Malware attack.. is it really gone? :S

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DomBray78, Jan 5, 2009.

  1. DomBray78

    DomBray78 Private E-2

    Hi,

    I have followed all your instructions to remove a mal-ware attack on my computer. I followed the REad and run me first instructions and then the xp clean off and then the specific instructions for smitfraud as that was one that was identified.

    The problems were bad, I think the windows firewall was somehow disabled, the destop changed multi-coloured and I was unable to access the task bar. I also got instructions to install antivirus 2009 (that is a nasty way to spread malware!)

    Anyway here are my logs, if someone could check them over for me that would be great!
     

    Attached Files:

  2. DomBray78

    DomBray78 Private E-2

    and the rest of my logs..

    Thanks for any help!
     

    Attached Files:

  3. DomBray78

    DomBray78 Private E-2

    That will be a solid no then, the blasted thing is back again. it says win32.banker.fs trojan.{something}.ds but clicing on that tells me to install antivrius 2009 which is malware isn't it? Oh heck, where does this come from a vulnerabilit in ie 7 or firefox (I use both)

    AUperantispyware finds trojan.smitfraud variant-Gen/SRem but i followed teh smitfraud removal stuff... any help guys?
     
  4. DomBray78

    DomBray78 Private E-2

    Apparently I could have picked this up visiting an infected site, I thought this kind of vulnerability was an IE kind of thing? Can firefox let me get infected like this and what can help suggest for future protection?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you can get infected via FireFox.


    Uninstall the below old versions of software:
    SpywareBlaster v3.5.1
    SpywareGuard v2.2 <-- to old and ineffective for the current state of malware


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now install this SpyWare Blaster which is the current version.

    Now run SUPERAntiSpyware and make sure you first update the definitions, then run a new scan. Attach this log later.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • the new SUPERAntiSpyware log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. DomBray78

    DomBray78 Private E-2

    The PC in question is actually my mothers, so I'll pop over there sometime soon and follow your instructions!

    Thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay as soon as you do, be sure to attach all the new logs. And also make sure you tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds