Please help log included

Discussion in 'Malware Help (A Specialist Will Reply)' started by spiderancy, Apr 13, 2009.

  1. spiderancy

    spiderancy Private E-2

    fire fox crashing/encounters problems....searches being redirected....cannot open regedit....Have never used IE on this machine but am getting IE errors...use eAcceleration for Av etc., tried running Malwarebytes but it see's eAccel as threat, tried uploading HJT LOG directly but it say's "no internet connection available"..... yea right lol....so here's my log.....hopefully you can help...I apologize if i missed reading somethinng before posting this but i'm not sure if FF was going to stay open long enough to accomplish this post

    please Help!!!

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:02:12 PM, on 4/13/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    not a rich man so I can't afford to purchase alot of programs to fix......just wanted to put that out there
    Thanks.....spiderancy



    ADMIN EDIT: READ & RUN ME FIRST. Malware Removal Guide and HOW TO: Attach Items To Your Post
     
    Last edited by a moderator: Apr 15, 2009
  2. spiderancy

    spiderancy Private E-2

    Malware Probs logs attached

    Thanks in advance....
    severe malware problems...browser redirecting,Firefox error-close/crash mess., I dont run IE and am getting IE error's, cant open Regedit, etc etc etc.
    ran the required scans that i could
    SAS-good
    mbam-good
    combofix -would not run
    MBtools-downloaded and double clicked to start, all the items are in folder, got command prompt window, let it sit for over an hour with nothing showing in window, finally closed
    included HJT log as substitute
    PLEASE HELP!!! SpiderAncy

    Logs attached
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HJT (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now try to run both Combo and then run the C:\MGtools\GetLogs.bat file by double clicking on it ( be patient and let it run till it tells you to press any key). Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. spiderancy

    spiderancy Private E-2

    Thanks Tim...Let me 1st update you.....since the original post i have been able to get all the required scans to run and i will attach those so you have a better picture and we can go from there ok?...figure this is better than using what i had which was half arsed at best due to the issues at the time.
    Thanks and I'll be waiting for reply!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still need to do what I asked.....at least we can remove those files and baddies....I will get to a fix based on your new logs as I can.
     
  6. spiderancy

    spiderancy Private E-2

    Ok.here are the requested log's

    just a quick FYI....i have been running SAS a few times and the 1 consistant thing that shows up is a Vundo Variant, dont know if that will help or not.

    Thanks again in advance!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt attach the SAS log for me to see exactly what it is trying to remove.

    In the meantime, please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now:
    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\p2hhr.bat
    C:\kgqxi.exe._eac_qt_
    C:\3670019.bat
    C:\hwjthdcs.exe._eac_qt_
    C:\qunxkv.exe._eac_qt_
    C:\xuyyhnc.exe
    C:\jurj.exe
    c:\windows\instsp2.exe._eac_qt_
    c:\windows\system32\avifil.dll
    c:\windows\system32\puhelero.exe
    c:\windows\system32\hoheyuli.exe
    C:\WINDOWS\instsp2.exe._eac_qt_
    C:\WINDOWS\system32\avifil.dll
    c:\WINDOWS\system32\diwovadu.dll.tmp
    c:\WINDOWS\system32\hsf73ikmdf3f.dll
    c:\WINDOWS\system32\ligemeho
    c:\WINDOWS\system32\nuzeriko.dll.tmp
    c:\WINDOWS\system32\puhelero.exe
    c:\WINDOWS\system32\sqlsodbc.chm
    c:\WINDOWS\system32\zugotike.dll.vir
    
    Folder::
    c:\WINDOWS\system32\ligemeho
    
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2BA40A2-74F3-42BD-F434-2604812C8954}\InProcServer32]
    @Class="REG_SZ"
    @DACL=(02 0000)
    @="c:\\WINDOWS\\system32\\hsf73ikmdf3f.dll"
    "ThreadingModel"="Apartment"
    
    RegLockDel::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2BA40A2-74F3-42BD-F434-2604812C8954}\InProcServer32]
    
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B4B13AA-9E0A-4620-8EA6-A9DBAD987DEF}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Remove this if you don't know what it is:
    c:\documents and settings\Chris\Application Data\MalwareRemovalBot

    Now use add/remove porgrams to uninstall:
    URL Assistant

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  8. spiderancy

    spiderancy Private E-2

    Ok...My AV does not have a "turn Off" button, I disabled my threat scanner and on access scan, I hope this was enough, if not i will have to uninstall it completely in the future.
    I was under the impression that the "maleware removal bot" was associted with the Malewarebyte's program? I deleted what you asked as far as that goes.
    Cannot delete the "URL Assistant" in add/remove programs, all it does is blink , but remains.
    Included a freash SAS scan, it's showing the same 8 Items it has been (5 Reg, 3 File) "Adware Vundo Varient"

    The combofix- ran as instructed, during re-boot it hung on the "windows shutting down" screen, let it sit for about 30 min. then did a manual (I know, not good to do).
    Re-ran the procedure and it worked out fine, I didn't click on the screen at all knowing it could cause it to hang, I'm at a loss as to why it did.
    Thanks again for your attention!!!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did fine with the av software. And the bot file was not associated with MBAM - it is malware and needed to be removed.

    Let's do combo again:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Rootkit::
    c:\windows\system32\avifil.dll
    
    File::
    Rootkit::
    c:\windows\system32\avifil.dll
    
    Registry::
    [-HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B4B13AA-9E0A-4620-8EA6-A9DBAD987DEF}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now also run MBAM as well as SAS and attach those logs.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  10. spiderancy

    spiderancy Private E-2

    Ok ...here ya go with the latest round

    One note on Malwarebytes scan.....It seem to be tagging alot/all of the AV definitions for eAcceleration( i get like 1784 hits from scan), when i did the fix i did not check these, all i checked was a couple p2p hits and a couple other ones that were obviously not AV def's....Please advise if i need to do otherwise and check everthing.
    another round of thank you's !!!
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to remove this:
    c:\documents and settings\Chris\Application Data\MalwareRemovalBot!

    I thought you said you had already.

    What issues are you still having?
     
  12. spiderancy

    spiderancy Private E-2

    I did remove that.....When i did the latest scan for Malewarebytes...In the upper right corner of the scanner window...It say's "Malware Removal Bot"..This is why I made the comment about it being related to Malwarebytes program, could it be a spoofed version???? it say's...Malware(in black)Removal(in red) and right above the "val" in removal it has the word "BOT"( in black).
    In that file are the sub folder....Log....Quarentine....Settings etc.

    As far as issues...everthing looks to be running pretty good, no search re-direction , none of my desktop items are locked, and the speed is back up where it should be.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is not MBAM....remove it. Let me give you the final cleanup....but tell me if you have problems removing that file.Can I assume you did not download that off the Read and Run First instructions? I want you to remove that file, uninstall MBAM and then after running CCleaner, redownload it off the R & R Instructions.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  14. spiderancy

    spiderancy Private E-2

    to the best of my memory I used the R & R first links for all the downloads associated here, knowing what re-direction issues I was having ...could it have re-directed that link to something else??
    your suspicion's are correct....cant remove it.....get the "access denied, make sure the disc is not full...etc. " stop window, and in the ADD/REMOVE there is no option to remove like normal...I will go into holding pattern on your instructions until you respond on getting rid of this.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * [color=darkred)Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.[/color]
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\Chris\Application Data\MalwareRemovalBot
    
    Folder::
    c:\documents and settings\Chris\Application Data\MalwareRemovalBot
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat[/b] file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  16. spiderancy

    spiderancy Private E-2

    Ok...did as requested....logs attached........It is still showing in Add/Remove, control panel & program files.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is going to tick me off!! Let's try this again:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * [color=darkred)Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.[/color]
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\avifil.dll
    c:\windows\Tasks\MalwareRemovalBot Scheduled Scan.job
    
    Folder::
    C:\Program Files\MalwareRemovalBot
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B4B13AA-9E0A-4620-8EA6-A9DBAD987DEF}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat[/b] file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  18. spiderancy

    spiderancy Private E-2

    Looks like a partial success........nothing in program files...The Icon in control panel changed to a generic one.....But still shows in Add/Remove....No icon in lower right task bar, Did notice that one of the Avifil items "failed to delete" in CF log
    She's bein a stubborn bastage!
     

    Attached Files:

  19. spiderancy

    spiderancy Private E-2

    Addendum to last post...My AV is picking up hits and they all seem to be related in some way to the MalwareRemovalBot!....
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me exactly what is being reported and where. I will get to your logs asap.
     
  21. spiderancy

    spiderancy Private E-2

    This is the only one I could retrieve for you....

    c:\documents and settings\chris\my documents\mb.exe._eac_qt_:MalwareRemovalBot/MalwareRemovalBot.exe is Quarantined.

    Hope thats of use:)
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it is quarantined, then there is nothing to worry about.

    Please check to see if this still exists ( its the only reference in your logs ):
    C:\Documents and Settings\Chris\Application Data\MalwareRemovalBot

    And you can delete this file now:
    C:\Documents and Settings\Chris\My Documents\MalwareRemovalBot.reg

    I would suggest that you uninstall MBAM, run CCleaner and then re-download it from the link in the Read and Run FIrst Instructions.
     
  23. spiderancy

    spiderancy Private E-2

    Ok Tim...here's the REAL...lol...Malwarebytes log...It did locate 26 items!
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me you attached the log before you had MBAM fix everything it found.

    Re-run SAS and MBAM and attach the logs showing you fixed the items found.
     
  25. spiderancy

    spiderancy Private E-2

    You should have gotten the post cleaning log!?....I did save the log manually before ( it's hard to remember what each scanner does having run them al so many times...kinda gets blurry!) BUT when I ran the cleaning step and it poped up the log I remembered that's the one you want, so I saved to the same "scan logs" folder I have and it came up with the "allready there, do you want to overwrite" message and I hit yes....so you should have the post cleaning log....
    In any event I will run them both again and post...
    Thank you!
     
  26. spiderancy

    spiderancy Private E-2

    Ok here ya go.......ran both including cleaning step...re-booted after each.

    I went to see if the file in windows was still present( the avfil32.dll...and it was) and when I opened the windows folder I noticed alot of files that would be hidden normally scattered throughout (like im gonna say 150 or so) that are labeled in blue text like this
    $uninstallKB######$....with the "#"'s representing a series of numbers.

    Are these something to be concerned with???
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are referring to windows update uninstall files....they are not a problem. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  28. spiderancy

    spiderancy Private E-2

    Oh ok.....always wondered what those were....MG log attached.

    Thanks'!
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    RootKit::
    C:\WINDOWS\system32\avifil.dll
    
    File::
    C:\WINDOWS\system32\avifil.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B4B13AA-9E0A-4620-8EA6-A9DBAD987DEF}]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  30. spiderancy

    spiderancy Private E-2

    Here ya go Tim......By the way....How many of your "tasks" for lack of a better term...go on this long, don't get me wrong, not complaining or anything like that,just curious if this is the norm for a cleaning....you guys are pretty damm dedicated to do this on your own time!..dont know if I could...

    Thanks' !!
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sneaky little service running is the cause. One more time!

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    [ If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    RootKit::
    C:\WINDOWS\system32\avifil.dll
    
    Driver::
    cqirehki
    
    File::
    C:\WINDOWS\system32\avifil.dll
    c:\windows\system32\drivers\cqirehki.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B4B13AA-9E0A-4620-8EA6-A9DBAD987DEF}]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  32. spiderancy

    spiderancy Private E-2

    Here ya go....
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One last file to remove. so let's do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\drivers\ywprdywo.sys
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    And use add/remove programs to uninstall:
    URL Assistant
     
  34. spiderancy

    spiderancy Private E-2

    Ok...Still can't remove "URL assistant", just blinks when ya click on it....Also the MalwareRemovalBot still shows in Add/Remove with no option to remove, says it's at 23.25mb space.
    anyhow....Logs attached

    Thanks'!!!!
     

    Attached Files:

  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't see it in your add/remove list. Do a search for it and tell me where it is found.
     
  36. spiderancy

    spiderancy Private E-2

    5 hits under search...All in C:\QooBox\quarentine\ I guess the item in Add/Remove is a residual image??? It's there....I see it!!! lol
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Which is exactly where it is supposed to be......quarantined!! We will now remove all of it:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  38. spiderancy

    spiderancy Private E-2

    What can I say but THANK YOU!!!!....MG has another devoted fan and I will spread the word(sorry, I know this means more work for you, but somehow I think you derive some satisfaction from this ;))as to the quality and services you provide, you saved me from some tremendous headaches and I greatly appreciate that.
    Thank you again!! Spiderancy
    (Chris&Anne R.)


    :hyper:clap:clap:clap:clap:hyper:celebrate:celebrate:dood:dood:clap:clap:clap
     
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds