Other > Viruses and worms

Help with removing Outerinfo

<< < (2/8) > >>

oldman:
Lot's of things here. You are using service pack 1. Do not attempt to install sevice pack 2 untill the machine is clean.

We'll start with this

* Download and run this removal tool for 180 Search

http://securityresponse.symantec.com/avcenter/Fix180Sh.exe


Please download ComboFix from Here or Here to your Desktop.

Do Not Run It Yet, we will run it a little differently.


**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**


* Go to add remove programs and uninstall the following if present

Rabio
180Search assistant
Yazzle
QdrDrive
QdrModule



* Open HJT, run a system scan only, check mark these lines if present

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {3712b7f2-1dd2-11b2-a814-d414ee082346} - C:\WINDOWS\nkvchwjs.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BndBlock5 BHO Class - {82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B} - C:\Program Files\QdrDrive\QdrDrive10.dll (file missing)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O4 - HKLM\..\Run: [pgdqjady] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pgdqjady.dll"
 

Close all other browsers/windows, click fix, close HJT.

** Now for combofix

[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
[*]Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.[/color]
-----------------------------------------------------------[/list]
[*]Close any open browsers.
[*]WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
[*]Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
[*]If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
[/list]


Open a new Notepad session (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.

Copy and paste all the text in the quote box below into Notepad.

Click File, Save as..., and set the location to your Desktop, and enter (including quotation marks) as the filename: "CFscript.txt" . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.



--- Quote ---File::
C:\WINDOWS\system32\sbwltbxa.exe
C:\WINDOWS\nkvchwjs.dll
C:\WINDOWS\bolgxafm.exe
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\QdrDrive\QdrDrive10.dll
C:\Program Files\QdrModule\QdrModule12.exe

Folder::
C:\Documents and Settings\All Users\Application Data\Rabio
C:\Program Files\QdrDrive
C:\Program Files\QdrModule
--- End quote ---


This will start ComboFix .Close  all browser/windows first. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJT log.


Attaching the logs is fine. DSS should have install hijackthis for you.

Thanks

Viper666:
Okay, I've hit a major snag. I'm currently on my desktop instead. I did everything as directed so far. I made the CFscript.txt and dragged it onto the ComboFix icon, turned off my antivirus and all that other good stuff. Then ComboFix started to run, but it's stopped. It says (somewhat paraphrased here):

Scanning for infected files...
Scan time should take no more than 10 minutes
However, for badly infected systems it could easily double

ComboFix has changed your clock settings
Do not change it back, it will be restored later

Delete Files/Folders:
*blinking cursor*


It's stayed like this for some time now. And my desktop is gone; the taskbar, all of the icons. The wallpaper has restored itself though, and the nasty green screen from the malware is gone. Should I wait it out or are there other courses of action that I should take?

oldman:
If there is any type of hard drive activity, blinking light, sound from the hard drive, combofix is still running, Do not stop it  Give it about 40-50 minutes. if CF has stalled completely, reboot, all desktop items will come back.

Viper666:
It's definitely been an hour now, and it doesn't sound like anything is going on. No fan running, no crackles of it doing any work. I guess I'll reboot then. What should I do after that?

ETA: I tried running ComboFix again with the CFscript.txt and it still isn't doing anything. No blinking lights, nothing. Is there anything else I need to turn off or anything else I should do before running it?

oldman:
No don't re-run CF. Run DSS and post that log. There will only be a main log this time.

Thanks

Navigation

[0] Message Index

[#] Next page

[*] Previous page

Go to full version