bankerfox.a removed and botnet question

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by subgeeky, Feb 19, 2010.

  1. subgeeky

    subgeeky Private E-2

    Believed was infected by bankerfox.a, went straight to siri.urz.free.fr to get the smithfraudfix.exe to try to get a quick fix, that didn't work.

    Ended up going through the entire Read Me in safe mode. Attached are the logs, except from combofix. Reran Malwarabyte in normal mode.

    Just want to be sure the computer is clean of malware.

    Read the yahoo article on botnet
    http://news.yahoo.com/s/ap/20100218/ap_on_hi_te/us_tec_computers_attacked

    Does the Read Me First remove the botnets and ZeuS?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you not get a pop up when you ran MGTools to accept the license to run HJT? It is not in your logs.

    You also did not attach the C:\ComboFix.txt log.

    Why am I not seeing any Anti-virus program on this system?

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator) and make sure you agree to run HJT.

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  3. subgeeky

    subgeeky Private E-2

    Couldn't attach combofix log because of the 4 attachment limit.

    Because of the oversized everything while in safe mode, I couldn't see the end of the box, so I hit tab and space, appears that decline the agreement for hijack this.

    Anyways, have rerun MGtools in normal mode.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\TEMP.dat
    C:\US.dat
    C:\PC.dat
    C:\EU.dat
    C:\AM.dat

    copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds