patched.fl/fm

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rhondall, Aug 30, 2010.

  1. Rhondall

    Rhondall Private E-2

    Hello, I was using AVG 9 when my winlogon and explorer.exe got infected with win32/patched.fm/.fl. I followed the instrucions in this thread http://forums.majorgeeks.com/showthread.php?t=139313. I got everything done except for combofix where I got an error that says "T was unexpected at this time". For now I uninstalled AVG and replaced it with Avast and I am running on windows xp SP3. I'll attach the log files and hope soneone can help me.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these old avg8 remnants:
    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now why did you not run Combofix, for I do see it on your desktop. Please run it now at this point as per the instructions in the R&R.

    Your Mglogs.zip was missing a hijackthis log. When you run MGTools.exe after a little while you will get a window opening asking you to agree to the Trend Micro HJT license. There's a bug and you have to click on "accept" TWICE.

    So... double click the C:\MGTools.exe to run it again and then attach the C:\Mglogs.zip once done.

    Let me know how things are running now please?
     
  4. Rhondall

    Rhondall Private E-2

    I restared my computer and when I run windows normally explorer.exe doesn't run anymore and I can only operate with task manager. When I run windows on safe mode the explorer is working fine. I can't run combofix because when I run it it starts but after a while it says "T was unexpected at this time" and nothing happens after that. When I ran MGTools it didn't ask me to accept anything so I just waited until it had scanned and told me to press any key to close the program but I'll upload my new zip anyway. Hope to hear from you soon and thanks for helping.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then try renaming combofix to kestrel.com and see if it runs then. If NOT, reboot into safe mode and give it a shot, let me know. But I start work soon so will reply when I can.
     
  6. Rhondall

    Rhondall Private E-2

    combofix did the same thing he did before on normal and safe mode
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Without seeing the log from combofix (which aids in helping us see which files are infected,) it's harder to work up an initial fix.

    I want you to run a full system scan with Avast soon, not yet, but soon.

    O20 - Winlogon Notify: Antiwpa - antiwpa.dll (file missing) <--- I see this in your logs

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Please run a scan with this: Norman Malware Cleaner

    Then after another reboot, see if you are still having problems. Also se if you can get a log from Norman to attach. Ignore any messages about items in the QooBox folder (from ComboFix) or in the MGtools folder being infected.

    Now run this in safe mode with networking:

    Using ESET's Online Scanner

    Now run a full system scan with avast, let me know what it reports (Again ignore anything about MGTools.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds