Virus Stressing 2

Discussion in 'Malware Help (A Specialist Will Reply)' started by dark4une, Dec 19, 2010.

  1. dark4une

    dark4une Private E-2

    First I want to thank the person who helped me on the last one and I want you to know that I think MajorGeeks has some of the best customer service I have experienced, with many forums out there I credit you guys with having the easiest one to navigate.

    Ok so the issues with my laptop is resolved but the one with XP tower is still causing problems, I am going to start with the fixes in your forum but I believe there will be logs involved in this one.

    XP Tower
    32 bit OS
    3 gb RAM
    XP professional

    The issue appears to be the same, browser redirect but also Win32/svhost errors as well as multiple virus attacks.
    Again I will try the fixes you suggest.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the requested logs when you are ready. ;)
     
  3. dark4une

    dark4une Private E-2

    It took a while to run all the malware and fixes so I am hoping I collected the right information.
    After running all of the fixes your forum provided I am happy to report I believe the malware/sypware issue is resolved the only thing that keeps popping up is a win32/scvhost error that locks my desktop up and does not allow me to proceed I have attached the 2 logs I was able to collect, if I need more information for you please let me know, thank you.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about logs from the below? You need to attach those too.

    • SUPERantispyware
    • RootRepeal
    • MGTools ---> C:\MGlogs.zip
     
  5. dark4une

    dark4une Private E-2

    MG tools I thought I had but I will look, spyware locked up and I could not get it and root repeal I could not find the exe even with your link, I will look again.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The forget Rootrepeal, just need to see the other logs. Especially MGlogs.zip
     
  7. dark4une

    dark4une Private E-2

    I found the mgtools zip but where wouls superantispyware log be.
     
  8. dark4une

    dark4une Private E-2

    Here are the other logs, hope this helps.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this:
    Statement on AVG Free 2011

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Now please put ComboFix directly on your desktop, it should not be run from here:
    Running from: I:\ComboFix.exe

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    AtJob::
    
    File::
    c:\windows\SET126.tmp
    c:\windows\SET11A.tmp
    c:\windows\SET117.tmp
    c:\windows\SET1E6.tmp
    c:\windows\SET1DA.tmp
    c:\windows\SET1D9.tmp
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message


    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and attach the new C:\MGLogs.zip
     
  10. dark4une

    dark4une Private E-2

    I followed your instructions and I am submitting the logs you requested, thank you again for your help.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In what order did you run the scans? TDSSKiller said it found an issue and cured it, but both Combo and the runkeys log still indicate a problem.

    Please download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe. Then attach the new C:\MGLogs.zip.
     
  12. dark4une

    dark4une Private E-2

    I ran it in the order of your previous reply.
    Combo Fix
    TDSSkiller
    MGtools

    I downloaded MGtools again and I am running it, when complete I will send you the zip log.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, the new version cleared up the question. All is well.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  14. dark4une

    dark4une Private E-2

    I want to thank you for your help, sorry I did not reply sooner, the reason I needed to get this expedited so quickly was my wife died in October and all her pictures were on this PC and I needed them for a life celebration, so thank you. With your help I was able to grab them and build the video show, I have always trusted you guys above most forums...
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My condolences on your loss! I am glad that you were able to get back to working order.

    You are most welcome. Safe surfing. :)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry for your loss. Glad you got the pictures safe. :)
     
  17. dark4une

    dark4une Private E-2

    I consider this thread resolved. :)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds