Should I run scans again before posting logs?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by schemero, Jun 28, 2011.

  1. schemero

    schemero Private E-2

    I ran the scans 6 days ago. Thought my problem had been solved, so I didn't post the logs, but I was wrong. Should I post the logs from 6 days ago, or should I run them again? This seemed to be one of my problems: Vundo/Variant-SR C:\WINDOWS\SYSTEM32\LENODANU.DLL

    Thank you in advance!

    Sandra
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Get us fresh logs. So do run the scans again and then attach them to your next reply.
     
  3. schemero

    schemero Private E-2

    Logs

    Initially, I notice my computer started running slowly and poorly. Then I started getting a popup every time I tried opening anything, including, files, browsers, programs, and documents.

    The popup read "c/windows/system32/lenodanu.dll is not a valid windows image

    I found a post where someone added .com to the end of the lenodanu.dll When I did this, it stopped all the popups. I notice my computer was still working poorly, and I tried run several scans.

    Eventually what happened was that every time I attempted to boot up, my computer would freeze up just at the point that it finished booting. The only way I was able to use my computer was in safe mode.

    One June 22nd I ran the scans you suggested. One of the things removed was the lenodanu.dll and was listed as a vundo variant/sr from SuperAntiSpyware.

    After running the 5 scans you suggested, I was able to log onto my computer again. Although it was still a bit sluggish, I ignored it because I was trying to catch up with work! (I had been down for 3 days)

    I shut my computer off last night, and when I went to login, it froze again just as it finished loading...and the loading was very slow.

    I rebooted in safemode and ran the SuperAntispyware and malwarebytes and stopped at that point waiting for your response. I tried booting in normal mode again and was able to this time.

    After your response to run fresh scans, here are my logs.

    The following is what I did:

    • ran CCleaner
    • uninstalled and then reinstalled the latest version of Java
    • DeFogger - disabled CD Emulation
    • ran SuperAntispyware (log)
    • ran Malwarebytes (log)
    • uninstalled AVG
    • Ran Combofix - while running the following popped up: pev.cfxxe has encountered a problem while running Combofix, so I ran it again and encountered the same problem so I waited for the log (log)
    • Re-installed AVG
    • ran Root Repeal (log)
    • ran MGTools (log)


    Thank you so much for your help in advance! :)

    Sandra
     
  4. thisisu

    thisisu Malware Consultant

    Re: Logs

    We're still missing your logs :-D
     
  5. schemero

    schemero Private E-2

    Re: Logs

    So sorry, I forgot to attach the logs!
     

    Attached Files:

  6. schemero

    schemero Private E-2

    Re: Logs

    Here's the last log
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Logs

    NOTE: AVG needs to be left un-installed until you are instructed otherwise.

    dr.m
     
  8. schemero

    schemero Private E-2

    Re: Logs

    Let me try it again
     

    Attached Files:

  9. schemero

    schemero Private E-2

    Okay, I will uninstall AVG again.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLogs.zip was missing a few logs. Did you wait until it told you it was finished? Please download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Now re-run the exe and attach the new log.
     
  11. schemero

    schemero Private E-2

    I apologize for the error...here is a new log for MGTools
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are basically clean, though there are a few things we can remove:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Application Data\tmp124.log
    C:\Documents and Settings\All Users\Application Data\tmp124.tmp
    C:\Documents and Settings\All Users\Application Data\tmp12D.log
    C:\Documents and Settings\All Users\Application Data\tmp12D.tmp
    C:\Documents and Settings\All Users\Application Data\tmp135.log
    C:\Documents and Settings\All Users\Application Data\tmp135.tmp
    C:\Documents and Settings\All Users\Application Data\tmp36.log
    C:\Documents and Settings\All Users\Application Data\tmp36.tmp
    C:\Documents and Settings\All Users\Application Data\tmp3D.log
    C:\Documents and Settings\All Users\Application Data\tmp3D.tmp
    C:\Documents and Settings\All Users\Application Data\tmpE1.log
    C:\Documents and Settings\All Users\Application Data\tmpE1.tmp
    
    Registry::
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  13. schemero

    schemero Private E-2

    Thank you so much for helping me so quickly. I created the CFscript as discribed above. I dropped it into combofix and it started, I updated to a new verison and then the sreen opened and read

    "Scanning for infected files...
    This typically doesn't take more than 10 minutes
    However, scan times for badly infected manchines may easily double"

    That's as far as it would go, there was a blinking curser...but it just sat for one hour this way.

    I finally tried closing it out, so I could write you, but I can't. I can't get online, I can't reboot. Please let me know how I sould proceed.

    Thank you again for all your time.

    Sandra
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what happened. Nothing we were removing would have caused this, unless Combo found some system file that was infected and remove it. Can you boot to safe mode? Do you have you OS cd?
     
  15. schemero

    schemero Private E-2

    I held down the start button to shut down, and now it rebooted fine! :major
    Combofix did not complete as described above...what should I do now?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
    • C:\Avenger.txt

    Make sure you tell me how things are working now!
     
  17. schemero

    schemero Private E-2

    I received a success message for adding the above to the registry. I ran MGtools, I'm assuming the new scan overrides the old logs? (I hope!) If not, let me know and I will redo it.

    I'm going to go see how it works now! :) If I am all set, would you please let me know which scans I should be removed and which should stay.

    Thank you again!

    Sandra
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. Let me know if you have any other issues. In the meantime:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  19. schemero

    schemero Private E-2

    THANK YOU , THANK YOU, THANK YOU!!! Thank you for all your help, and all the time you gave to help me with my problem. Everything is running well, and I am so very pleased. Also, thank you for the instructions and recommendations now that we are done!

    Can I just say, I LOVE MAJORGEEK!!!

    With much appreciation...

    Sandra Mejia
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome, Sandra. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds