Logs attached. Please review

Discussion in 'Malware Help (A Specialist Will Reply)' started by mudbog, Sep 3, 2008.

  1. mudbog

    mudbog Private E-2

    This is myfirends computer that wouldn't even start windows when he gave it to me. As I understand, he tried to download a program and it downloaded a virus that changed his desktop, hid many of his icons, and seriously limited access to anything else.
    I had to pull his hard drive and install it in my old tower to boot from cd. Then I repaired windows, ran through read me, and here's what I got.
    By the way, the clock is still military time after combofix.
     

    Attached Files:

  2. mudbog

    mudbog Private E-2

    SASLog
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off....it looks like this computer once had Symnatec install but was removed so you have no anti-virus installed.

    If you haven't already, please disable the Guest account in User accounts.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  4. mudbog

    mudbog Private E-2

    At the end of the getlogs.bat, I received an error message that "ProcessDll.exe" could not run. I had to close it for the getlogs to finish.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    Now we need to clean up from the scans.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you did get a success, then it is time to do our final steps:
     
  6. mudbog

    mudbog Private E-2

    everything seems to be running well. The only thing that seems to not have worked is the clock didn't change back from military time. Is there a way to manually change it back?

    Other than that you are the best and I thank you for all of your help.
     
  7. mudbog

    mudbog Private E-2

    can malware go beyond the hard drive? When I put the hard drive back in his tower, it starts at the Dell screen, then goes to the "windows was interrupted" screen. I've tried start windows normally and safe mode. It immediately reboots after either selection and repeats the same thing over and over.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This was a repair install when in your tower? It is possible that there were some system changes for you motherboard and it will not recognize its original tower...so you may need to do a repair install again now that it is in the original machine.

    As to the clock ...go to the control panel / Regional and Language / customize / Time and set it the way you want it.

    You may have to post in the software forum as to reinstalling issues back to the original machine.
     
  9. mudbog

    mudbog Private E-2

    I will post with them. Thanks again for all of your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds