Windows XP BSOD recovered

Discussion in 'Malware Help (A Specialist Will Reply)' started by WHAnderson, Oct 25, 2010.

  1. WHAnderson

    WHAnderson Private E-2

    I just finished salvaging a system which had a BSOD and accomplishing your MalWare Removal procedure. Could you look at the logs and verify they are clean?

    Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reviewing your logs, and will get back to you with a set of instructions later on tonight when I return from work.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    What happened with SUPERantispyware and Malware Bytes? Soon I will have you run both and attach logs from doing so.

    Uninstall this ---> Fast Browser Search Protection

    and these outdated java versions

    • J2SE Runtime Environment 5.0 Update 11
    • J2SE Runtime Environment 5.0 Update 6
    • J2SE Runtime Environment 5.0 Update 9
    • Java 2 Runtime Environment, SE v1.4.2_03
    • Java(TM) 6 Update 20
    • Java(TM) 6 Update 3
    • Java(TM) 6 Update 4
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7

    Uninstall this too ---> Viewpoint Media Player

    Running from: c:\downloads\ComboFix.exe <--- Combofix needs to be directly on your desktop before we continue.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FileLook::
    C:\WINDOWS\system32\73626C89A0.sys
    File::
    c:\windows\Kxeyupet.bin
    c:\windows\Ayeqinagogutages.dat
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Goto VirusTotal and upload the following file for analysis.

    • C:\WINDOWS\system32\73626C89A0.sys

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Attach logs from MBAM and SAS and include the results from virustotal.

    Leave a brief description of how things are running for you now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds