Infected, Cleaned, Looking For Peace Of Mind

Discussion in 'Malware Help (A Specialist Will Reply)' started by MKUltra81, Jul 7, 2008.

  1. MKUltra81

    MKUltra81 Private E-2

    Hi and thank you all for the work you do and resources you provide.

    I got infected with a number of Trojans while installing a torrent program (very stupid I know, definitely won't do it again), including Zlob.yrq, dropper.agent.iwj, virtumonde, sheur.btos, and mediatubecodec. Not all of these infections occurred, or appeared to occur, at once but showed up over a 2-3 day period of all types of scanning. When the initial infection happened I quarantined everything AVG free notified me of, but apparently the Zlob infection took hold, since I continued removing elements of it with subsequent SBS&D scans, along with the aforementioned trojans that I imagine were spread during the program install as well.

    I saw none of the described ill effects that commonly accompany these trojans except for one instance of a porn webpage that popped up. I know this doesn't mean much but figured it was worth mentioning.

    I have since cleaned my computer using this: http://forums.majorgeeks.com/showthread.php?t=139313 and other resources. I did not take it to the point of using Combofix or MGtools as my computer appeared clean after using the tools prior to them on the list, along with HJT, Kapersky online scanner, CCclean, System Restore Toggle, and others.

    I have since followed this http://forums.majorgeeks.com/showthread.php?t=44525 process to a T and appear to be clean for the last few days with nothing coming up at all on any of the tools currently installed from that list.

    My question/concern now is how do I know my computer is really safe to use? I haven't logged into email or any other personal sites (banking) for fear of keystroke loggers, or other malicious things. I even read that these trojans can hide commands to take over your router. I don't know what to believe and what my level of concern should be going forward from this infection.

    I hope/imagine these are misplaced concerns as you guys seem to imply if things aren't showing up in any of these tools then a computer is safe to use. I'm not trying to put words in your mouth, I'm just saying my interpretation of the end of this http://forums.majorgeeks.com/showthread.php?t=139313 page since you don't specifically delineate what the likelihood of continued/unseen infection is.

    Please help me understand if my computer is really 'safe'. You guys specifically reference this site http://technet.microsoft.com/en-us/library/cc512587.aspx in regard to Cleaning a Compromised System. Does this only refer to hackers actually breaking into your system or does this information pertain to trojans as well? Is the only way to really know your comp is safe to format your hard drive then re-install? Even then, that msft article says things could have been hidden in other files? Jpgs, mpegs, docs?

    I know this a lot of stuff to cover and subject to lots of opinion but I'd love to know your thoughts. None of this is meant to be accusatory at all and I'm sorry if any of my phrasing came off that way. I'm sorry this is rambling, but I wanted to give context to my situation and frame my concerns accordingly within them.

    Thank you very much for any info/thoughts you can provide.
     
  2. MKUltra81

    MKUltra81 Private E-2

    Perhaps I spoke too soon on being clean, but this is exactly what I'm referring to when I question my computer being safe to use.

    I just ran a Kapersky Online Scan and got this, please advise.


    Is it possible for a trojan to infect an uninstall file?
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This is a false detection.


    If you want to know it you are really clean you have to run ALL of the READ & RUN ME that you referred to. And you need to attach all of the requested logs. Unless you do that, we cannot help you or tell you about your malware status.
     
  4. MKUltra81

    MKUltra81 Private E-2

    Thank you for the Kapersky diagnosis.

    Ok, will do. READ & RUN ME FIRST section prior to OS specific cleaning is complete. Proceeding with scans. Attached are SASlog and MBAMlog.
     

    Attached Files:

    Last edited: Jul 8, 2008
  5. MKUltra81

    MKUltra81 Private E-2

    I forgot to mention SBS&D scan was clean too.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the other two requested logs from ComboFix and MGtools.
     
  7. MKUltra81

    MKUltra81 Private E-2

    Yes, coming in a bit. Sorry, should have done them all together.
     
    Last edited: Jul 8, 2008
  8. MKUltra81

    MKUltra81 Private E-2

    Here is combo fix. I screwed up when I ran it the first time and just double clicked it from the desktop instead of doing the run prompt/killall thing. I ran it a second time with killall. Sorry.
     

    Attached Files:

  9. MKUltra81

    MKUltra81 Private E-2

    And Here's MGtools.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix removed the last of your malware files. Your logs are clean now.

    Zlob infections are not major issues. Nor are they the type to worry about where personal information is stolen. You don't need to worry about this as your infections were just minor annoyances.

    We now need to cleanup from running the READ & RUN ME.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  11. MKUltra81

    MKUltra81 Private E-2

    Thank you very much for your help, I really do appreciate it.

    In regard to my ongoing level of concern, I imagine the rest of the trojans I was infected with (Vundo, dropper.agent, mediatubecodec) should not worry me? i.e. same as what you said about Zlob in that they are more annoyances than threats to information security?

    Progressing with Run & Read Me cleanup.

    Many Thanks Again!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes they in the same category, but your logs did not show any of these. Are you referring to an older infection? However if you are really extremely conerned about security ( which it seems like based on you continued questions), then your only real guarantees are the total clean reinstall option. However, everytime you get a malware problem, you will be faced with the same dilemma. So make sure you really follow all of the tips in the How to protect yourself from malare link properly and do not cheat. Otherwise you may always be reinstalling.
     
    Last edited: Jul 10, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds