Malware Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vedder45, Jul 11, 2009.

  1. vedder45

    vedder45 Private E-2

    Hello-

    Earlier this evening I visited an acquaintance's business website. Within seconds of arriving at the site, my Zone Alarm firewall began indicating that files were attempting access and I had numerous other security alerts pop up. My CPU fan started to fire up (which scares me because of a previous infection) and I shut down my computer immediately.

    Upon restarting, I ran Malwarebytes. I got this list of infections:

    braviax.exe
    Trojan - figaro.sys
    Backdoor.Bot - sysldtray
    Backdoor.Bot - ld12.exe
    Fake.Beep.sys - beep.sys
    Fake.Beep.sys - beep.sys
    Trojan.FakeAlert - braviax.exe
    Worm.KoobFace - ld12.exe
    Disabled Security Center

    My AVG also informed me of a threat detected: bravia.exe

    I told Malwarebytes to remove all the found/selected files and AVG to move the file to the Virus Vault.

    Because I was concerned about files still hidden and regenerating upon restart, I decided to come to Major Geeks. I've gone through the Read & Run Me First steps and have attached the first 4 logs to this post (5th log to immediately follow). Although I didn't see any problems found in the scans and my CPU fan has since calmed, I want to run the logs by the expert team for peace of mind as I've relied upon Quarantines and the Virus Vault with (what I hope were) minor attacks over the past year or more. Would love to get an 'all clear' before proceeding.

    Can I provide any additional information?

    Thank you very much for the help!
     

    Attached Files:

  2. vedder45

    vedder45 Private E-2

    5th log attached.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean, but we can remove some junk.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. vedder45

    vedder45 Private E-2

    TimW -

    Thank you VERY much for your assistance! Here's an update:

    I removed the 4 lines listed above as directed. Would you mind elaborating on what 'some junk' means?

    Complete. I did receive a success message.

    HijackThis was not found in my Add/Remove Programs list, but I was able to complete all other tasks on the checklist.

    Thanks again! I really appreciate the help!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    "Some junk" just refers to items that are either no longer existing or just leftover from uninstalled programs, etc.

    Our final clean up instructions are to cover numerous item....some do not apply to all situations.

    And you are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds