Request help with malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by jokib, Dec 26, 2008.

  1. jokib

    jokib Private E-2

    I completed all of the steps on this thread:
    http://forums.majorgeeks.com/showthread.php?t=139313

    and I'm wondering if someone would be willing to look at these logs.

    I'm pretty sure everything is fixed but I don't really know what I'm doing so I would appreciate an expert opinion.

    The problem started when I did an IQ test following a link in Facebook. I don't remember if I was using Firefox or IE 6 at the time.

    attached are three of the logs ... I can't seem to find the SPybot search and destroy, but will try to attach that one seperately.
     

    Attached Files:

  2. jokib

    jokib Private E-2

    I can't find the remaining log - I was having a lot of trouble getting combofix to run, so I may have deleted the log accidentally. Should I repeat some or all of the steps?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome to majorgeeks

    We are currently reviewing your logs and will get back to you with a plan of action as soon as possible. Thanks for your patience during this time.

    Now you ran MBAM but didn't let it fix what it found! You need to re-run it and ensure that you fix all it finds.

    In the meantime if you come back and see my response, forget about the Spybot search and Destroy log but could you attach for us the SUPERAntiSpyware log please? You can retrieve it very easily by doing the below:

    • Open up SAS
    • Go to "Preferences"
    • Hit the "Logs/Statistics" Tab
    • and there is your log

    Thanks
    Kestrel13!
     
  4. jokib

    jokib Private E-2

    Thank you, here is the SAS log.

    Am re-running MB.
     

    Attached Files:

  5. jokib

    jokib Private E-2

    Here is my new MBAM log ... looks like it didn't find any problems. Is it possible that I saved the log before I fixed the problems?
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) You are not running any anti-virus on this machine! Please install one when I instruct for you to do so further on down in my fix!


    2) you should organise your desktop because when it's messy it provides the perfect place for malware to hide.


    3)
    Please go to Add or Remove Programs and uninstall the following old software:

    • J2SE Runtime Environment 5.0 Update 2


    4) Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    02 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


    After clicking Fix exit HJT.


    5)
    Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    
    File::
    C:\LOG12F.tmp
    c:\windows\Tasks\chzpzjmu.job
    c:\windows\Tasks\ipiwtbow.job
    c:\windows\Tasks\mxckkzme.job
    c:\windows\Tasks\sukpmkly.job
    c:\windows\Tasks\wkdetilz.job
    
    
    DirLook::
    c:\windows\system32\cap2
    c:\windows\system32\ain
    c:\temp\REX81 
    C:\Documents and Settings\Owner.DESKTOP\Local Settings\Application Data\.#
    
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    "TkBellExe"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000000
    "UpdatesDisableNotify"=dword:00000000 
    
    
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    6) Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6



    7) Now Run Ccleaner!


    8) Please visit the following link to install an antvirus available from the list there. I would recommend you steer clear of AVG8 at the moment until you upgrade your memory as it can be quite resource hungry unless you change the install step to *CUSTOM* and uncheck the Link Scanner and Safe Search options, to reduce system resource use and speed up browsing.

    How To Protect yourself from Malware

    9) Now delete the older version of MGTools and download the latest version of MGTools.exe and run it

    10) Now attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  7. jokib

    jokib Private E-2

    Thanks so much ... I installed Norton Utilities before I saw your reply so my apologies if that was the wrong thing to do. I really appreciate your help.

    I followed the instructions and attached are the requested logs.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All you have from Norton is "Norton Save and Restore" which is not an antivirus program. You still need to get your PC protected.

    1) Now we need to use ComboFix to remove a bunch of files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    [code
    KILLALL::

    File::
    C:\LOG12F.log
    c:\temp\REX81\BDF.log

    Folder::
    c:\windows\system32\cap2
    c:\windows\system32\ain
    c:\temp\REX81
    C:\Documents and Settings\Owner.DESKTOP\Local Settings\Application Data\.#

    [/code]
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    2) Now Run Ccleaner!

    3) Now goto this link Using MGtools and download the new version of MGtools.exe using the black bold print link in the first sentence.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    Thanks
    Kes13!
     
    Last edited by a moderator: Dec 30, 2008
  9. jokib

    jokib Private E-2

    My computer seems to be working much better.

    The combofix log and MG tools logs are attached.

    When I went to download Ccleaner, I must have followed a wrong link or something and wound up running something called Reg Cleaner.

    I went back to the instructions in the forum and got Ccleaner and ran that too.

    I have some more Norton software to install, so I will do that too.

    One other thing that I must have screwed up: in your instructions below, I still see these files on my computer

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    but they did not show up when I ran analyze.exe, so I didn't have the option to fix them.

    Thanks again
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it! :)



    Yes, you followed a wrong link, you clicked on a sponsored ad. You can uninstall RegCure 1.5.1.3 using Add or Remove Programs.

    We fixed these 04 entries back in my message #6 step #4 that is why they are no longer present when you scan this again with HijackThis. And yes their files are still present in your machine because all we were doing when we fixed them was prevented them from running at start-up unnecessarily. WE didn't want to get rid of the programs completely because they are not malware.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. jokib

    jokib Private E-2

    Thanks, Malware Fighter!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're welcome! Happy New Year!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds