Please check to see if all trojans are gone

Discussion in 'Malware Help (A Specialist Will Reply)' started by MistressRene, Apr 22, 2010.

  1. MistressRene

    MistressRene Private First Class

    Hello,

    I ran the scans, and I will post the results.
    I think it look clean now.
    The MGlogs is the clean log.
    I am going to re-run a few scanners just in case.
    If they come up clean I will turn on my restore points again, and the UAC.
    Thanks!


    I am on Windows 7 32 bit
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.

    You are trained to read logs? I'll review them and let you know. Do not run any other scanners unless I request that you do. Do not flush system restore until we know for sure you are clean.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, (if you haven't done so already.)

    2. Why did you not run combofix?

    3. Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 18
    4. Without clicking on anything that may be contained within the folders can you tell me what you know about them, what they relate to or what they are for?

    5. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    6. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    7. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    8. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited by a moderator: Apr 23, 2010
  4. MistressRene

    MistressRene Private First Class

    Hello and thank you for your response!
    I am looking at your post, and wanted to let you
    know what the C2MP and Wat are:
    C2MP -
    http://www.downloadroute.com/Media-Player-Codec-Pack-MPCP/antivirus_report.html

    and the Wat is:
    WAT system to download latest and updated signatures that are used to identify new activation
    exploits in order to verify and determine whether the Windows 7 installed on a PC is genuine or pirated

    Now I will continue reading and following your advise.
    I will post back when done, thanks!
     
  5. MistressRene

    MistressRene Private First Class

    I am getting the error: is not accessible
    access denied

    I have the shortcut arrow on the dir.

    Is that that same dir. as C:\Users\Mistress\AppData\Local\Temp
    That one I can access.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, just continue on with the instructions :)
     
  7. MistressRene

    MistressRene Private First Class

    OK everything has been run.

    If everything is ok, how do I remove the Avenger dir. and program, as well as the MGtools and dir.

    Also, I run ZAISS and SUPERAntiSpyware Professional,
    and I have MBam, yet on this windows 7 something sneaks in.
    When ever I download anything, I always scan it!
    Is there any way to prevent this or is it just a
    flaw with windows 7 or my anti-virus/spyware programs?

    This is very frustrating as with XP I almost never had a problem in all the years I ran it!

    Hoping everything is back to 'normal',
    THANK YOU!!!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please bear with me, your logs look good except for a couple of questionables which I am consulting colleagues about.
     
  9. MistressRene

    MistressRene Private First Class

    Mornin'

    I am online now, and will be here most of the day.

    I haven't had any weird problems since I cleaned the
    rest of the files up.

    PLEASE tell me how to uninstall the MGTools, as it is making my
    ZAISS see the FP it throws.

    TY!
     
    Last edited: Apr 24, 2010
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    would rather you hung on until I have spoken to Chaslang about something. We are all on diff time zones so be patient and thanks for understanding :) You can easily move MGTools.exe to someplace else for now if your AV/AS apps are wrongly flagging it.
     
  11. MistressRene

    MistressRene Private First Class

    ok, I will hang in there
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, I have been busy with work this weekend.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Windows\2c48~1
    C:\Windows\a0dc~1 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. MistressRene

    MistressRene Private First Class

    HiHi!!!
    I hope you didn't work too too hard! :)

    I ran the combofix and MGtools and the logs are posted.
    I do, however how a question or 3 about the ComboFix-quarantined-files, that I also posted.
    What is the CTXFIREG, HKU-Default-RunOnce-SetDefaultMIDI, and AddRemove-HijackThis.reg.dat ???
    I thought that the CTXFIREG was a Creative Labs sound card driver,
    Not that I need it any more as I am switching sound cards, as we speak...LOL!



    Thank you lots!
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes sometimes combofix gets a little over ambitious and deletes things it shouldn't. Which is why we advise against running it without supervision. Things that wrongly get removed can be restored, however in your case as you are switching cards, we won't bother. :)
    Most welcome :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. MistressRene

    MistressRene Private First Class

    Did this eat part of the registry?

    More possible pertinent information:

    I also found another dir. that seem to have been created by this removal process:
    C:\32788R22FWJFW\EN-US\cmd.cfxxe.mui
    AND
    Most importantly now ... I tried to install a new soundcard and software,
    and when it came to the registry software\microsoft\windows\currentversion\run\VolPanel
    and
    software\microsoft\windows\currentversion\runonce\

    The software was not able to utilize the run and runonce.
    I had this problem with the trojan also, but didn't even really think it was related.

    So my question to you is, IF this trojan has done something to the registry,
    is there a way to fix the registry with some sort of windows 7 repair?
    And not having done a win7 repair, will that kill all of my programs that
    are currently installed?

    whew......
     
    Last edited: Apr 26, 2010
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Did this eat part of the registry?

    Simply delete it.

    This is something you can discuss in the software forum :)

    Safe surfing!
     
  17. MistressRene

    MistressRene Private First Class

    You have been a wonderful help to me,
    and it is appreciated!
    You get 4 gold stars! :)
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nice one! :cool
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds