also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

[Solved] Rootkit, Rogue Malware, Firefox/Flash Spoof

Discussion in 'Virus and Malware Removal' started by brentjonas, Oct 28, 2010.

Thread Status:
Not open for further replies.
  1. Bobbye Helper on the Fringe

    Okay- looks good. Just 2 persistent entries. Run the script below- you don't need to leave the log:

    Custom CFScript

    • [1]. Close any open browsers.
      [2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      [3]. Open notepad and copy/paste the text in the code below into it:
    Code:
    KillAll::
    Registry::
    [HKLM\~\startupfolder\C:^Documents and Settings^Brent^Start Menu^Programs^Startup^Winter Fun Wallpaper Changer.lnk]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "LDM"=-
    
    Save this as CFScript.txt, in the same location as ComboFix.exe
    [IMG]

    Referring to the picture above, drag CFScript into ComboFix.exe

    When finished, it will produce a log for you at C:\ComboFix.txt . Please paste into to your next reply.
    ====================
    Boot into Safe Mode
    • Restart your computer and start pressing the F8 key on your keyboard.
    • Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.
    To remove entries from Startup using the msconfig utility:
    • Click on Start> Run> type in msconfig> enter>
    • Click on Selective Startup
    • Choose the Startup tab:
      This is where you UNCHECK the Startup items. This does not remove the item or uninstall anything> it just stops it from starting on boot. It can be rechecked at any time if wanted.
    • To expand the Command Column, (this shows what the process 'belongs' to) hold left mouse button down on the dividing line on frame above Location and move to the right to expand.
    • Uncheck any process related to the Logitech Desktop Manager (LDM)> if you do not do this, entries like the 018 processes will continue to add up and slow you down> Uncheck any processes related to the Winter Fun Wallpaper Changer
      [*] Click on Apply> OK when finished.


    NOTE:
    When you reboot the system the first time after making changes using the msconfig utility, a nag message comes up that can be ignored and closed after checking 'don't show this message again.'
    Once you make changes to the Startup menu, you must remain in Selective Startup to retain those changed. If you go back to Normal Startup, everything you unchecked will be checked again and start on boot.

    Check Add/Remove Programs for either of the above entries> if showing, uninstall both.
    Use Windows Explorer to remove the program folders: Windows + E> My Computer> Double click on Local Drive (Usually C)> Programs> Navigate to the program folder for SetPoint and double click to open> do a right click> Delete on the LDM on the right screen> then do a right click> Delete on the Wallpaper Changer folder> Apply> OK> Exit Windows Explorer.
    =========================================
    Removing all of the tools we used and the files and folders they created
    • Uninstall ComboFix and all Backups of the files it deleted
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    • Download OTCleanIt by OldTimer and save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.

    Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.
    • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
    • Go to Start > All Programs > Accessories > System Tools
    • Click "System Restore".
    • Choose "Create a Restore Point" on the first screen then click "Next".
    • Give the Restore Point a name> click "Create".
    • Go back and follow the path to > System Tools.
      [*]Choose Disc Cleanup
      [*]Click "OK" to select the partition or drive you want.
      [*]Click the "More Options" Tab.
      [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


    Empty the Recycle Bin

    I don't think the Sound problem is related. Please open the Volume Controls in the Notification Area and check the settings. Also look in the Device Manager for any error on the sound card driver.

    Let me know if you have any more questions.
  2. brentjonas Newcomer, in training

    Bobbye,

    Thanks for your help. As more and more problems crept up, I opted for a clean install. I did it over the weekend and everything is running normally now.

    Thanks, and this can close now.
  3. Bobbye Helper on the Fringe

    Thanks for the update.
Thread Status:
Not open for further replies.