Wife downloaded Facebook Trojans to my school laptop, Followed ALL instructions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jpantanava, Nov 13, 2011.

  1. jpantanava

    jpantanava Private E-2

    Hello and thanks for your time and help in advance... My wife was on Facebook on my school laptop and got hit with a Trojan complex. I am farely computer savy and ran the laptop in safe mode and ran Malwarebytes, it found and removed 8 things, I have the original log and will post it. When I restated in normal mode, I reinstalled symantec endpoint protection and the active scan quarantined a trojan. Also, as requested, I will attach the dds.txt and attach.zip logs from dds.scr. I also have a hijackthis log that I will attach if you need that as well. Once I had run Malwarebytes in safe mode, I also installed and ran Spybot S&D, unhide.exe(all my shortcuts from the desktop were made hidden, and all shortcuts within folders on the start menu are still gone, unlike the destop shortcuts after running unhide.exe...it also fixed right clicking on the desktop and choosing "next destop background". Also, right clicking on my computer and clicking "Manage" says the file is not found! I am not sure what else is screwed up but was hoping the logs and a fine computer savy buddy can help... . I will give as much info below and hope that it will be all you need, if not pleae ask:

    Initial Virus attack descripton: multiple popup message boxes opened and said something like "Warning! Hard disk failure, fix now..." I immediately shutdown the computer and rebooted to safe mode and ran the above programs. I believe that the Symantec Endpoint protection active scan quarintined something initially, then again on reinstall here is one from the log around that time: Trojan.Malscript!html - file name:dwh7fc9.tmp.
    I also ran, ccleaner, ATF-Cleaner.exe.
    -----------------------------------------------------------------
    I have attached multiple logs, see attached:

    SASlog.txt log from SuperAntiSpyware.
    Malwarebytes Anti-Malware log
    ComboFix.txt
    *NOT THIS ONE>RRlog.txt (from RootRepeal) -64bit OS
    MGlogs.zip

    -----------------------------------------------------
    Here is the virus names from the malwarebytes log (See attached):

    LEnXuYtOREFxPor.exe (Trojan.FakeAlert)

    Start_ShowMyComputer (PUM.Hijack.StartMenu)

    Start_ShowSearch (PUM.Hijack.StartMenu)

    DisableTaskMgr (PUM.Hijack.TaskManager)

    go_ez.exe (Trojan.FakeAlert)

    zugo.exe (PUP.Zugo)

    -------------------------------------------------------
    Infected Computer Info:

    System Summary: Microsoft Windows 7 Home Premium
    System Name :JPLAPTOP
    System Manufacturer: ASUSTeK Computer Inc.
    System Model: G50VT
    System Type: x64-based PC
    Processor: Intel® Core™2 Duo CPU P7450 @ 2.13GHz, 2133 Mhz, 2 Core(s), 2 Logical Processor(s)
    BIOS Version/Date: American Megatrends Inc. 209, 11/7/2008
    SMBIOS Version: 2.5
    Windows Directory: C:\Windows
    System Directory: C:\Windows\system32
    Boot Device: \Device\HarddiskVolume3
    Locale: United States
    Hardware Abstraction Layer: Version = "6.1.7600.16385"
    User Name: JPLaptop\Joe
    Time ZonE: Eastern Standard Time
    Installed Physical Memory (RAM): 4.00 GB
    Total Physical Memory: 4.00 GB
    Available Physical Memory:1.28 GB
    Total Virtual Memory: 10.0 GB
    Available Virtual Memory: 7.48 GB
    Page File Space: 6.00 GB
    Page File: C:\pagefile.sys

    Again, I am fairly certain that the threats are gone, however, I am running a 64 bit machine so I could not run the rootkits scanners. Also, I am now left with an injured Windows 7 OS and need help identifying how to repair it, since there are several subroutines that did bad things, I don't even know where to begin looking for non-functioning OS functions...However, It appears to be mainly associated with shortcuts to programs and applications,

    Thank you , Joe :confused
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. jpantanava

    jpantanava Private E-2

    Thank you for your quick reply. I went to the site http://www.sevenforums.com/tutorial...rams-windows-7-restore-default-shortcuts.html
    and restored my start menu items including, accessories, system administration, and default games, and default all user start menu shourtcuts and user. Right-clicking on My Computer and clicking Manage now works, as this is linked to System Admin folder in start menu. It appears that some system files that are suppose to be hidden are not hidden anymore, leaving them exposed to future virus attack I suppose; I had to manually add 3rd party apps shortcuts back to start menu, other than this, I think I am clean and in good working order! :) Thanks for the help, I have not trouble-shooted much of anything at this point, but I did update alot of Windows security updates including SP1 for X64 systems. Everyting is looking as it should be.... is there anything that you can suggest I check for proper function as I am unsure of the exact nature of the Virus that I encountered....?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I just suggest you keep an eye on things for a while and report back if you run into troubles.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds