Quick question about malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bobby62586, Jul 7, 2008.

  1. Bobby62586

    Bobby62586 Private E-2

    Ok i had malware- i posted in the intro and was directed to the read&run me first section. Ive followed everything perfectly and it seems every thing is doing fine. HOWEVER. i have a few questions.

    1. Most of those programs are on my desktop- can i just put these in a fold now, with the exception of MGTools, and just store them away in another part of my computer

    2. Not sure when these two showed up, but on my desktop i have the following
    -Thumbs.db
    -CAZZ5591.
    they are dark, and the CAZZ wont be deleted, and with Thumbs.db- when trying to delete i get a "Thumbs.db is a system file. If you remove it, your computer or one of your programs may no longer work correctly. are you sure you want to move it to the recycle bin? And if i try to move it to a folder. "are you sure you want to move the system file 'Thumbs.db'?

    I don't wanna disturb anything ive done so far- the computers running great
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on the malware you said you had, I suggest that you attach the 4 logs requested in the READ & RUN ME before doing anything else. You may still have leftovers and it is worth the time to check. We will address your questions later when we finish up.
     
  3. Bobby62586

    Bobby62586 Private E-2

    here are the first 3
     

    Attached Files:

  4. Bobby62586

    Bobby62586 Private E-2

    and the last i believe
     

    Attached Files:

  5. Bobby62586

    Bobby62586 Private E-2

    anyone?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should read the sticky threads. In particular: Don't Bump! It Only Hurts You!!!

    You need to attach the log from MGtools that was requested. We did not ask you to post anything from the C:\MGtools folder. You need to attach the C:\MGlogs.zip file as requested in the instructions.
     
  7. Bobby62586

    Bobby62586 Private E-2

    sorry
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of Java:
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 8, 2008
  9. Bobby62586

    Bobby62586 Private E-2

    Followed

    First of the fixme.reg was a success
    here are the files you requested. and i have a few questions.

    I have the following icons on my desktop- and are "greyed"
    Thumbs.db and CAZZ5591.

    wont let me delete, or move. what should i do about those?

    so far seems to be fine.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thumbs.db is a valid/normal system file. For the other, do the below. Yes the file name should be how I entered it in the below fix. Do not change it.



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the same fixME.reg patch that you ran last time.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds