RE: Read and Run Me Guide

Discussion in 'Malware Help (A Specialist Will Reply)' started by gplaydee, Feb 18, 2009.

  1. gplaydee

    gplaydee Private E-2

    Hi, i read the read and run me guide. I'm stuck at the "empty all quarantine type folders..." step. I use Avast 4.8 and in my virus chest, there are a list of "infected files". I read in another thread that because of false-positives, I should leave them alone?

    Should i just go on with the read and run me guide? not sure what to do. Any advice is greatly appreciated.

    Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Skip that step...just continue on and get us the logs for:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip
     
  3. gplaydee

    gplaydee Private E-2

    Okay. Here are the logs. I couldn't run ComboFix (it said my OS was not compatible).

    The reason I've done the "Read and Run Me" is because I've been getting Chinese Pop-ups. Hopefully you can tell me that they're gone! :D

    My Comp Specs:
    Microsoft Windows XP
    Professional x64
    Version 2003
    Service Pack 2
    Intel(r) Pentium(R) D CPU
    3.00 GHz
    3.00 GHz, 2.00 GB of RAM

    Please and Thank you!
     

    Attached Files:

  4. gplaydee

    gplaydee Private E-2

    Oh, quick update. The read and run me guide didnt' get rid of the popups :(
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the entire C:\MGLogs.zip.
     
  6. gplaydee

    gplaydee Private E-2

    Oh, sorry about that. It's in the attachment below.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not in front of a W2K machine so bear with me. There are a number of items I have questions about and would like some additional info.

    Use windows explorer to find and then right click each of these items and select properties....tell me the creation date:
    C:\Glenyx
    C:\WINDOWS\system32\50170B
    C:\WINDOWS\system32\D71ACF
    C:\WINDOWS\system32\E6AD0D
    C:\WINDOWS\SysWOW64\wezuzavu

    I also want you to download and run both CCleaner and ATF Cleaner by Atribune.

    This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  8. gplaydee

    gplaydee Private E-2

    C:/Glenyx -- July 15, 2006

    I didn't find 50170B, D71ACF, or E6AD0D in System32, but i found them in sysWOW64.

    50170B (Date: Feb 16, 2009)
    D71ACF (Date: Feb 16, 2009)
    E6AD0D (Date: Feb 16, 2009)
    wezazu (Date: Aug 21, 2008)


    Also ran both CCleaner and ATFcleaner. what next?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hummm...that is not what the log indicates:
    Delete them as well as the wezazu file.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me what issues you are having.
     
  10. gplaydee

    gplaydee Private E-2

    I can't delete the d71acf or E6AD0D. It says that it's still in use or protected.

    Btw, the attachment section isn't working for me. this is all it says under Attach Files: "Valid file extensions: bmp doc gif jpe jpeg jpg log pdf png psd txt zip" -- No clickable area.
     
  11. gplaydee

    gplaydee Private E-2

    I think ever since the ATF cleaner, alot of pages are not fully loading or something for FIREFOX. I'm using IE to upload the zip. Here you go.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Removing history in FF maybe the reason for that....however, lets do this first:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day):
    C:\Documents and Settings\Administrator\Local Settings\TEMP\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  13. gplaydee

    gplaydee Private E-2

    Hi, it merged successfully. Unfortunately, avenger.exe is not compatible with my system. I run Windows XP 64 bit.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    downloading a tool we will need -

    Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HJT

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the

    below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

    (or, after highlighting, right-click and choose copy):

    * Return to Killbox, go to the Folder menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if

    you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Get me the new MGLogs.zip
     
  15. gplaydee

    gplaydee Private E-2

    I got NO PendingFileRenameOperations prompt. :)

    MGlog in attachment.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Killbox is not showing that it removed anything. And the logs show it is all still there.

    The registry fix seemed to have stopped them from loading, so do a search for each of these in safe mode and see if you can delete them:
    C:\WINDOWS\system32\50170B
    C:\WINDOWS\system32\D71ACF
    C:\WINDOWS\system32\E6AD0D
     
  17. gplaydee

    gplaydee Private E-2

    how do i start windows in safemode?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You reboot your computer and immediately start hitting F8 ...you will then have the option to start in safe mode .....
     
  19. gplaydee

    gplaydee Private E-2

    Okay, I deleted those three, but once again, i found them in my syswow64 folder. I went through my system32 folder they are not there.

    I ran MGtools again. zip in the attachment.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have no idea what your syswow64 folder is....but I suggest you remove them also.
     
  21. gplaydee

    gplaydee Private E-2

    Yep, did that. Am I in the clear? :D
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It just dawned on me that you are running a W2003 server?

    If you did manage to remove those files, then just let me know if you have any additional problems before I give you the final cleanup. You can re-run both MBAM and SAS to see if anything shows up.
     
  23. gplaydee

    gplaydee Private E-2

    So i did both scans, they came up with NO infected files.

    As for the W2003 server, I have no clue what that is.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  25. gplaydee

    gplaydee Private E-2

    So far so good. thanks alot, tim!
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds