Malware Tutorials followed... More help needed!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dafunk, Mar 15, 2008.

  1. Dafunk

    Dafunk Private E-2

    Ok... I've followed the malware removal procedures that this site recommends and have also followed the procedure for removing Win32.tiny.abk (which seems to be the only returning problem) and yet it still prevails. Thanks for the help thus far! More would be very much appreciated! Running XP Home and every program run seemed to remove a little bit... I've rerun things a few times and FixIEDef.exe doesn't seem to help any....whats next.....My Superantispyware, Combofix, and MGtools loag are all attached. I have a FixIEDef log as well as Hijackthis log available....Thanks Again!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not too bad...let's just do this:

    download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Please attach that log to your next relpy.
     
  3. Dafunk

    Dafunk Private E-2

    Thanks again for the help!....here is the avenger log attached...sorry for the delay in response
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem...how are things running?
     
  5. Dafunk

    Dafunk Private E-2

    After about 3 minutes of internet surfing things slow down again (using 100% safe sites). I also did a test with my internet provider just to make sure it wasn't them and its not them....The good ol' Win32.tiny.abk comes back still....
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double click C:\MGTools\GetLogs.bat and attach the new MGLogs.zip. Where is this file showing? What is the path and what is reporting it? Have you deleted all of your temp files?
     
  7. Dafunk

    Dafunk Private E-2

    give me a sec...I'll reboot
     
  8. Dafunk

    Dafunk Private E-2

    Spybot seems to find Win32.Tiny.abk: [SBI $70B44025]
    Temporary file (File, nothing done)
    C:\WINDOWS\Temp\7CF28762C38CA0D4.tmp

    The browsing gradually slows right down after it shows up

    I ran the Mg log without removing it just in case that might help you see something....after this post I'll remove it again.....
     

    Attached Files:

  9. Dafunk

    Dafunk Private E-2

    A couple other files that show up at the same time or shortly after....c:\windows\temp\
    AE8AB41F91F72503.tmp
    8AF12AB59DCE7145.tmp
    745C6E9ECB8F4863.tmp
    I watched the temp folder after connecting to the internet and opening Firefox.... nothing happened for a couple minutes then they all just popped up ....let me know what you think
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...you need to clean out the temps....also delete these:
    C:\Program Files\.autoreg
    C:\WINDOWS\system32\coneefyw.dll

    Did you run ATF Cleaner?
     
  11. Dafunk

    Dafunk Private E-2

    I'll get rid of those files.....Right now I use CCleaner but I can switch to ATF Cleaner if you want....Thanks again
     
  12. Dafunk

    Dafunk Private E-2

    Browsing is preforming better than it was... it doesn't seem to slow much if at all!....Is that the last thing we need to do?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  14. Dafunk

    Dafunk Private E-2

    Sorry spoke too soon on my last post.... given, I can browse a bit longer but the slowdown in browsing STILL comes and spybot still identifies the same file as Malware each time it comes back....are they supposed to be there?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you really cleaned out all of your temp files? Please attach a new MGLogs.zip.
     
  16. Dafunk

    Dafunk Private E-2

    Thanks again for your reply!... Here is the MGlog...Here is what my computer is doing: I empty all the temp folders and make sure nothing is detected anywhere then reboot my computer...Then I connect to the internet and check email or come here to the forum and about 3 minutes in all internet activity slows to a snails pace...sure enought I go check and there are those same 4 files in c:\windows\temp that Spybot doesn't like...Then I clean it all up again and reboot...and it'll do it again....Is the Malware still coming from somewhere on my computer or is it coming that quickly over the net?....sorry, just getting fustrated with my computer!...Your help is greatly appreciated TimW
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Aarrrgg.....please run a new ComboFix scan (properly installed and renamed as directed in the Read and Run FIrst) and SASpyware scan and attach those logs. Also attach the log from Spybot. Then do a GMer scan:
    Running GMER to detect rootkits
     
    Last edited: Mar 19, 2008
  18. Dafunk

    Dafunk Private E-2

    OK!! Here are the logs and this is exactly how they were done....1. Clean out temps 2. SAS run 3. Combofix done right 4. GMER froze up (everything to this point was run in normal windows with full admin ability) 5. reboot to safe mode 6. Run GMER again 7. Reboot to normal mode 8. Forgot to run Spybot 9. Run Spybot

    Thanks again for your time in sorting it out!
     

    Attached Files:

  19. Dafunk

    Dafunk Private E-2

    And the GMER log.........
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download and install the proper version of ComboFix as requested multiple times and follow the instructions given in the READ ME for running it. Make sure you attach a complete log.

    See this: Running ComboFix You do not have the current version
     
  21. Dafunk

    Dafunk Private E-2

    Here is the new Combofix log. :)
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So now tell me how things are running. Combo caught some items I missed.

    But also delete these:
    C:\WINDOWS\SET4B.tmp
    C:\WINDOWS\SET48.tmp
     
  23. Dafunk

    Dafunk Private E-2

    Things seem to working fine now!! Thanks again....I guess I'll give it a couple days then remove the programs that you suggested earlier! I guess the proper combofix made the difference...
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...it did. Let me know if you have other problems. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds