major trojan/adware/virus dating back 2 years

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sbelgard, Oct 30, 2008.

  1. sbelgard

    sbelgard Private E-2

    Hey guys,

    I am trying to clean up a friends machine that has been infected for 2 years. It was so bad she hasn't turned the computer on in over a year. I have ran the run and read me steps. Am attaching the logs.

    Sonya
     

    Attached Files:

  2. sbelgard

    sbelgard Private E-2

    I cannot find the MBAM log file. Should I rerun the program?
     
  3. sbelgard

    sbelgard Private E-2

    ok found MBAM log. Here it is
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see the scans removed quite a lot of malware....so lets do this:

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Download and install:
    Java Runtime

    Please tell me what this is:
    C:\stdtsa

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  5. sbelgard

    sbelgard Private E-2

    c: stdtsa is a remnant of sophos antivirus. I removed this.
     

    Attached Files:

  6. sbelgard

    sbelgard Private E-2

    I did not remove the c:\stdtsa file. I removed the program
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....your logs are clean.

    If you aren't having any other malware issues, then:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds