Win32:Cinmus-AU [Adw] found on my System !!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by simonrankin, Apr 23, 2009.

  1. simonrankin

    simonrankin Private E-2

    Hi guys....

    This is Simon...new to Major Geeks.....
    Please help me out with this situation. rolleyesrolleyes

    One bad dirty day i found that KAV 2009 on my system was bloscked by some shit!!! so i just tried finding it out by installing MALWAREBYTES'S ANTI MALWARE and scanned my system coz it was not allowing me to install Avast 4.8 that i have downloaded. after a long fight back with Malwarebytes, that damn shit allowed me to install it !:cry:cry

    Then my KAV 2009 also worked for few minutes, scanned some parts of my PC, but t got disabled again !!!:confused

    MY Avast now shows me that it had found this Win32:Cinmus-AU [Adw] and when i click on DELETE or DELETE PERMANENTLY or MOVE TO CHEST....it shows me this...

    cannot process : " c:\Documents and Settings\Local Service\Local Settings\Temporary Internet Files\Content.IE5\780JKUVE\4[1].exe\$Temp\145.exe\$[34]\$RO" file.

    Please Help Me !!!!!!:confused:confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach ​
     
  3. simonrankin

    simonrankin Private E-2

    Hi Chaslang.....thanx for ur reply.

    I did nit found that drive TDSSERV.sys in my System. However i found this bdfdll drive which is shwing a warning sign on it. :)

    Chaslang, the problem is that the KAV2009 i hav is disabled and i have tried installing it again, but it doesnot uninstall.:(

    The Avast4.8 home edition that i have doesnot show me anything on the system, neither does the Bitdefender free v10 antivirus. The Malwarebytes' Anti Malware also shows me nothing now.

    But when i connect my External drive (that has all my important data) when the system, is running it behaves normally except for the hidden files option, where it highlights both the show hidden as well as does not show hidden ! but it never shows hidden files. i can access them by typing their address in the address bar however.:cry:cry:cry

    When i connect the external hard drive and reboot the system, i can see some different language when i right click on it in My computer. So on a friend's advice i have deleted all the .exe files in my external hard disk. But still the problem persists !!:major
    Please help me out sir !!

    I have

    Avast4.8 home edition
    Bitdefender free v10 antivirus
    Malwarebytes' Anti Malware
    Ccleaner

    installed on my system. I have unlimited Internet connectivity, so if u want me to download any software, i can. Please help my clean this shit out of my system without harming my important data which is career related.

    I believe in Major Geeks. So Thank you in advance !:wave:wave
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is Bitdefender.

    When you complete my instructions and run the cleaning procedure and attach the logs that are requested, we can then begin to help you.

    The first instructions in the READ & RUN ME tell you that you must not have more than one antivirus program installed. You need to uninstall all but one immeditately before even starting the READ & RUN ME cleaning steps.
     
  5. simonrankin

    simonrankin Private E-2

    Guess My System is working fine now !!!

    Hi Chaslang....

    Thanks a lot for ur valuable advice in Read & RUn.
    I have followed them and now my system seems to be running fine. I have not encountered any problem during the installation or scan of all the four (Super AntiSpyware, Mbam, Combofix, Mgtools) !:)

    I have ONLY AVAST 4.8 Home edition on my system now. You have mentioned that as one of the good anti virus software .I have also installed PC Tools FireWall Plus for future protection.:confused:confused

    So Please take a look at my Logs and let me know if i have to do anything else...:major

    Thanks once again chaslang​
    :cool
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need the proper log from MGtools. As stated in the instructions this is the C:\MGlogs.zip file. DO NOT attach anything from inside of the C:\MGtools folder. We need only this ZIP file as stated.
     
  7. simonrankin

    simonrankin Private E-2

    Hey Chaslang.....sorry for the issue....rolleyes
    Hope i have attached the right one now.:confused

    Please reply !:)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's the correct file, but it is totally incomplete because you did not follow the instructions for downloading and running MGtools.exe. We stated that it must be saved and run from the root folder of your Windows boot drive. For you like most people, this would be the C drive. Thus you should have C:\MGtools.exe. However you saved and ran it from drive E and thus it did not run properly. Please follow the instructions again and save and run it from C:\MGtools.exe Then attach the C:\MGlogs.zip file.
     
  9. simonrankin

    simonrankin Private E-2

    Hi Chaslang,

    I did another mistake sir.....
    I had installed Windows updates onto my system. It said Windows Service Pack 3. So i thought it would be better. But that thing has completed taken the system for a toss....There was a Blue screen error and it never re started again. It would not restart in any mode....neither in recovery console, nor in safe mode...nothing....:cry:cry

    The only choice i had, was Formatting the system !
    I did that with my Original Windows XP CD. I deleted both the partitions first and then partitioned it again.
    The system was now OK....:(

    Then when i opened My Computer and was Horrified to see that both my C and D drives when i right click on them show a different language all together !:confused
    Then i opened my IE to go to Major geeks and repeat READ N RUN ME but it had a Chineese homepage !! I was shocked.....Dumbstruck....Horrified.....Petrified....and anything u would expect. The problem is back again.....:cry:cry

    I then downloaded AVAST 4.8 HOME EDITON, SUPER ANTSPYWARE, MBAM, COMBOFIX, MGTOOLS, Firefox.

    I tried real Hard to Install Avast....but it wouldn't let me do it !!but by God's Grace.....i installed it at last.....and then when i scanned with it, it found
    • ROOTKIT TROJAN
    • TROJN GEN OTHERS
    • WIN32 CINMUS-AU
    • and 1 or 2 others. But it was able to delete them.

    Now i installed Super Antispyware and also MBAM. Now i connected my External Hard Drive which has all my Important data in it !( Chaslang, i am an Animation Student. So i have many works that are too imp for me and to get a job for me they are the only proof that i can show anyone to prove iam an animator )

    Now i have Run the READ N RUN ME FIRST...and now when i right click on all my 3 drives....C, D, F(External Hard Drive)...They are all normal..... :)
    I am now attaching all the Recent three logs again. Iam unable to attach MGTOOLS log as it is a large file. SO i would try attaching it if you really want it. Please let me know.Please check them and let me know the status of my system....
    Waiting for a Good News from u Chaslang......
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not attached the new MGlogs.zip file from a properly installed MGtools. I cannot continue without it and I so see at least one issue that needs to be fixed based on your ComboFix log.
     
  11. simonrankin

    simonrankin Private E-2

    Hi chaslang.....
    iam unable to upload the file.its big in size !
    please tell me how do i do it ?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you trying to upload the correct file? The log file is C:\MGlogs.zip
     
  13. simonrankin

    simonrankin Private E-2

    Yes.....this is the file. I am succesful !!!!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. simonrankin

    simonrankin Private E-2

    Hi Chaslang....

    These are all my new logs....i ran all of them today....Please check them and reply me.....

    My system looks fine now.....:)

    Waitin for ur reply sir.....
    :major
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow my instructions properly. I did not say to simply double click on ComboFix. You need to do what I requested with the CFScript.txt file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds