1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved aswMBR keeps crashing midway?

Discussion in 'Malware and Virus Removal Archive' started by virtue1boy, 2012/04/30.

  1. 2012/05/02
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    You don't see norton because I uninstalled it before I ran Combofix. I followed the intructions to disable norton it but combofix kept saying it was running. Log will be posted soon.
     
  2. 2012/05/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Reinstall Norton as soon as possible.
     

  3. to hide this advert.

  4. 2012/05/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
  5. 2012/05/06
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    Yes i'm working on everything. Get back to you soon.
     
  6. 2012/05/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Ok.........
     
  7. 2012/05/06
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    Results of screen317's Security Check version 0.99.24
    Windows Vista Service Pack 2 x86 (UAC is enabled)
    Internet Explorer 7 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Norton Internet Security
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Java(TM) 6 Update 32
    Adobe Flash Player 11.2.202.235
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Malwarebytes' Anti-Malware mbamservice.exe
    ``````````End of Log````````````





    Farbar Service Scanner Version: 30-04-2012 01
    Ran by Kerry (administrator) on 06-05-2012 at 19:21:17
    Running from "C:\Users\Kerry\Desktop "
    Microsoft® Windows Vista™ Ultimate Service Pack 2 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Yahoo IP is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall "=DWORD:0
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall "=DWORD:0


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================




    C:\ProgramData\Microsoft\Windows\DRM\B1F0.tmp Win32/Olmarik.AYD trojan cleaned by deleting - quarantined
    C:\Users\Kerry\Downloads\WinRAR.exe multiple threats deleted - quarantined
     
  8. 2012/05/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I still need a log from OTL fix.
     
  9. 2012/05/07
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
    C:\Windows\Downloaded Program Files\DivXPlugin.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\Windows\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Kerry
    ->Temp folder emptied: 19260290 bytes
    ->Temporary Internet Files folder emptied: 3794514 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 456 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 946495 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 23.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Kerry
    ->Java cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Kerry
    ->Flash cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.42.3 log created on 05072012_152757

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
  10. 2012/05/07
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    Broni,

    I have a new slew of folders in my Local Disk (C:) including:

    Program Data (shouldn't this folder be hidden?)
    Perflogs
    MSO Cache (shouldn't this folder be hidden?)
    Boot
    Qoobox
    ComboFix (text doc)
    JavaRa (text doc)

    Which ones do I hide? and which ones can I delete???
     
    Last edited: 2012/05/07
  11. 2012/05/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Open Windows Explorer, go Tools>Folder options>View tab, checkmark:
    - Do not show hidden files and folders
    - Hide protected operating system files

    As for other see what will be left after following last steps....
     
  12. 2012/05/07
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    Well I tried that already and they are still visible. Let me change the system file folders....MSO Cache and Program Data to "hidden ", Perflogs is ok. The others appear to be remnants of the exe stuff we've been running and will be deleted after cleaning is complete.
     
  13. 2012/05/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
  14. 2012/05/12
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    Yea...whats next? I'm ready to finish this project?
     
  15. 2012/05/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     
  16. 2012/05/13
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    umm

    Norton refuses to let me download OTL. It deletes it automatically. Any other suggestions?????
     
  17. 2012/05/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Disable Norton until you're done with OTL.
     
  18. 2012/05/14
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    Disabling doesn't work that why I had to uninstall it. Any other suggestions???
     
  19. 2012/05/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download OTL from safe mode with networking.
     
  20. 2012/05/15
    virtue1boy

    virtue1boy Inactive Thread Starter

    Joined:
    2008/08/14
    Messages:
    104
    Likes Received:
    0
    I downloaded it to a usb on another computer. Here you go...


    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Kerry
    ->Temp folder emptied: 250131 bytes
    ->Temporary Internet Files folder emptied: 250575261 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 3796 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 25876867 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 264.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Kerry
    ->Flash cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Kerry
    ->Java cache emptied: 0 bytes

    User: Public

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.43.0 log created on 05152012_093559

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
  21. 2012/05/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good.
    Go on....
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.