Submitting Malware Removal Logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shaase, Jun 10, 2011.

  1. shaase

    shaase Private E-2

    2 days ago my husband was on Amazon.com completing his check out of a purchase when he had a pop up dialog message indicating that there was a problem detected with his hard drive it had critical errors. If you clicked the OK button to remove the dialog it would just came back. After multiple pop ups another dialog appeared "Microsoft Repair Scan" my husband clicked the button to start scanning PC, and everything went downhill from there.

    The icons on his desktop are light in color like they are hidden files, the start menu recent files icons are not associated with there application folders any longer, the all programs list is empty. Many features were disabled like the task manager, Norton anti virus, control panel and I was unable to run programs like TDSSK.exe. The programs I was able to run were Registry Mechanic, Registry Booster and Trojan remover. All programs had to be executed from there application folder C:\Program Files\filefolder\filename.exe. I was unable to run them from a command prompt, error message could not find the files. The only files I have in my All Programs now are files I had just recently installed on the PC. It feels like I have 2 explorers. I did notice when I was finally able to run Task Manager that there are 2 iexplorers loaded "even on start up without accessing IE". One runs around 20,244k memory usage staying pretty consistent with the number while the other is running at around 51,000k memory usage and constantly changing (going up in size).

    I ran across you site for Mal-ware Removal/Cleaning Procedure and decided to give your steps a try. I was able to complete all steps and logs successfully with the exception of Combofix. Combofix completed half way thru the scan when it locked up the PC creating output files at C:\filename.txt I had to do a hard shutdown. The SuperAntiSpyware did not create a log the first time it was ran, it found tracking cookies which it removed. I ran a search of entire hard drive for the file SASlog.txt and could not find one. I ran the application again and attached it. I hope this did not mess up things.

    I hope I have provided enough details, if I had been the one this happened to I might would have more details about how it occurred, I can only tell you what I was told by the user.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your Programs and how are the icons on the Desktop looking?

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. shaase

    shaase Private E-2

    I went through the steps you provided but still had to reinstall the OS. The Analysis.exe did not find the file O4 - HKCU\..\Run: [UU9G4E9I4A9I4UXAKOTC] C:\pagess.sys\pagess.sys.exe, so I moved onto the next step.

    After running through all the steps and a fresh restart of the PC I still had pop ups warning about a security risk. Antivirus kept warning of Trojans.
    While the unhide.exe brought back all programs list, all the folders were empty. If you right clicked on the folder and tried find the target it was pointing to administrator/Steve or administrator/Steve_oooo the folder they should have been pointing to was Steve and it was not visible to select even though I could see it was in c:\documents and settings.

    Thank you for your assistant, I believe it would have worked but too much time had gone by before I asked for help and I believe with each restart it prorogated/embedded even more in to the system.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you reformat and reinstall?
     
  5. shaase

    shaase Private E-2

    Yes I did a full format and reinstall OS
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, then that would have removed any malware you were having. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds