WinAntivirus 2009 on XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by cjon, Nov 21, 2008.

  1. cjon

    cjon Private E-2

    I have read most of the existing threads on WinAV2009 and done the preliminary cleanup steps down through running Combofix. I had to rename the executables for SuperAntispyware, Malwarebytes and Spybot, but since you had tipped me off ahead of time, it worked. I am attaching my logs (I ran mbam twice because I couldn't get it to update before the first pass) and will await instructions on how to proceed. I'm comfortable with Registry edits, if necessary.
    Note that I created a new account from which to do the work (AAserviceguy).

    Thanks,
    CJon
     

    Attached Files:

  2. cjon

    cjon Private E-2

    My bad. I read in the wrong place and posted the preliminary logs instead of the MGTools log. it is attached.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans took care of most of it...let's do this:

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Use add/remove programs to uninstall Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL:
    
    File::
    c:\documents and settings\Ronald Tolen\Application Data\qiripu.pif
    c:\windows\qenoxa.pif
    c:\windows\tiheni.ban
    c:\documents and settings\Ronald Tolen\Application Data\qugoki.com
    c:\windows\asonukoc.exe
    c:\windows\SYSTEM32\sehixyz.sys
    c:\windows\rehita.sys
    c:\windows\upukex.db
    c:\program files\Common Files\qohapozyqy.pif
    c:\windows\SYSTEM32\xolywucuxo.bat
    c:\program files\Common Files\pigop.scr
    c:\documents and settings\Ronald Tolen\Application Data\yjeroru.bin
    c:\windows\emumi._dl
    c:\documents and settings\All Users\Application Data\yfasal.dat
    c:\documents and settings\Ronald Tolen\Application Data\nupesixahy.exe
    c:\program files\Common Files\xotemyxune.bin
    c:\windows\aquwifyp.scr
    c:\windows\SYSTEM32\ynapewa.bin
    c:\windows\SYSTEM32\ubeb.bat
    c:\windows\SYSTEM32\obiqahow.db
    c:\windows\kypaqav.pif
    c:\windows\SYSTEM32\aqokaf.bin
    c:\program files\Common Files\afyfatoxot.exe
    c:\windows\tybug.sys
    c:\windows\SYSTEM32\osoly.scr
    c:\program files\Common Files\ditojohapi.dl
    c:\program files\Common Files\hoky.lib
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. cjon

    cjon Private E-2

    Tim,
    Thanks for the response. I had gone part way down the road already. The 'no file' items had been removed via HJT, I had updated Java to the latest version. and I reinstalled AVG and ran another complete scan. I also ran Panda's online scan. It does not like Combofix. As a result, I had to reinstall it to complete your instructions.

    When the machine rebooted at the end of removing the file list, it hung and I had to do a hard reset. It didn't seem to matter, combofix went ahead and wrote the log as expected. It looks to me like it fixed everything it was supposed to.

    I will once again reinstall AVG. I couldn't figure out a way to completely disable it, so I simply uninstalled it. If there is a way, you might consider a sticky to tell folks how. (or maybe it's there and I missed it...)

    Anyway, thanks for all your help and here are my logs. I'll check back later for any followup I need to do.

    CJon
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing showing is from your Combo log:
    c:\windows\cornbroom.ico
    c:\windows\SYSTEM32\fbbcbabdada_z.ocx

    They do not show in the NewFiles log......but do a search for them and if found, remove them.

    Otherwise, your logs are clean.

     
  6. cjon

    cjon Private E-2

    Tim,
    Many thanks. The cornbroom icon is simiply that, an icon of a broom that I use to mark a "Weekly Cleanup" folder I put on all the machines I work on. It contains links to CCleaner, Malware Bytes Anti-malware, Adaware, Spybot and the owner's antivirus of choice. I'll kill the .ocx file and finish the cleanup. Thanks for all your help.

    CJon
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds