Re: I need to remove malware from my laptop, hardrive and usb

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by flawliz, Aug 16, 2010.

  1. flawliz

    flawliz Private E-2

    Hi again, long time. :)

    I feel that i might have malware on my laptop, external hardrive and memory stick. I do not even know where to begin! I completed the 'read and run me first' section and could not get the logs for combofix and rootrepeal.

    My laptop is a IBM T60 Thinkpad, and has Windows 7.
    The external hardrive is an iomega prestige, and holds 1TB
    The memory stick holds 1GB

    I have attached all other logs for you to have a look at.
    Please help. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you let SAS and MBAM do "complete scans" whereby you can choose which drives to scan? I see you ran a full scan with SAS but did you let it scan all drives?

    But answer me this - what leads you to suspect malwares presence?? I am not seeing anything in the logs that you have provided, however I still need to see the log from combofix. Perhaps it addressed something or shows something suspicious.

    You only did a quick scan with MBAM.

    I recommend you using this:

    For the external Hard Drive and a USB stick.

    Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

    Now the log from combofix is sitting right here:

    C:\ComboFix.txt, please attach it.
     
  3. flawliz

    flawliz Private E-2

    Hi,

    Do you want me to redo the SAS and MBAM scans?

    I downloaded the flash drive cleaner but it would not run. Help!

    Thanks.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes! Re-run both MBAM and SAS, complete FULL scans, and choose the external, and the flashdrive to be included. Attach the logs when done.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    also do not forget to address my question. :)

     
  6. flawliz

    flawliz Private E-2

    Ok. I have attached the logs for SAS, MBAM and COMBOFIX.
    There are two logs for SAS because log(1) was done without the external hardrive and usb, and log(2) was done with them attached.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, now do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    And tell me how things are running now please.
     
  8. flawliz

    flawliz Private E-2

    i have attached the mglogszip. Thanks.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not tell me how things are running now ;)

    But your logs are looking good to me.
     
  10. flawliz

    flawliz Private E-2

    Everything is running fine. THANK YOU SOOO MUCH...again.

    I guess i need to follow the procedure of prevention of malware now?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! And you can indeed follow final steps at this point, yes.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds