Log for review please...

Discussion in 'Malware Help (A Specialist Will Reply)' started by drivenlegend, Apr 1, 2009.

  1. drivenlegend

    drivenlegend Private E-2

    I'm working on a friend's computer, it had some infections that Norton's boot scan caught, the pc normally runs Trend Micro. I tried to download and run Malwarebytes, combofix, etc and none of them would run. They would install but not run. I was able to run MGTools and am going to load the zip. Any help would be appreciated.

    Another oddity... when I tried chkdsk on startup, it would not because it listed the C drive as RAW. Everywhere else it show it as NTFS, and the computer runs fairly well.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this and then see if you can run the other scans:

    Please make sure msconfig is set to normal startup.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\Tasks\At1.job
    C:\Documents and Settings\Special K\Application Data\tbiprumc
    C:\Documents and Settings\Special K\Local Settings\Application Data\9F361520-DEC1-4E1E-BC55-FB3C408E978B.txt
    C:\Documents and Settings\Special K\Local Settings\Application Data\tbiprumc
    C:\WINDOWS\svcho.exe
    C:\WINDOWS\syssvc.exe
    C:\WINDOWS\SYSTEM32\ehyduxe.dll
    C:\WINDOWS\system32\sdra64.exe
    C:\WINDOWS\system32\lowsec
    Let me know if you have trouble deleting those.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Special K\Local Settings\Temp\

    Reboot and download and install:
    Java Runtime 6

    Now see if you can run SAS, MBAM and Combo. If so attach the logs.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
    Last edited: Apr 5, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds