msconfig bug

Discussion in 'Malware Help (A Specialist Will Reply)' started by eminentsoup, Apr 3, 2008.

  1. eminentsoup

    eminentsoup Private E-2

    So I read a couple of the threads and it seems that I have that same msconfig back door thing here ... I have attached the 3 logs you requested and did all the prelim cleaning as well , after spending the last 2 days registry editing via directions from trend micro ... and frustrated still knowing that it resides on my computer still , I did notice the msconfig utility trying to access the internet and may have allowed it at one point through my fire wall ... I guess that's why there were so many hits from my server (literally hundreds) Rogers and att in the states now I can't use the internet at all and am using the other computer on my network , runnig files back and forth via usb stick :) ... any help in this matter would be greatly appreciated

    Thank You

    P.S I will go online to check my e-mail as my outlook is non functional :(
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [DRam prosessor] msconfig.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. eminentsoup

    eminentsoup Private E-2

    First of all Thanks for the speedy reply :) Everything seems to be good except for the fact that I cannot access the internet still :( I've been running between my 2 computers with a usb stick :cry
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    This may not be a malware issue. Your logs are clean at this point. Are you sure that your firewall or protections software are not blocking your browsers? Shut down your firewall and try. Are you getting a valid IP Address assigned to your Network Interface Card? Are you set for DHCP (I assume you use an ethernet type interace to connect to the internet)?

    If that does not work, see if you can get to the internet in safe boot mode.

    If that does not work, try running this XP TCP/IP Repair
     
  5. eminentsoup

    eminentsoup Private E-2

    Thanks again for all your help or rather than thanking you I will thank God for people like you ;) While Iwas waiting for your reply I did a little tinkering by myself , and decided to look in the registry to see if the dhcp and other misc. settings had changed (as per the trend micro bat_batten.a removal instructions) and sure enough a lot of the settings had changed to how the virus/malware did them ,I guess while we were removing it , it had time to make the registry changes ... we are up and running now though and all is well .
    thanks again for all your help.

    Em
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  7. eminentsoup

    eminentsoup Private E-2

    Everything is working as good or better than before the malware prob ... thx again so much

    Em
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds