Wife's laptop has trojans & worms

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jbkiddtx, Oct 10, 2010.

  1. jbkiddtx

    jbkiddtx Private E-2

    Starting several months ago, an Adobe update icon in lower rt corner appeared but when selected, Adobe wouldn't update and something strange would happen, computer would shut off or re-boot and the icon stayed. The serious problems were 1st noticed between Sept 16 and 25th. Using Internet Explorer, she went to the Bank Of America site to pay bills on-line and the site key was wrong. She had to exit and re-enter 6 - 8 times before the correct site key was seen and proceeded. Later, while checking her student's book orders on the Scholastic Book Club site, she got a warning Windows was being shut down to protect itself and when she did what it asked being the 1st time it had happened, she got the blue screen. Then Yahoo Mail started insisting entery of visual security codes to send email but when she entered them, it would say 'that's wrong" and not allow the email to send. Days later, Yahoo Mail accepted the code she entered and never asked again.
    My initial scans with IOBit Security 360 found Win32.bho & file names indicating zlob.trojan and Win32.vb.bp or wormagent184320. I then registered with your forum and followed the directions. Attached are the files requested.
     

    Attached Files:

  2. jbkiddtx

    jbkiddtx Private E-2

    5th log attachment
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, jbkiddtx.

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, jbkiddtx

    I don't see alot to do.

    Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ insert user account here ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    NOTE: There is less than 10% free space remaining on your hard drive. Your choices to make additional room on your harddrive are deleting, saving to external media, or upgrading to a larger drive.
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Now open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Then install the latest Sun Java Runtime Environment

    Let's run an online scanner by following the instructions for Using ESET's Online Scanner and attach the log it creates.

    What malware problems are you still experiencing?
     
  5. jbkiddtx

    jbkiddtx Private E-2

    Thank you for all of your help! I got an email of your initial reply but not the second one, my reason for my delay. I followed your instructions. Java 6 update 20 was deleted and 22 installed. The ESET log is attached. I can't report what problems are still being experienced, we ceased using the laptop untill cleaning and repairs were finished. I will ask her to start transfering files to another drive or cd's to make room and clean-up the desktop. If you think her laptop is clean now, can/should I uninstall all of the programs used in the process?
    Jeff
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're welcome.

    Nothing troubling in that report, our final steps will cleanup after the tools and give recommendations.

    *If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds