Not sure if I removed everything

Discussion in 'Malware Help (A Specialist Will Reply)' started by AggieJillPA, Mar 23, 2008.

  1. AggieJillPA

    AggieJillPA Private E-2

    I had numerous malware items on my computer. Some of the names I found were worm.win32.netsky, xp antivirus, vapsup, antiviirus.exe. I ran the smitfraudfix and then I followed the instructions in Windows XP Cleaning Procedures. The steps all ran smoothly with no problems. I have attached the logs. The computer seems to be running ok, but I just want to make sure since there were several different viruses/trojans. Also, the clock never reverted back from the 24-hr mode after running the combofix. It seemed like it ran like it was supposed to. Just making sure it is all gone and I didn't screw something up! Thanks sooo much!!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Saving files liek below to your C:\Program Files folder is not recommended. If you need these files, store them somewhere else. This folder should only contain installed programs not the files you download for installing the programs.
    Code:
    2007-03-29 22:50 5,954,520 ----a-w C:\Program Files\Windows-KB890830-V1.27.exe
    2007-03-01 00:18 1,045,664 ----a-w C:\Program Files\qmpsetup_win_mozilla_07010901.exe
    2007-01-27 00:04 5,037,072 ----a-w C:\Program Files\spybotsd14.exe
    2007-01-26 23:50 1,497,680 ----a-w C:\Program Files\ccsetup136.exe
    2007-01-15 20:26 1,410,680 ----a-w C:\Program Files\install_flash_player.exe
    2007-01-10 21:30 7,050,552 ----a-w C:\Program Files\psa30se_en_us.exe
    2007-01-10 21:30 21,822,168 ----a-w C:\Program Files\AdbeRdr80_en_US.exe
    2006-06-23 18:28 212,849 ----a-w C:\Program Files\hijackthis.zip
    2006-02-01 19:10 6,839,296 -c--a-w C:\Program Files\DingInstall.exe
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
    O21 - SSODL: SetupDrive - {fbfc4eb8-1a1a-46ae-989f-6f59501f15f0} - C:\WINDOWS\Installer\{fbfc4eb8-1a1a-46ae-989f-6f59501f15f0}\SetupDrive.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. AggieJillPA

    AggieJillPA Private E-2

    Thanks for your response. I got really busy and was just now able to do the steps you listed. I am unable to run the combofix, however. I downloaded the new version like it said. It says it is scanning but then freezes up. I let it run for 2 hours and nothing happened. I tried it again after I disabled superantispyware and my anti-virus software, and the same thing happened. I am not touching the computer while it is running. What should I do?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have have done the first part with analyse.exe and then do the below instead of what was in the last message.



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds