Please check my logs after recovery from iuser_admin account & malware.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Private CF, Sep 13, 2008.

  1. Private CF

    Private CF Private E-2

    I followed all instructions included in "Read & Run First" and "XP Removal Procedures". I also removed the malicious account "IUSER_admin" and it hasn't returned. My machine appears to be clean so far; however since this one seemed to be nasty, especially with the backdoor creation of a user account, I would be grateful it you would review my attached logs and tell me If it looks to be fully clean. Thanks.

    Here is some additional information in case it is helpful: Once NOD32 started alerting, the damage was already done. The IUSER_admin account had been created and other symptoms such as random audio playing and multiple websites opening started. NOD32 found frequent threats...mostly win32/...varients. During cleanup, Spybot S&D reported that it couldn't fix 3 items tagged as "WildTangent". I think "win32/bagle.gen.zip" may have been related to these. They may have been cleaned during the other scans.

    Anyway, It seems to be clean so far but I would appreciate a review of my logs.

    Also, I plan to uninstall Adaware and SpywareBlaster and go with either SuperAntiSpyware or Malwarebytes if it's not recommended to use both. What do you recommend?

    Thanks for your help.
     

    Attached Files:

  2. Private CF

    Private CF Private E-2

    Attached is my 4th log. Thanks.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You look pretty good.....let's just do a few things:

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now re-run ComboFix and attach the new log.
     
  4. Private CF

    Private CF Private E-2

    Hi Tim, I really appreciate your help.

    The registry changes were successful and I attached the new combofix log as instructed.

    I'm curious...What was left after the initial cleaning procedure and what did the fix.bat and registry changes do?

    Also, I plan to uninstall Adaware and SpywareBlaster and go with either SuperAntiSpyware or Malwarebytes if it's not recommended to use both. What do you recommend?

    Any idea why this particular malware, especially whatever created the IUSER_Admin account, was only detected by NOD32 after damage was already done?

    Thanks again.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You had two fake security drivers which we stopped and deleted.

    The reg patch was just to clean out some crud that Combo does to your system.

    As to why one av finds things and others don't is just a matter of the source programmers keeping up with the new attacks...some can respond faster than others....a good reason to keep your systems updated.

    If you are not having any other malware problems, it is time to do our final steps:
     
  6. Private CF

    Private CF Private E-2

    "The reg patch was just to clean out some crud that Combo does to your system."

    Tim.....with this in mind, since you had me run combofix again after this reg patch, should I run the reg patch again without running combofix so that the system is cleaned post combofix?
     
  7. Private CF

    Private CF Private E-2

    Also, is there any reason not to update winXP all the way to sp3?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be fine.....make a restore point and go ahead and download sp3.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds