trojan fake-alert came back

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by IceMaiden, Feb 16, 2010.

  1. IceMaiden

    IceMaiden Private E-2

    Hi, This is a different computer, not the one I asked for help for 2 weeks ago. I have run all the scans as instructed for both user partitions. I am uploading the scans from the first user. The reason I am asking for help is that I did all of this three weeks ago and thought it was gone. Decided to run the scans again and Malware bytes found it back on. I have uninstalled my Avira virus ware and am going to go with AVG when this is clean. Thought you should look at my scans to see what I missed doing last time. Thank you for your help.
     

    Attached Files:

  2. IceMaiden

    IceMaiden Private E-2

    MGTools Log is attached. Thank you.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi & welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing much to do here:

    1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    2. Please use windows explorer to locate and delete the below remnants from avira and avg:

    Also find the below bold folder and delete it.

    3. Now I would like for you to rescan with Malware Bytes after first updating if it needs to. Fix all it finds if anything, and attach the log here into your next reply.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also attach the MBAM log.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. IceMaiden

    IceMaiden Private E-2

    I did all that you said without a problem. Then I downloaded and ran a scan with PC Tools and it found Application.Nir.Cmd and said it was a threat. I removed it with PC
    Tools. Do I need to do more than that? Things seem to be running fine and faster. Thanks so much for all of your help. Icemaiden :)
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\jilly\My Documents\wfpymt

    If you do not know what the above bold file is then please use windows explorer to find and delete it.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\Documents and Settings\HD\Local Settings\temp

    nircmd is a valid tool from NirSoft ( see http://www.nirsoft.net/utils/nircmd.html ) It was put on your PC by ComboFix.
    C:\TEMP



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited by a moderator: Feb 21, 2010
  7. IceMaiden

    IceMaiden Private E-2

    I am sorry but I cannot find the file: C:\Documents and Settings\HD\Local
    Settings\temp

    that you asked me to delete. Is there another name for it or another way to it?
    This computer has very little in C:\Documents and Settings. I also used file search
    and looked myself. I have seen Local Settings in another computer but can't find it in this one. Thanks,
    Icemaiden
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's a folder not a file, full of temporary files. And I didn't ask you to delete the folder itself, simply it's contents.
     
  9. IceMaiden

    IceMaiden Private E-2

    Thanks again for all of your help. If I did this right I was able to delete all of the contents of temporary files in local folders. At first there was an index folder
    in temporary internet files whose contents I couldn't delete but when I went back it was empty. I will do all of the remaining protection items. Ice Maiden
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds