F-Secure found 6 infected files and could not clean them

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thai_american_42, Mar 15, 2010.

  1. thai_american_42

    thai_american_42 Corporal

    F-Secure found 6 infected files and could not clean them.

    I went through READ & RUN ME FIRST. Malware Removal Guide and the logs are attached.

    1. SAS was clean and didn't produce a log (that I know of).
    2. Running RootRepeal froze my computer (I terminated RootRepeal after 36 hours) and there is no log.
    3. MGtools ran into a processDll.exe runtime error, process id=0xc54 (3156), thread id=0xc58 (3160). The program got stuck on "Running processdll.exe to find loaded DLLs"
     

    Attached Files:

  2. thai_american_42

    thai_american_42 Corporal

    Here is the SAS log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell exactly what F-secure found, the full path to the files.

    Do you have a C:\MGlogs.zip?

    If not, please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  4. thai_american_42

    thai_american_42 Corporal

    I have C:\MGlogs.zip and previously used it to run MGlogs. This time, I click Start, Run, and enter cmd, cd \MGtools, then GetRunKey. That produced the attached file "runkeyslogMar17,2010".

    For the past five munites, the cmd.exe prompt has been running GetRunKeys.Bat Version 2.49 and has been reading "updating:runkeys.txt (188 bytes security) (deflated 82%)" The cursor is blinking under the "u" in "updating". Nothing else seems to be happening.

    I can't find any way to enter "ShowNew" in the open cmd.exe window.

    I'm working on getting the full path to the files to tell you exactly what F-secure found.


     

    Attached Files:

  5. thai_american_42

    thai_american_42 Corporal

    OK, I jumped the gun. I received the cmd.exe message "All finished getting Run Keys." I attached the final runkeys log to this message. I'll now try to run ShowNew.


     

    Attached Files:

  6. thai_american_42

    thai_american_42 Corporal

    I entered the ShowNew command to try to run another scan from MGtools. No error messages came up, but after eight hours of running ShowNew, the program was stuck at "updating: winfiles.txt (188 bytes security)(deflated 84%). It also was stuck on updating ffdata.txt (deflated 73%, and newfiles.txt (deflated 80%). I attached a screen shot of MGtools showing what it did and where it got stuck.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, are you disabling all your AV and AS programs before you run the GetLogs.bat or ShowNew.bat?

    Try going to C:\MGTools\SN64.bat and double click it. Attach that log.

    Have you re-run the F-secure scan to find the path to the files?
     
  8. thai_american_42

    thai_american_42 Corporal

    Attached Files:

  9. thai_american_42

    thai_american_42 Corporal

    Also, here is the fsecure report (attached)
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The image you attached is showing FP reports of malware in your printer files. They are not infected.
     
  11. thai_american_42

    thai_american_42 Corporal

    On looking closer, the w32/Malware/Gemini "virus" report likely was generated as seeing a toner low message, paper jam message, or paper out message sent from my printer to my hard drive as "performing suspicious or potentially undesirable actions on the system." See http://www.f-secure.com/v-descs/suspicious_w32_malware!gemini.shtml Obviously, such messags are not suspicious or undesirable actions. Thanks for all your help, Tim.

     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds