malware problem need spyhunter compact os

Discussion in 'Malware Help (A Specialist Will Reply)' started by cabbie1985, Jun 24, 2009.

  1. cabbie1985

    cabbie1985 Private E-2

    hi i have a pretty major problem with my cpu..
    i dl'ed a video which asked to update codec before it would play
    something like "windows dixv codec update" (stupid i know)
    upon reboot screen froze with mouse cursor unmoveable at windows loading screen...
    got in thru safe mode but still cant move mouse.
    system restore wont work (using all keyboard hot key)
    mcafee wont load, nor will malwarebytes, or combofix, or spybot
    i had an excellent experience with spyhunter 3 before so i installed that.
    after instalation it found a rootkit but cant download spyhunter compact os
    trying to find download on another cpu but cant
    the other option is any rootkit remover from recovery console
    thanks very much,
    bob
     
  2. cabbie1985

    cabbie1985 Private E-2

    ps reason cannot dl'ed spyhunter compact os internet explorer affected by rootkit
     
  3. cabbie1985

    cabbie1985 Private E-2

    sorry for extra posts but rootkit info:
    file: windows/system32/drivers/MSIVXpkcjmtauhwuhdtppqyvjeejsykdjelwy.sy
    key: system\controlset001\services\MSCIVXserv.sys
    key: system\controlset003\services\MSCIVXserv.sys
    can just delete them directly?? dont think so
    otherwise spyhunter compact os will work if someone has link or other info
    once thank you in advance
     
  4. cabbie1985

    cabbie1985 Private E-2

    just fyi i managed to fix this problem on my own
    i downloaded the newest version of combofix and rootrepeal on another computer and put on a flash drive. neither would run still, however i rebooted into safe mode and changed the names of the .exe (example combofix.exe was hjf.exe or something) got both to run combofix removed said file (MSIVX...), fixed mouse by unplugging and plugging back in
    ran malwarebytes after reboot came up clean
    here are logs for anyone interested: combofix:

    ComboFix 09-06-23.01 - Administrator 06/24/2009 21:53.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.293 [GMT -4:00]
    Running from: K:\hjh.exe
    AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .


    cpu is running fine now
    one question is about file in report from rootrepeel:
    c:\windows\system32\6f.tmp
    safe or not?




    ADMIN EDIT: Please read and follow the following READ & RUN ME FIRST. Malware Removal Guide and HOW TO: Attach Items To Your Post, many thanks.
     
    Last edited by a moderator: Jun 25, 2009
  5. cabbie1985

    cabbie1985 Private E-2

    sorry about that, was kind of panicked at the time
    seen rootkits before but never one that severe
    i attached the logs
    now as i said cpu is running fine now just wondering about the 6f.tmp in rootrepeel report, none of the other porgrams i ran (spybot, malwarebytes, or combofix) mentioned it. sorry but i didnt save the malwarebytes report
    at the least i was hoping this info maybe helpful to you for diagnosing other problems in the future
     

    Attached Files:

    Last edited: Jun 26, 2009
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the logs from SUPERAntiSpyware, Malwarebytes and MGtools before we can continue.

    The 6F.tmp file is probably due to you having installed Sophos AntiRootkit. Just a guess since you did not attach all the logs we need.
     
  7. cabbie1985

    cabbie1985 Private E-2

    here are the logs you asked for,
    SuperAnti-Spyware did find a few things that the others all missed
    by the way i did install Sophos Anti-Rootkit to try to remove the rootkit
    shall i delete all items from SAS quarantine? thanks again
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to put a current copy (redownload) of combofix.exe on your Desktop as requested in the procedures. You ran it from K:\hjh.exe last time. Download a new copy to your Desktop and keep the original file name this time.

    Then put your PC into Normal Startup mode with MSconfig as requested in step 1 of the READ & RUN ME. MSconfig should only be use for temporary debugging. You have things trapped in here that need to be removed.

    Now make sure that you reboot and after reboot, make sure that Spybot's Teatimer is disabled. See this: How to disable Spybot's TeaTimer


    Now I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. cabbie1985

    cabbie1985 Private E-2

    Here are the logs you requested. System seems to be running fine. Ran CCleaner as described in the Read & Run Me First.

    However Windows Messenger re-installed itself immediately upon reboot, but i don't have any problems with popups.

    Can I clear out the Combo-Fix quarantine (C:\Qoobox\Quarantine)?

    Thanks.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No it did not. You are looking at Windows Live Messenger which is not the same program. :)

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. cabbie1985

    cabbie1985 Private E-2

    thanks again for all your help!
    i like Malwarebytes and SAS looks like a good program. so i'll keep those
    thanks
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds