Most prep done, little help and we're done

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by oooeemrlee, Oct 12, 2008.

  1. oooeemrlee

    oooeemrlee Private E-2

    Props to ChasLang, The man's got skills ! :dancer
    You've inspired me to post here and ask for help:

    I've completed most of the steps requested to clean my Dell laptop.
    My first post here, thank you for a great site. I'll do my best to follow directions and protocol!

    Dell Inspiron 710M, full of Virtumonde, Smitfraude, some Trojans, not good. Hitting the disk constantly, always looking for a net connection, etc. Pop up operating system windows messages asking if I want to work off line when not connected to the net, starting iexplorer as a task without showing a desktop program (took me a while to see that one!) Most FRUSTATINGLY, it blocked many many helpful sites in both my brosers'; IE and FF such as Major Geeks, Broadband Reports, Symantec and some of the sites of the tools you have suggested here. I could not update scan files in all cases. I think you know the drill. If I didn't have a second machine to use, I would have never been able to do this. I kept emailing myself the proper files. Pathetic.

    Not sure, but I believe I opened a strangely embedded attachment from Yahoo mail. The attachment was embedded as a MS Outlook doc that was named 1[1].pdf, an acrobat file. Sharing this file with my friend's machine broke her machine and it is at Sony support getting reloaded; they couldn't fix it! Yahoo Mail AV (McAfee I think) flagged this file once, but not subsequent files from the same user. They could have all been infected and would be .pdf files starting form two weeks ago.

    I've followed your directions best as possible with a few exceptions:

    1. I was ad hoc trying to clean this machine without much success prior to discovering your excellent board with SBS&D, Symantec Anitvirus coporate edition, CClean, Avira Antivir before reading your instructions, so some items may not be to the book ie Teatimer was on for a time etc. and not in exactly the right order. Also, I don't have the Admin password to this machine, so I was unable to remove Symantec Anti Virus corporate edition...suggestions welcome as it's acting flaky and I would like to remove it. Scared AV wasn't working properly, I'm also running Antvir from Avira (2 Antivirus packages; a MG's no no!) Note also that I couldn't get to some of suggested tool's sites for most recent updates.

    Timing-wise, I think I got this file about two weeks ago.

    2. No Admin password precluded me from running one of the last steps using the repair console i.e. Combofix. Hopefully we can get round this. I DO HAVE the Dell Drivers and Utilities and OS disks for XP Pro SP2.

    3. This is a former corporate machine that could have mulitple log ins and partitions that I don't have access to. Admin info is long gone, the company firing the support staff when business was tough. I would like to clean this up too. Just send me to the proper forum once we get this puppy cleaned up.

    4. I have not reloaded the JRE yet, I had many many versions on this machine, jeez. I've noticed the same is true with the .net framework, I suppose only the latest should be loaded with .net as well, correct?

    5. I have toggled system restore and run cclean several times. One question here, should I be running both the std temp file as well as registry cleaning routines? I have been doing both and deleting everything suggested, sometimes creating a back up log of the registry but not always.

    I'll attach the logs I have so far in follow up posts. Should be everything except Combofix data. Before I do that, some of the data in these logs could be sensitive, how do I ensure only you and the MG's staff are looking at them and not the General Public?

    Thank you very much in advance:wave
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the logs......I doubt there is anything that would compromise you in any way...we have done this thousands of times and no one has ever had an issue with their logs. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds