remnants of xp antivirus 08 and possibly a worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by SomeCrazyStuff, Sep 15, 2008.

  1. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ok im working on recleaning my dads laptop.. obviously last time i tried i didnt get it all.. it would seem that whatever i left on it is still going out and downloading trojan downloaders as in the past 2 weeks dad has gotten 51 in one week and 8 in the next(as marked by zonealarm)..

    i ran the read and run first..

    i must appologize before i go any further because instead of making notes i decided to try to remember the errors and such.. and now i cant remember them after the 3hours of scans... so.. sorry... will do better in that area in the future..


    a couple of notes:
    was unable to defrag.. both by the windows defrag and i tried diskkeeper... neither worked..

    superantispyware free edition ran just fine.. but on shutdown it hung and i had to force shutdown(i waited about 15 minutes while staring at a black screen for it to shutdown)...
    it rebooted just fine though..

    everything else ran fine except mgtools.. it gave me an error that i still didnt write down.. but this error was different from the ones listed in the guide to running mgtool in read and run first.. again sorry for my idiot decision to not write the error down... but it gave me the option to hit ok to terminate or cancel to debug.. i hit ok to terminate and mgtools seemed to go on and finish...

    ok heres the logs.. i hope there isnt anthing i missed in the read and run first as i uninstalled almost everything dad had on the computer that didnt come preinstalled.. if i did miss something let me know so ill know to look for it in the future..

    thx in advance for any help xD
     

    Attached Files:

  2. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    and the combofix log..

    again thx for help
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I assume you will be installing an AV program and Java Runtime 6

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\14.tmp
    C:\Program Files\WildTangent
    C:\Documents and Settings\All Users\Application Data\WildTangent

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now tell me what problems you are still having.
     
  4. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    oook.. now... i ran HJT and had it fix that line... but i couldnt get the java or windowsmessenger remover downloads due to a http 403 forbidden error..

    is that from one of the scans or somthing else..

    all other webpages seem to load fine.. just downloads give me the 403 error

    what you think?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Possibly a problem with the forum........try again later. :)
     
  6. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    nope i dont think so.. on my laptop which i have sitting right next to me i can download the files.. but not on here.. i relize i could just get the files from my laptop.. but if this is going to cause a headache for all downloads i would like to address that now as well...
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Strange indeed.....run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  8. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    iight here you go.. sory im just now gettin back to you.. bloody school and work too.. i wanna break.. lol xD

    odd that this is saying it cant find the specified files and listing all the system services..

    ok i got a processDll.exe - common language runtime debugging services error

    the exact text of the error is:

    application has generated an exception that could not be handled.

    process id=0x970 (2416), thread id= 0xdc0 (3520).

    click ok to terminat the application
    click cancel to debug the application

    ...i hit ok...

    crap im typing this on the wrong computer.. will post the mgtools.zip from the laptop we are dealing with in just a second...
     
  9. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ok slightly longer than one second.. but here it is..

    and i think i typed mgtool.zip earlier.. i meant mglogs.zip...my bad.. been a long day..
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs....you could try going to start / run / type "sfc /scannow" without qoutes.....have you xp cd handy and note the space between the sfc and the /scannow.

    Run it at least twice.....then I may have to send you to software to continue with your issues.
     
  11. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    hmm.. trying now.. yes i have an xp pro oem cd.. but not the full fledged version... dont remember if this computer was xp pro or not... too many of them.. >.<

    ok its asking for xp pro service pack 3 cd.. the one i have is sp2.. any ideas there?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click my computer / properties
     
  13. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    check edit.. i thought i got it before you posted again.. sry
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software section regarding slipstreaming SP3 into your xp disc....they may also help with the other issues. :)

    If you are not having any other malware problems, it is time to do our final steps:
     
  15. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ight will do.. and thx for all the help.. xD
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds