Sorry Had to start over due to attachments count

Discussion in 'Malware Help (A Specialist Will Reply)' started by 3strokes, Mar 29, 2009.

  1. 3strokes

    3strokes Private E-2

    Hi
    I was still under the impression that we were allowed up to three attachments per submission (thus necessitating two posts for four attachments).
    I'm therefore attaching my four to this one (and I can't remember the title I used for my preceding one--of today (with two attachments).

    Preparing for 01APR I ran Avast (My usual is Zone Alarm Security Centre/Suite..... paid for version)

    Avast told me I had numerous infections of:
    Nidle.exe4ff Win32:Trojan-gen HTML:Iframe-inf Win32:Vitro and
    ALCMTR.exe was infected.

    I ran the READ and RUN me first and here are the four logs.

    Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Majorgeeks. :)

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    Thanks for your patience during this time.

    Kes

    PS.. ensure that you have followed Tim's advice in this post
     
  3. 3strokes

    3strokes Private E-2

    Thank you.

    Done.
    C:\Program Files\Mozilla Firefox\extensions\{3E3C9BC8-9234-4A24-BF2A-A0AEB83DC32E}
    No longer exists.
     
    Last edited: Apr 1, 2009
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did Avast remove these files? Nidle.exe was definitely a problem.

    I'm not seeing anything much in your logs at all


    Please go to Add/Remove Programs and uninstall the following old versions of java:
    • Java(TM) 6 Update 2
    • Java(TM) 6 Update 12


    Then use Windows Explorer to find and delete the below bold files:

    • c:\windows2\000001_.tmp

    Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any CURRENT problems you are having.

    Thanks
    Kes
     
  5. 3strokes

    3strokes Private E-2

    Yes, Avast removed Nidle

    Done, but as GetLogs.bat was running, an Alert Window popped up
    over the DOS cmd window.
    Its title said: "ProcessDll.exe - Common Language Runtime Debugging Services"

    The text said,"Application has generated an exception that could not be handled.
    Process id=0xb4 (180), Thread id=0xeb0 (3760).
    Click OK to terminate
    Click Cancel to debug the application

    I clicked OK to terminate, and the batch file told me to get
    my log from C:\MGlogs.zip (which I'm attaching...)

    When IE6 launches from clicking on a URL link (whether the link is in a post or an email) two instances of Internet Explorer 6 open, one remains blank and the other displays the target URL. This behaviour (two instances of the browser) has only started recently with the discovery by Avast of "malware". I don't know if it's significant.

    Iobit Advanced Care has been wanting to update its database for the last couple of days (when I would turn my computer ON to check for replies, but I would Cancel it since I was not supposed to install anything or run any scans.

    Thank you ever so much for the help all of you ladies and gentlemen are giving us.

    Thanks
    Kes[/QUOTE]
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Any non malware related issues you are having should be resolved/worked out in the software forum.

    Just a couple things left to do now, you're logs are clean. :)

    Please empty temporary files in the below bold directories:

    • C:\Documents and Settings\Ahmed\Local Settings\TEMP
    • C:\WINDOWS2\TEMP

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. 3strokes

    3strokes Private E-2

    I didn't know if that behaviour was not due to any malware. It only appeared when I was struck by malware.


    C:\Windows2\temp would not let me delete a file called Perflib_Perfdata_70c.dat dated today. I'll try rebooting and see if I can get to it and delete through Command Window.




    1. Done

      Done

      Done.

      Thank you very much
      and have a Happy Easter.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not necessary. :)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    A very happy Easter to you too! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds