Author Topic: HTML:iframe-inf infection  (Read 6753 times)

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #15 on: August 23, 2012, 04:28:39 PM »
Ooops missed the bit about you having the CD

To install the Recovery Console, follow these steps:

1.Insert the Windows XP CD into the CD drive.
2.Click Start, and then click Run.
3.In the Open box, type d:\i386\winnt32.exe /cmdcons where d is the drive letter for the CD drive.
4.A Windows Setup Dialog Box appears. The Windows Setup Dialog Box describes the Recovery Console option. To confirm the installation, click Yes.






Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #16 on: August 23, 2012, 04:51:56 PM »
Yes drop the MS programme on to combofix, it should recognise it.. I will check my links thanks

I tried to run it 3 times.  I dragged the windows cd to ComboFix on my desktop and closed Avast and COMODO firewall.  Each time I got the Message:

{Command prompt window}
C:\
Combo Fix is preparing to run.

(the program loads after two windows opened up)
Then I get a message window:

CFScript Error
i Were you trying to run CFScript?
  The name CFScript appears to incorrectly spelt.

I'm going to sleep.  I have to work tonight.

Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #17 on: August 23, 2012, 05:15:22 PM »
Yes drop the MS programme on to combofix, it should recognise it.. I will check my links thanks

I got more error messages(two jpg file attachments)when trying to run the Windows CD with the command:
d:\i386\winnt32.exe /cmdcons

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #18 on: August 23, 2012, 05:17:31 PM »
On the second image where it asks to install the recovery console click yes




Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #19 on: August 24, 2012, 01:37:07 AM »
I executed the command "d:\i386\winnt32.exe /cmdcons"  and said yes to the second message.  then I got another message windows was going to contact MS I guess to verify or update the Recovery console.  Then I got a message(attachment) to on the recovery console.  I rebooted and Bios CMOS and the Recovery Console still has the "Yukon PXE" still listed.   
Getting ready for work now.  I check for messages before I leave in about an hour.

Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #20 on: August 24, 2012, 02:57:55 AM »
On the second image where it asks to install the recovery console click yes

essexboy:

My system went into standby mode and I could not reboot into windows and put me into setup recovery.  I rebooted and found the CMOS Bios was changed.  The Primary Master [WDC WD3200JB-00KFA0] and Primary Slave [WDC WD1600JB-00GVA0] were disabled. the second boot device was changed from WD1600JB to WD3200JB, and system clock was set to 2001.
I re-initiated:
Security Settings
      Supervisor Password :       Installed
      User Password          :            Not Installed
      User Access Level                [No Access]
      Password Check                      [Always]
      Boot Sector Virus Protection [Enabled] 
   
I going to make a lunch and go to work.

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #21 on: August 24, 2012, 12:20:09 PM »
Could you check out the CMOS battery as those are classic symptoms of it failing



Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #22 on: August 24, 2012, 01:33:28 PM »
I would check the CMOS battery if it wasn't that this only happens when the System Bios is disrupted when I lower the Boot Sector Virus Protection, Supervisor Password, and the User Access Level.  If it keeps happening after the Recovery console, CMOS, and the USB Drive is cleaned I will.  For now, what is the next step?  I think I need a command to check the Recovery console and Setup files on the hard drive?  But your in charge you tell me.  When I installed the recovery console I am not sure if it was updated or not from MS.  Is ComboFix going to find the recovery console or do I drag the XP on to ComboFix?  I've been looking for answers online to check the status of the Setup Files and Recovery Console with only 2 results dead end.
« Last Edit: August 24, 2012, 03:03:05 PM by CAS159 »

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #23 on: August 24, 2012, 02:41:08 PM »
The quickest check would be to re-run Combofix as it uses the recovery console files

Also to to check the system files I would need first to know if you have an XP cd



Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #24 on: August 24, 2012, 03:09:46 PM »
The quickest check would be to re-run Combofix as it uses the recovery console files

Also to to check the system files I would need first to know if you have an XP cd

Yes I do have the XP CD but it is outdated.  When I ran d:\i386\winnt32.exe /cmdcons I got that message to update.
Alright I'm going to shut down, lower the security setting for Bios and run the ComboFix .

Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #25 on: August 24, 2012, 05:24:51 PM »
The quickest check would be to re-run Combofix as it uses the recovery console files

Also to to check the system files I would need first to know if you have an XP cd

I ran ComboFix.  It took an hour to run.  I checked Bios and the "Yukon PXE" is gone.  I attached the log file.  However, the Recovery Console has changed and since the update I suppose and I didn't see:

Please Select Boot Device
  Floopy Drive
  PM-WDC WD3200JB-00KFA0
  PS-WDC WD1600JB-00GVA0
  SM_NEC DVD_RW ND-3500A
  Yukon PXE

Are there any other checks you need before checking my external USB TByte drive?  You mentioned "Also to to check the system files I would need first to know if you have an XP cd".  I do have a 2002 XP cd.  Is there a command to isolate the USB from the rest of the system while scanning it? 

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #26 on: August 24, 2012, 05:39:55 PM »
Recovery console installed properly

To isolate the USB just disconnect it

Go start > run and type in the following command :

sfc /scannow

This will check your files



Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #27 on: August 24, 2012, 06:21:41 PM »
The USB has been turned off since this bug started.  However, I do remember I did a Boot time scan with Avast that night and when I came back in the morning the USB green light was turned on, my internal drives were disabled, and I had to go into Bios to enable them to reboot.

Offline CAS159

  • Jr. Member
  • **
  • Posts: 29
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #28 on: August 25, 2012, 03:28:38 AM »
Recovery console installed properly

To isolate the USB just disconnect it

Go start > run and type in the following command :

sfc /scannow

This will check your files

I executed sfc /scannow but I'm unable to find a report.

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22262
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: HTML:iframe-inf infection
« Reply #29 on: August 25, 2012, 11:03:15 AM »
There will be no report for SFC unless it finds errors, then I will need to generate a report

Are you still experiencing the BIOS changes ?