Malware System Cleaning

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pretteyes, Sep 2, 2008.

  1. Pretteyes

    Pretteyes Private E-2

    Good Day All
    I believe I have completed the READ & RUN ME FIRST. Malware Removal Guide as you advised and I have included the log postings for your expert review. Thanks in advance.

    Original Post
    Hello

    I would like to first thank you for helping me to resolve some previous issues with my system. I think you are AWESOME!

    I recently had a problem accessing automatic windows updates(error 1058). I went through some scaning & cleaning recommendation I found on your site. I believe I have resolved that issue. I am now able to get the updates automatically (Thanks 2 U).

    I would like to be certain that all malware and possible infections have been removed. Please tell me what I need to provide so that you can evaluate my system and point me in the right direction if I need take further action.

    Thank you Computer GODS!!!
     

    Attached Files:

  2. Pretteyes

    Pretteyes Private E-2

    ComboFix log

     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    Folder::
    C:\Window\U2hhdW5l
    C:\WINDOWS\system32\imp32
    C:\WINDOWS\system32\olixds18
    C:\WINDOWS\system32\provdll
    C:\WINDOWS\system32\sfig
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. Pretteyes

    Pretteyes Private E-2

    Hi Tim & Thank you for time and expertise

    Here are the updated logs you have requested.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try one more time:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    Folder::
    C:\Window\U2hhdW5l
    C:\WINDOWS\system32\OBDE
    C:\Temp
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  6. Pretteyes

    Pretteyes Private E-2

    Tim W, I can't thank you enough for your time and assistance;)

    Here are the additional logs for further eval.

    Did I THANK YOU already?
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And maybe this time will be the charm:

    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\vbzip10.dll
    
    Folder::
    C:\Window\U2hhdW5l
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  8. Pretteyes

    Pretteyes Private E-2

    Hello TimW

    Here are the latest log results.

    More Thanks
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Aaaggghhh.......stubborn little thing.

    Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FolderLook::
    C:\Window\U2hhdW5l
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  10. Pretteyes

    Pretteyes Private E-2

    I was'nt sure if you wanted me to complete both of the previous steps like before so I did. I hope it's what you presumed I would do, if not I will re-do the the first step with copy paste & combofix only.

    By the way, combofix auto restarts at a certain point. Not sure if it should or if this is something that I should share.

    UR a Trooper Thanks
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well...I have no idea what that folder is.....are you having any issues?

    If not, then I think we should give you the clean up and just see how your system is running.

    Let's clean up from combo:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
     
  12. Pretteyes

    Pretteyes Private E-2

    OK TimW
    1. I have not identified any issues after cleaning system.
    2. I received the following message: FixMe.reg has been successfully entered into the registry.
    3. I proceeded with the final steps as indicated and I am working through the How to Protect yourself from malware link provided.

    Just one more question; Can I delete the fixme file from the desktop?

    You have been a tremendous support and I appreciate all that you have done:major
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you can remove the registry patch as per item #7

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds