Lost all confidence in anti malware programs. Help Please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sython, Apr 27, 2008.

  1. Sython

    Sython Private E-2

    Ok, for several days now I've noticed an increasing amount of problems which I suspect to be Malware, which started (I think) when a friend of mine installed a game and a patch (I believe to had the malware in it), on the 23rd of April.

    I have done extensive research into the majority of the problems Kaspersky, Spybot Search and Destroy and several other programs recommended by the "READ & RUN ME FIRST Malware Removal Guide," of which I have completely run through, and had a small amount of success with - (I can now 'unhide' my files and folders and also get into C drive without exploring it).
    Several dodgy programs/processes are still running, which I have found to be problematic, such as 'kxvo.exe' and 'fool0.dll' are the ones that first come to mind.

    I've almost given up and am considering doing a complete rebuild, if I can't get the situation under control soon.
    I'll post the logs which the programs created on this message and my next one.

    Thanks for all the help so far.
     

    Attached Files:

  2. Sython

    Sython Private E-2

    And here's the MGlogs.zip also requested... tell me if theres anything else I can include...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Have you uninstall these yet? If not then uninstall them to avoid reinfection. If they below are from it, I suggest you delete them immediately.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Sython

    Sython Private E-2

    Hey Chaslang,
    I'd just like to say thankyou so much for the detailed help, I think it may have worked :)

    A message that popped up while running Getlogs.bat said:
    Since I'm not quite sure what this means I clicked OK... I just thought I should mention that, in case it changed something I should do/should have done?

    And another small thing (sorry), the Combofix.txt file was found in C:\cf\combofix.txt... I don't think that would have affected anything but as I've learned, very minor changes can make quite a difference in this area.

    Other than those small things, everything seemed to go according to plan! :cool
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the correct log. It is only a partial log. The correct log should have been C:\combofix.txt Since you did not get this log it means ComboFix did not run all the way thru and it may have left your clock set on military time. At anyrate, it does appear that it deleted the files.

    If your clock did remain on military time, you can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    3. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. Sython

    Sython Private E-2

    Sorry Chaslang!
    I just read the message about the technical support after I posted the private message... rolleyes
    I'll only reply in the forums from now.
     
  7. Sython

    Sython Private E-2

    Unknown files - I have only attached the .txt files because Regruns570.exe (which was in regruns.zip) is too big, and CF16243.exe apparently isn't the right file type to be uploaded...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you were working at other websites you may have things installed from them. In the future, you should not work on multiple websites when you have problems. Only post on one website. We did not ask you to install RegRuns or Avenger (which you mentioned in your PM - please keep all communication in the forum). You can uninstall RegRuns and delete all things related to them. Also you can delete all the files from ComboFix that you mentioned (did you run the ComboFix uninstall). CF16243.exe is from ComboFix.
     
    Last edited: Apr 30, 2008
  9. Sython

    Sython Private E-2

    Yeah sorry about that... I think I'll stick with MajorGeeks - you have been by far the most helpful.
    I did uninstall ComboFix, and the rundll32.exe errors seem to have stopped, although I'm not too sure why.

    Next time I know who to come to :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds