Maleware removal???? Please check my logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by lwhitneysmith, Feb 11, 2010.

  1. lwhitneysmith

    lwhitneysmith Private E-2

    Is there anything I need to do???
     

    Attached Files:

  2. lwhitneysmith

    lwhitneysmith Private E-2

    I have spent 3 days trying to get this computer clean... i have no idea if it is or how I clean it! Please help me figure this thing out! Thank you so much!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like somewhere in the middle of your scanning, some items were removed. But let's double check them.

    First use windows explorer to find and right click, then choose properties and tell me if it is signed or not.
    C:\WINDOWS\system32\C024C14085.sys

    Now uninstall your old Java:
    J2SE Runtime Environment 5.0 Update 11"
    Java 2 Runtime Environment, SE v1.4.2_03

    Please double-click the RootRepeal.exe previously downloaded.

    * Select File then Scan
    * On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    C:\Program Files\Ohtmnoauatfyz
    C:\WINDOWS\system32\mstHngern.dll
    C:\WINDOWS\Temp\HPSLPSVC0088.log
    * After Wiping all files, immediately reboot your pc!

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\program files\ohtmnoauatfyz\pvoatuv.exe
    C:\Documents and Settings\Lisa\Local Settings\Temp\TNeWC8oD.rar.part
    C:\Documents and Settings\Lisa\Local Settings\Temp\wza8a5
    C:\Documents and Settings\Lisa\Local Settings\Temp\"WZSE0.TMP
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "18gcr"=-
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "18gcr"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. lwhitneysmith

    lwhitneysmith Private E-2

    Thank you so much for responding. Seriously! I just feel so appreciative for your willingness to help. OK so I am not a computer expert, but I will give all your request my best shot. Here we go...

    First use windows explorer to find and right click, then choose properties and tell me if it is signed or not.
    C:\WINDOWS\system32\C024C14085.sys

    **I cannot find anything that would look like a signature. I looked on the other files and they had like a Microsoft thingy, so I assume this file has no signature. As a matter of fact I had to physically find the file in my windows folder on the C drive file because the search would not find it.

    Now uninstall your old Java:
    J2SE Runtime Environment 5.0 Update 11"
    Java 2 Runtime Environment, SE v1.4.2_03

    **Removed both

    * Select File then Scan
    * On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    C:\Program Files\Ohtmnoauatfyz
    C:\WINDOWS\system32\mstHngern.dll
    C:\WINDOWS\Temp\HPSLPSVC0088.log
    * After Wiping all files, immediately reboot your pc!

    **Could not Wipe Ohtmnoauatfyz file. Nor would it allow me to force delete.
    Could not find the HPSLPSVC0088 file.
    Did not find the other file mstHngern.dll

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    I am going to try to set my computer up as before I started your five step process to remove malware. Right now every program we use is in the start up tray and causing a slow start up. The constant running of my computer seems to have stopped for now. I need to check the sys restore settings and check and see if there are any new security patches for my router. Please let me know what you find? Should I turn my computer off? Turn my Internet connection off? I am just going to wait until I hear back from you.... I guess I'll get a beer! LOL! Thanks again! Lisa View attachment ComboFix.txt

    View attachment MGlogs.zip
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, let's have you do this. Use windows explorer to find and then rename this file:
    C:\WINDOWS\system32\C024C14085.sys --> right click and choose rename. Then just all .old to the end so you have:
    C:\WINDOWS\system32\C024C14085.sys.old

    Now lets speed things up a tad ( In the future, you can use Startup_CPL ):

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    C:\WINDOWS\ka.ini
    c:\program files\Ohtmnoauatfyz
    
    Folder::
    c:\program files\Ohtmnoauatfyz
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. lwhitneysmith

    lwhitneysmith Private E-2

    Tim I got the blue screen during the Combo fix.... should I shut down my computer and try again? Everything worked fine until this step.... help! Thanks Lisa
     
  7. lwhitneysmith

    lwhitneysmith Private E-2

    OK Tim. Rebooted after the blue screen of death and re-ran the ccleaner and the mglogs. I really have no idea how my computer is preforming at this time. I am a litle gunshy to just start up any old program. I do not want to spread the infection any further (If that is possible!) So I am waiting til we get it cleaned out. But if you give me the go ahead.... I'll give it a shot. Based on what you have found on my logs, do you think anyone have taken any of my person information? Do I need to change passwords and bank accounts, ect?

    I have attached my logs as you have requested. Thank you so much for your help. Will the start up CPL help my computer NOT load up all these programs at start up? I will add it as soon as we are finished cleaning up my mess. Again, thanks and you RULE!

    Lisa
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. You should not be having any malware related issues now. I don't think any personal info was compromised, but it is always a good idea after an infection to use a different computer to change passwords on any online accounts.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for
      scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are
      useful as backup scanners.They do not use any significant amount of resources ( except a little disk
      space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK.
        Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the
      C:\MGtools\enableUAC.reg
      file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file
      to run this cleanup program that will remove files and folders related to MGtools and some other items
      from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to
        Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds