Ran all scans, Still infected;(

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Nanners46, Aug 4, 2011.

  1. Nanners46

    Nanners46 Private E-2

    Hello Computer Geek Angels,

    I have a Windows XP computer, with a load of problems. Not sure how, but we have been overrun with problems, including internet pop ups on IE that you cannot close, and I am still unable to get Firefox to open. The windows control center has been hacked. The Superanti spyware seems to have resolved some of it, as you will see.
    Right now, the computer is running very slowly, so I hope this works, and posts..

    I have attached all of the scans here, and with results showing anything from Backdoor trogan to locked to Windows API!
    When I ran Root Repeal, the first time, it froze,
    Results on the screen were this
    C:|WINDOWS\Systen32\71551f2eab2db360fa904479d1aba24[1].swf
    (Locked to Windows API!)
    C:WINDOWS\temp\fla5a.tmp
    Allocation size mismatch (api...)
    The place it was frozen at while screening was
    C:\Windows\$NtUninstallKBB946648$\


    and when I shut down the computer and restarted Root Repeal it did complete with a different result as shown in the log.

    MB Tools was also unable to complete twice warning about the computer, with a blue screen
    tech info
    atapi.sys-addressf73AB71D base at F73A1000, Datestamp 4802539d
    Physical memory dump
    I am attaching all files, and have a full time job, so they are not all back to back, timewise, but I can assure you, the computer was not used during any of the in between time.
    Since running the scans, I have reloaded Avira anti virus again.
    Not sure if that was the right thing to do, but please let me know, if I should try to update, or if the virus will mess it up too.
    Please help..
    AND THANK YOU AHEAD OF TIME!!!
    Nancy
     
  2. Nanners46

    Nanners46 Private E-2

    including logs for Root Repeal and MG tools here.
    I await further instructions after work.
    Thank you!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No logs attached, Nanners. :( Attach them when you can and I will review them. :)
     
  4. Nanners46

    Nanners46 Private E-2

    logs 1-4
     

    Attached Files:

  5. Nanners46

    Nanners46 Private E-2

    MGTools
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    uninstall outdated java

    • Java(TM) 6 Update 21

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FileLook::
    C:\Documents and Settings\User\Application Data\D872.4CC
    
    Folder::
    c:\program files\Spyware Doctor
    c:\program files\Common Files\PC Tools
    c:\documents and settings\User\Local Settings\Application Data\AskToolbar
    c:\program files\Ask.com
    
    File::
    c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    C:\Documents and Settings\User\Local Settings\Application Data\t75v1fa8rrg7d4lxmq
    C:\Documents and Settings\All Users\Application Data\fmmw.exe
    C:\Documents and Settings\All Users\Application Data\wurn.exe
    C:\Documents and Settings\All Users\Application Data\t75v1fa8rrg7d4lxmq
    C:\Documents and Settings\All Users\Application Data\xxgd.exe
    C:\Documents and Settings\User\Templates\aumn.exe
    C:\Documents and Settings\User\Templates\cyni.exe
    C:\Documents and Settings\User\Templates\hhdl.exe
    C:\Documents and Settings\User\Templates\odoh.exe
    C:\Documents and Settings\User\Templates\t75v1fa8rrg7d4lxmq
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop.

    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )



    Could you please get this: D872.4CC into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\Documents and Settings\User\Application Data\D872.4CC


    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. Nanners46

    Nanners46 Private E-2

    Hello, thank you for your response and directions..
    The very first one, has created a problem. I went to add/remove programs and this is the message I received when I tried to uninstall
    Java6.21
    The feature you are trying to use is on a network resource that is unavailable. Click ok to try again or enter an alternate path to a folder containing the installation package 'jer1.6.0_21.c.msi' in the box below.
    I tried clicking again and recieved this message
    The installation source for this product is not available. Verify that the source exists and that you can access it.

    I did run the Combo fix with the Kill all packet, thinking that it would maybe give me access to the Java, but after running that and TDSSkiller, I still cannot get it off.

    I am including the logs so far. I am unable to access MBRCheck either:(
    Thanks for your continuing patience with my problems.
    Nancy
     

    Attached Files:

  8. Nanners46

    Nanners46 Private E-2

    I did get it to open!
    plus the D872 zipped file, included.
     

    Attached Files:

  9. Nanners46

    Nanners46 Private E-2

    Was unable to upload the file for analysis at Virus total, as it exceeds the 20 mg limit.
    will not try to install the Java, as I cannot uninstall the old one.
    and will now wait for further instructions.

    thank you very very much
    Nancy
     
  10. Nanners46

    Nanners46 Private E-2

    Hello,
    Since it has been a bit, and Avira seems to have removed a malware this morning!, Accessing the internet has been easier.
    SO, that being said, I did run the CCCleaner and removed old registry files as well
    and then installed the new Java Runtime 6, it seems to have installed, but I still am unable to remove the old one..
    Here is the new MG Tools log..and even though it is running smoother, I am nervous that it still lurks here..

    Nancy
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    
    :files
    c:\documents and settings\All Users\Application Data\xxgd.exe
    c:\documents and settings\All Users\Application Data\wurn.exe
    c:\documents and settings\All Users\Application Data\fmmw.exe
    C:\Documents and Settings\User\Application Data\D872.4CC
    C:\Documents and Settings\User\Application Data\D872.zip
    C:\Documents and Settings\User\Local Settings\Application Data\AskToolbar
    C:\Documents and Settings\User\Local Settings\Application Data\t75v1fa8rrg7d4lxmq
    C:\Documents and Settings\All Users\Application Data\fmmw.exe
    C:\Documents and Settings\All Users\Application Data\t75v1fa8rrg7d4lxmq
    C:\Documents and Settings\All Users\Application Data\wurn.exe
    C:\Documents and Settings\All Users\Application Data\xxgd.exe
    C:\Documents and Settings\User\Templates\aumn.exe
    C:\Documents and Settings\User\Templates\cyni.exe
    C:\Documents and Settings\User\Templates\hhdl.exe
    C:\Documents and Settings\User\Templates\odoh.exe
    C:\Documents and Settings\User\Templates\t75v1fa8rrg7d4lxmq
    C:\Program Files\Ask.com
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. Nanners46

    Nanners46 Private E-2

    Hello,
    I have followed instructions, all went ok, except the OTM link was blank, so I typed in the website to OTM.
    It is running, a bit glitchy, slow, and Windows wants to update, should I TRY?
    Here are the requested logs.
    THANK YOU
    Nancy
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome!

    It wasn't, it does not redirect you to a website to download it, it should automatically pop up with the file for you to download.

    Sure...why not?

    Try Revo Uninstaller to be rid of old java.

    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    • Java(TM) 6 Update 21
    • Java(TM) 7

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    I am close to giving you final steps now.
     
  14. Nanners46

    Nanners46 Private E-2

    Hi,

    I have installed windows update, and had to go to windows update online, cause the little icon is still telling me it has the same update to install in my system tray. Even though WIndows said it is installed already! odd.



    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
    The remover worked perfectly and the one for the old Java found 151 bits to remove, but I only did the bold ones, and all seems to be fine now that I have rebooted and installed the new one again.

    I am close to giving you final steps now.[/QUOTE]
    YEAHHHHHHHHHHHHHHHHHH!!! That is GREAT news!!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. Nanners46

    Nanners46 Private E-2

    Thank you very very much!!

    Nancy
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds