Still Infected I think !!

Discussion in 'Malware Help (A Specialist Will Reply)' started by dedeunix, Apr 30, 2008.

  1. dedeunix

    dedeunix Private E-2

    Hi,

    I've followed a fews tips and the "READ & RUN me first", but i still find these files in the hidden files:

    C:\rhh31b.com
    E:\3bqqnkd.bat
    E:\rhh31b.com
    E:\rxub.bat
    E:\e2u.exe

    also I would like to clean my laptop from the MGTools, this programme installed a bunch of files ??

    like

    rhh3lb.com
    ig.bat
    gvsqikes.cmd
    ...etc

    thanks for helping and thanks for your website ;)

    NB: DO NOT TAKE MY NAME AS MY RUNING SYTEM, I'M UNDER XP :eek:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not run ComboFix as requested. You should have run it before running MGtools. Please follow the procedure for ComboFix and attach the log as requested. Then get a new log from MGtools by doing the below.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. When it finishes, attach the new C:\MGlogs.zip file.


    Are you currently having any problems with malware?
     
  3. dedeunix

    dedeunix Private E-2

    HI, thank's for u're help,

    i did run cf.exe yesterday? using this post (http://forums.majorgeeks.com/showthread.php?p=1145937)
    and also during the read & run me first?

    Anyway, here are my new log files as requested.

    THX again ;)

    for the malware question, i have a "PSW" that keeps on comming back ?? seems to be a sort of "adobeR" he keep me from seeing the hidden files. it better now i've followed u're instructions.
     

    Attached Files:

  4. dedeunix

    dedeunix Private E-2

    Here is my cmd "screenshot" of what is hidden (dir /ah) on my root hard drive "C: & E:"
    E: is an external usb drive
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But the confusion has come from the fact that you did not install it where requested. You put it here:

    C:\Documents and Settings\David\bureau\cf.exe

    It must be on your Desktop as requested. You need to do this now or you will not be able to do the next steps. You should have this:

    C:\Documents and Settings\David\Desktop\cf.exe




    Now we need to use ComboFix again. Make sure it is on your Desktop.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. dedeunix

    dedeunix Private E-2

    The reason for this difference is that my running system is installed in french, Bureau mean's Desktop :)

    Anyway, i've donne all that you talled me, and got a success message for the new entered registry.

    here are my new log and the "invite comande" result.

    Everything seems to be back in order? hope it wont come back like it did for weeks now :confused

    tell me how my logs go !!

    Thanks Dede
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's goood to know. I'll add that to my foreign languages vocabulary. ;)

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  8. dedeunix

    dedeunix Private E-2

    Everything seem 's ok exept this thing ?

    My antivirus get this entry each time i start the computer (attach file) note that my AV is NOD32 (eset) and the PSW... came thru USB disk?

    is there anithing to do?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not complete my final instructions if you are getting that. That is a detection in System Restore. In step 6 you should have toggled System Restore as requested and all restore points would have been removed.
     
  10. dedeunix

    dedeunix Private E-2

    Hi Chaslang,

    I'm sorry for that, after checking the time on the repport, it was before doing the final step :eek:.

    My computer as been allright since, faster and no more alert from the anti-virus.

    Thank you very much for your help.

    Dede ;)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds