This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Bad Infection

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I tried to get rid of the infections, but I don't know if it's all gone. I booted into safemode and ran: Norton Internet Security 2009 Ad-Aware Spybot S&D CCleaner Here's some info: Under System Configuration (msconfig), I noticed these strange Startup Items: Startup Item: PowerReg Manufacturer: Leader Technologies Command: rundll32.exe "C:\Users\Dan\AppData\Local\alerf32.dll",Startup Location: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Startup Item: uishf9wuifwuh387fh3wufinhjfdwefe Command: C:\Users\Dan\AppData\Local\Temp\jxegb4cps.exe Location: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Startup Item: asg984jgkfmgasiBug98jgkfgfb Command: C:\Users\Dan\AppData\Local\Temp\win32.exe Location: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Then in Registry Editor I found these also: Same section–> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 1) Value name: Dbixidarexow Value data: rundll32.exe "C:\Users\Dan\AppData\Local\alerf32.dll",Startup 2) Value name: asg984jgkfmgasiBug98jgkfgfb Value data: C:\Users\Dan\AppData\Local\Temp\win32.exe 3) Value name: uishf9wuifwuh387fh3wufinhjfdwefe Value data: C:\Users\Dan\AppData\Local\Temp\jxegb4cps.exe Ad-Aware found these 2 infections: FamilyName–> Trojan.Win32.Sasfis.a (v) Full Path–> C:\Windows\SysWOW64\xlyf.ppo FamilyName–> VirTool.Win32.Obfuscator.hg!a (v) Full Path–> C:\Windows\SysWow64\by7es.dll Malwarebytes' Anti-Malware 1.44 found these: Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dbixidarexow (Trojan.Hiloti) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xlomemuguxavig (Trojan.Agent.U) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe rundll32.exe xlyf.ppo ebneby) Good: (Explorer.exe) -> Quarantined and deleted successfully. Files Infected: C:\Users\Dan\AppData\Local\alerf32.dll (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Users\Dan\AppData\Local\elacafojufanero.dll (Trojan.Agent.U) -> Quarantined and deleted successfully. C:\Windows\System32\mshlps.dll (Backdoor.Bot) -> Quarantined and deleted successfully. So am I safe now, how can I make sure it's all gone?
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


I suggest you do this:

XP users:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Combofix won't open, I get an error message.

Error - Win32 only
Incompatible OS. Combofix only works for workstations with Windows 2000 and XP.


Since my computer uses Win7 (64-bit) OS, I tried to run "combofix.exe" thru Compatability Mode (as Win XP) & Run As Administrator – But nothing is working, I keep getting the same error message.
That will limit the tools we can use.

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
Kaspersky log
Man, you're lucky my computer wasn't destroyed because of your ignorance.

I decided to do some research online, to try and figure out why ComboFix wouldn't work for me. I IMMEDIATELY found out that ComboFix destroyes computers that use Win7 64-bit OS. And, there I was following your "expert" advice, on trying to run ComboFix on my PC. Thank god I wasn't able to open ComboFix - otherwise my computer would be dead right now.

How can you portray yourself as a computer expert, and offer expert advice - when you don't even know about a MAJOR FLAW with running ComboFix on computers with Win7 64-bit OS.

There's no way I can follow you're advice from this point, cause you apparently have never used a PC with Win7 64-bit OS before.

I'd like a different technician to help me.
I thought I had posted what my OS was, I guess I left that out. You're absolutely correct about my mistake. I'm a man who has no problem admitting when I'm wrong. I apologize for accusing you of ignorance, I was completely off base. I would completely understand if you no longer wish to help me.

That will limit the tools we can use.

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:

  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
Kaspersky log

That's why I posted the above after I saw what OS you were using.
Do the above and lets see if anything bad is found :thumbup:
Here's my Kaspersky log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, February 20, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, February 20, 2010 08:32:33 Records in database: 3593408 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 104809 Threats found: 3 Infected objects found: 1 Suspicious objects found: 4 Scan duration: 01:02:18 File name / Threat / Threats count C:\Users\Dan\AppData\Local\Microsoft\Windows Live Mail\Hotmail (dp ac0\Inbox\2370288C- 000002C1.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Dan\AppData\Local\Microsoft\Windows Live Mail\Hotmail (dp ac0\Inbox\48473C0A- 000002C4.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Dan\AppData\Local\Microsoft\Windows Live Mail\Hotmail (dp ac0\Sent items\2A50689D- 0000008F.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Dan\AppData\Local\Microsoft\Windows Live Mail\Hotmail (dp ac0\Sent items\504315B3- 0000008E.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Users\Dan\Desktop\Accessories & Downloads\mirc616.exe Infected: not-a- virus:Client-IRC.Win32.mIRC.616 1 Selected area has been scanned.
Looks like you have / had some infected mail. I can't tell you which email it is so you'll need to find that out on your own. How's it running now?
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI