Still have malware issues after all steps followed

Discussion in 'Malware Help (A Specialist Will Reply)' started by usmc_wife_1345, Dec 11, 2007.

  1. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay, I have followed all the steps in the read and rub before asking for support sections. I am still having the same problem. What happens is that a box pops up (made to look like a security alert) telling me there has been an attempt to infect my computer. If you click on anything in the box (red X, cancel or OK) an IE page pops up for a download of spyware.

    S&D was finding a zlob trojan and a smitfraud. The smitfraud is now gone but S&D is still finding a zlob.download.vcd

    I also ran an SE adware.
     

    Attached Files:

    Last edited: Dec 12, 2007
  2. usmc_wife_1345

    usmc_wife_1345 Private E-2

    More logs attached

    SE found nothing.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and install:
    Java Runtime 6

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I have completed all the steps and attached the requested files. Thanks again for all the help! I hope this did the trick!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are getting there .....tell me what these are:
    C:\WINDOWS\go
    C:\WINDOWS\hip
    If you don't know ...delete them.

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Reboot your computer.

    • Download FindAWF and save the file to your Desktop
    Double-click FindAWF.exe to start the tool.
    Select Option 1 by pressing 1 and then Enter. The scan will start and a log will open (awf.txt)

    • Post back with with the contents of awf.txt

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from AWF.

     
  6. usmc_wife_1345

    usmc_wife_1345 Private E-2

    No clue so I deleted them. I did it in "My Computer" but wasn't sure if there is anywhere else I needed to delete it. I also emptied my recycle bin after I deleted it.

    Okay I will post logs in the next post.
     
  7. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I don't have a link anymore to "manage attachments" I see the block where it says the accepted file types but not the actual button to open up where I attach them. What do I do?
     
  8. usmc_wife_1345

    usmc_wife_1345 Private E-2

    No idea what is going on but I can't attach files at all. I am going to try to send it to my desk top and post it from there.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are using IE --> clear all your temp files and cache. Then Hit F5 a few times to refresh it.

    Try using FireFox ....
     
  10. usmc_wife_1345

    usmc_wife_1345 Private E-2

    I am using fire fox. On my desk top which is where I am following instructions, I do have a button Ont he lap top (infect computer I have been trying to fix) there still is no button. I will try yo open it up in IE and follow those steps. I couldn't email the logs as attachments to my desk top to post from here.
     
  11. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I was able to do it in IE but not firefox on the laptop. Wierd. Did I change a setting or something?
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you copy them to a different computer via cd or thumb drive and then try to attach them?

    Oh...good....let me look at them....hang on.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run ATF Cleaner?

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Start FindAWF.exe
    Select option 2 by pressing 2 and then Enter. A text file will open (files.txt).
    In that files.txt, copy and paste the following list of files to be restored:



    C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe
    C:\WINDOWS\system32\bak\ctfmon.exe
    C:\WINDOWS\system32\bak\hkcmd.exe
    C:\WINDOWS\system32\bak\igfxtray.exe
    C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\query_prams.js
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\no_connection_frame.html
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\index_local.html
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\DesktopWeather.exe
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\app.html
    C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe
    C:\Program Files\Siber Systems\AI RoboForm\bak\RoboTaskBarIcon.exe
    C:\Program Files\QuickTime\bak\bak\qttask.exe
    C:\Program Files\HPQ\Default Settings\bak\cpqset.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe
    C:\Program Files\Grisoft\AVG7\bak\avgcc.exe
    C:\WINDOWS\system32\bak\igfxtray.exe


    Close the files.txt and click Yes to save the changes.
    FindAWF wil now terminate the bad processes if running, delete the bad files and restore/replace them with the good files.
    Then it will open a log. Copy and paste the contents of that log in your next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and AWF log.
     
  14. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Yes I ran the ATF.

    Now that I rebooted I can attach files with firefox. They are attached.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You keep getting re-infected.....

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Start FindAWF, select Option 3, by pressing 3 and then enter.
    This will open the text file folders.txt
    Copy and paste next list in it:

    C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe
    C:\WINDOWS\system32\bak\ctfmon.exe
    C:\WINDOWS\system32\bak\hkcmd.exe
    C:\WINDOWS\system32\bak\igfxtray.exe
    C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\query_prams.js
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\no_connection_frame.html
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\index_local.html
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\DesktopWeather.exe
    C:\Program Files\The Weather Channel FW\Desktop Weather\bak\app.html
    C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe
    C:\Program Files\Siber Systems\AI RoboForm\bak\RoboTaskBarIcon.exe
    C:\Program Files\QuickTime\bak\bak\qttask.exe
    C:\Program Files\HPQ\Default Settings\bak\cpqset.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe
    C:\Program Files\Grisoft\AVG7\bak\avgcc.exe
    C:\WINDOWS\system32\bak\igfxtray.exe

    Then close folders.txt and let it save the changes.
    FindAWF will now remove the bak folders and open a log aferwards.
    Post the log in your next reply.

    Next, start FindAWF again.
    Press E then Enter to EXIT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and AWFLog.
     
  16. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I did it! They are attached,.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download SDFix and save it to your Desktop.
    • Run the SDFix.exe by double clicking on it.
    • Allos it to install into the default location which is c:\SDFix
    • Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode )
    • When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Attach the Report.txt file to your next message.
     
  18. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I am running the SDFix right now. Once I have done this and it reboots the computer, will it reboot in safe mode again? When should I switch out of safe mode?
     
  19. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay it rebooted the computer but didn't run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. It is still in safe mode with my desktop icons loaded.
     
  20. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I have tried it three times now and on each reboot, it does not start up again.
     
  21. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Okay I got it to work!
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That looks much better ....run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  23. usmc_wife_1345

    usmc_wife_1345 Private E-2

    Here it is...
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.

    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds