Malware, Trojan Infestation

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HumbleServant1611, Mar 13, 2012.

  1. Alright this isn't urgent serious news as im using the computer that has been or was infested not sure yet that is why im posting these logs for a more expert opinion.

    my friend gave me his Acer aspire One notebook to look at it said there were some serious issues with it so i gave it a shot.

    Before i ran the READ & RUN procedure i run a AVG scan and it picked up 9 infections.... so i quarantined and cleaned or deleted them and then i ran Mbam but it was Mbam.exe instead of renaming it to Mb.exe, granted i hadn't read the READ & RUN just was doing some regular virus scans, it picked up 10 infections ran the cleaner on that deleted but since i found this many i wanted to be sure so i ran the READ & RUN procedure, also great tools for malware i've used these steps and programs for many computers its great but i still don't know how to read them :/ but thats why you guys have such a great forum. Anyways i'd appreciate if someone could look over these logs to check for formalites?

    Greg

    View attachment mbam-log-2012-03-10 (13-15-49).txt

    View attachment combofix.txt

    View attachment SUPERAntiSpyware Scan Log - 03-12-2012 - 18-03-37.log

    View attachment MGlogs.zip
     
    Last edited: Mar 13, 2012
  2. Here Is The RootRepael logs i couldn't get it to run so i just continued on with the rest of it i didn't try safe mode if need be i will

    Greg

    View attachment RRlog.txt
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Command switches used :: c:\users\antwinaya\Desktop\CFScript.txt.txt <--- Who instructed you to run this script?

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    You need to re-run TDSSKiller and have it fix these this time round.
    Attach the new log.


    Delete these folders.

    c:\program files\Conduit
    c:\users\antwinaya\AppData\Local\Conduit

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds