Malware scans2

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wild, May 6, 2009.

  1. Wild

    Wild Private First Class

    After a long day scanning and finding logs here are my scans from another comp. we have. This one has had multiple infections,namely loss off IE,DVD/ROM,Drivers. Thought it may have been after downloading service pack 3 as it was within an hour of doing so it went haywire.
    Where can i get this driver HL-DT-ST.DVDRAMGSA4167B for my dvd/rom?
    Thanks in advance.
    Wild
     

    Attached Files:

  2. Wild

    Wild Private First Class

    Not forgetting Combofix.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not attach the C:\MGLogs.zip from running the C:\MGTools,exe.
     
  4. Wild

    Wild Private First Class

    Here is MGlogs.zip. One thing i did not do but did in the past was to turn off system restore before scans.Should i have done?
    These scans are from the comp. i changed to service pack 3.Soon after installing SP3 i did a driver update scan using Driver Detective from driver tool section. Just after this i lost IE , DVDROM , and picked up multiple infections.Not entirely blaming this prog but it was the last thing i did on line at that time.Contacting my server,(Virgin media) they tell me i have lost IP adress? Not sure how to resolve that one?
    Thanks in advance Wild.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Re-run Combo.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  6. Wild

    Wild Private First Class

    Here are the MGlogs.zip and combofix.txt.log

    Thanks wild.
     

    Attached Files:

  7. Wild

    Wild Private First Class

    Forgot to state that Avenger could not find c:\windows\system32\asr_wbjzu
     
  8. Wild

    Wild Private First Class

    Apoligies if it looks like i bumped but i since ran Spybot search and destroy and it reported system32\TDss rtkt. Is this a virus? Im considering reinstalling Xp disc but my dvd/rom has a exclamation mark in device manager.The drivers there but code 41 says the device is not recognised.It does not appear on `My Computor`.
    Please help.
    Wild
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    [ If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\asr_wbjzu
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  10. Wild

    Wild Private First Class

    Hi TimW,did the Combofix and cf script but it could not update as unable to get on line with the comp. A box appeared with `unable to find HIDECexe`.
    Is this an important file? Did a search but nothing.
    Thanks again.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you need to download a new copy of COmbo and transfer it to the this machine.

    DId you try manually removing it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds