malware removal assistance needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by indigolite, Oct 17, 2008.

  1. indigolite

    indigolite Private E-2

    I have followed the read and run me... Here are the logs. trojan.agent and broken.open command were found. Still having problems with something in microsoft word making copies of document, has a blue dot on all documents. replaces title with ~$ for the first two letters. Please advise on how to get rid of this.

    spybot didnt find anything i keep this on the desktop and run every few days and super antispyware didnt find anything. Hijack This didnt run, a prompt said to close the window.

    Also when following the read and run me steps when emptying norton recycle bin an error message showed up with sun java- something like: java language death thread?????? Thank you for your assistance.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, indigolite

    Please attach the log from running Malwarebytes' Anti-Malware.
     
  3. indigolite

    indigolite Private E-2

    Hi HI HI dr.moriarty,
    I thought i had yesterday. So i opened it up on my computer to look at it and it is the malwarebytes anti-malware log on notepad.
    I might have renamed the file the other day when i was saving it, so it might look different in the title. i will look and see if i can find it and re- attach.
    When i try to re-attach this it says i have already uploaded it.
    Let me know if this is what u need or if i need to do something different. Thanks.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    I think I've stared at the monitor too long, today - indigolite.... it's the SUPERAntiSpyware log that I need you to attach.

    Thanks!
     
  5. indigolite

    indigolite Private E-2

    dr.moriarty
    Your welcome....
    Here u go.
    :cool
    ... thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for the delay.

    Other than what has already been removed by the cleaning procedure, your logs are clean.

    This is not malware. Anytime you open up a Word Document, Word will create this type of temp file. It replaces the first letter of the filename with the ~$ and the rest of the filename is kept the same. When the Word Document is properly closed, the temp file will go away.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. indigolite

    indigolite Private E-2

    Thank you Chaslang for your response.
    After the malware scans had been run.... when i disabled the connections.. a few days later, something in the computer brought up 20 network connections screens and attempted to re- establish connections, even bringing up a help screen. The computer then restarted without me doing anything {the cd-rw drive opened and closed a few times)..approx 20 cc cleaners came up when i had only clicked once on cc cleaner to try and rid this. Prior to running the malware removal scans the cd-rw drive door would open and close numerous times by itself. please advise...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you disable connections? And are your referring to your network connection and how many did you have?

    This does not sound like malware. It sounds more like hardware issues. However even in a few days, we have seen people get a PC very badly infected. If your PC has not been connected to anything, then it is not a malware problem and since it has been a few days after the cleaning procedure before this occurred, it is also not an effect of the cleaning.


    Also sounds like you have hardware issues.

    You can attach a new log from MGtools if you wish and I will look at it to see if anything new shows up.
     
  9. indigolite

    indigolite Private E-2



    When i try to submit this reply i get an error message to lengthen the message longer than 4 characters. i dont understand the error message
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your log you did not allow Malwarebytes to fix the problem. If you don't fix it, it will keep finding it. It is just registry settings that have been changed. They could effect your ability to load screen saver files and also the Windows Registry Editor.

    Your logs are still clean.
     
  11. indigolite

    indigolite Private E-2

    Originally, you asked me to do the MGtools scan and include the MGtools log. Would you please take a look at the Mgtools log. I noticed that the it didnt appear to have been opened. Can you please view it and let me know what i need to do to make sure system is clean.
    I also included the malwarebytes scan as well to show that broken.open command is still showing up. I did follow the recommened steps which includes restarting after removal. It still shows up. I don't understand why.
    Thank you for your time and progress made.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have looked at them even though the view counter shows 0. I just looked at them again to double check and there are no problems in the logs. In fact runkeys.txt shows the registry keys that Malwarebytes is mentioning to be set to the correct values. Now it could just be that you ran MGtools after MBAM had already fixed them. You could try rebooting and not running MBAM and then getting another new MGtools log to see if it shows the registry keys being changed to the incorrect value after a reboot.

    You can look at the runkeys.txt log inside of the C:\MGtools folder for yourself and you will see the last log showed the below for those two registry keys and these are the correct values. If they are being changed back to the wrong values, it is probably due to Symantec not allow the keys to be set to the proper values.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds