    lactrain Private E-2

    No, I beleive im in preety good shape here. My office programs open quick, both ie and firefox are are loading well, no more system errors on restart, and malwarebytes has not notified me of any pages trying to access the internet ....

    My only concern now is what to do with all the diagnostic programs we utilized...and what should I keep and run to further protect me in the future Hopefully you could advise me on how to set the protection programs so they operate efficiently.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think the below should address your questions. ;)



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. lactrain

    lactrain Private E-2

    Thank You!​


    Chaslang and Majorgeeks.com! Your services/advice have been greatly appreciated.​
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds