Am I clean now? A question

Discussion in 'Malware Help (A Specialist Will Reply)' started by ragexzero, Dec 5, 2008.

  1. ragexzero

    ragexzero Private E-2

    I followed the READ & RUN ME successfully and after all the scans, I was clean from the trojan Ad-Aware detected. Thank you all so much.

    But before I claim victory, I have a question. I have always had hidden files visible on my computer and I am 100% sure that I didnt have the "RECYCLER" and "System Volume Information" folders on each of my hard drives (two partitions and one external) before.

    These folders appeared today after I did a scan with AdAware and "deleted" the offending trojan for the second time (Win32.Worm.Autorun). And I read that they might appear because of malware so I did the READ & RUN ME and it seems Im clean now (scanned with AdAware again, since this was the only program that claimed infection and it turned out nothing).

    Is this something I should be worried about? can I delete these folders now that it seems that Im clean? why did they appear out of nowhere?

    Attached are my logs, just in case. Thank you all again for the help.
     

    Attached Files:

  2. ragexzero

    ragexzero Private E-2

    Heres the last log.
     

    Attached Files:

  3. ragexzero

    ragexzero Private E-2

    Ok, Ive just learned that some kinds of malware stop the hidden files from being displayed. And Im realizing all kinds of new files now on Windows Explorer (like the ubiquitous "thumbs.db" for picture folders, which wasnt there before). So maybe I didnt have hidden files showing after all. Also, I recently installed SP3 on my computer and maybe that brought the Folder options to a default (not showing hidden files). No? maybe?.

    The question now is, why did the hidden files become suddenly visible? They didnt become visible after the first time I deleted the trojan with Ad-Aware, so why now?

    Also, I cleaned my register with CCleaner after I read the post here on how to speed up your computer and do maintenance. After I rebooted, I used Hotmail to view my inbox, and when I closed the IE window, I got a pop-up alert about my computer being infected with malware and to install Antivirus 2009. Of course I knew this was malware, so I hit Cancel, but I had never had one of those pop ups before I ran Ccleaner. What gives?

    Any help is appreciated. Thanks a lot.
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ragexzero

    First - Running MGtools.zip does Unhide Files & Folders for you.
    Second -The correct way to deal with the installations of these rogue applications is to use Task Manager > End Task rather than using Cancel because clicking ANY buttons WILL install the appl anyway.
    Third - Ad-Aware is not very effective with dealing with today's malware.

    Please be patient while I look over your logs.

    Thanks!
    dr.m
     
  5. ragexzero

    ragexzero Private E-2

    Thanks for your reply and your help.

    I think you misunderstood something a bit tho. My files became unhidden before I ran MGTools. They became unhidden when I deleted the malware through Ad-Aware for the second time. Before I did the Read & Run Me.

    I ran checks with every antispyware I have again and they all came out clean, so I probably dont have the Antivirus 2009 malware I was afraid of.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ragexzero


    First - some answers to your questions. The Recycler and System Volume Information folders being a part of Windows and have always been on your system. Next, the unhiding files is only one settting - there is also the unhiding of protected operatiing system files which is a separate setting as explained in the READ & RUN ME FIRST. Malware Removal Guide. I cannot explain how you had your system set before, since we have no logs to show what the state (your settings) really was.

    Now - let's get started with the malware removal.

    *If you have not already done so, please disable the Guest account in User accounts.


    First, please disable any antivirus and/or antispyware programs you have installed so they will not block this fix. (Remember to enable them again when this steps are completed.) Print out these instructions or save them to a text file so as All Browser Windows must be CLOSED. *The fixes are specific to your problem and should only be used for issue(s) on this machine.


    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed


    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=- 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Step 3:
    Run Ccleaner


    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    Thanks!
    dr.m
     
  7. ragexzero

    ragexzero Private E-2

    Followed your steps and didnt get any errors during the use of ComboFix or MGtools. It went pretty smoothly, like the first time. I just had to find out how to disable the AVG Resident Shield beforehand but that wasnt too difficult. I havent had any problems since my previous post. I never got the "Antivirus 2009" pop-up asking me to install it anymore while using IE and Ive done some scans with MBAM, Spybot and Ad-Aware, as well as AVG and they have all come up clean as a whistle.

    Attached are my logs as requested.

    Thanks for the answers to my questions and for all the help. Let me know if theres something else I should do.

    One thing I did notice when I rebooted after using ComboFix and MGtools this last time, was that during the boot up process, my computer now flashes that black screen that says something along the lines of "What would you want to do? -start windows with last known good configuration -start windows in safe mode..." etc, before the Windows XP logo. Is this a sign that something went wrong during the use of the cleaning programs? That screen didnt use to flash on boot-up before. Just curious.
     

    Attached Files:

    Last edited: Dec 9, 2008
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ragexzero

    Your new logs are clean. I do have a question about your last post.
    Did you experience a system crash at any time during the cleaning process? If not, by installing the Recovery Console - there will be a momentary black screen asking whether you want to boot to the Recovery Console or normal Windows boot-up that lasts for a few seconds. Please reply post to this question.

    Thanks!
    dr.m
     
  9. ragexzero

    ragexzero Private E-2

    To answer your question, no, I didnt experience any crashes during the cleanup process. I think it was ComboFix that restarted my computer, but thats it. It all went smoothly (or so I thought).

    The black screen is present EVERY time the computer boots up, but it only flashes for less than a second and I cant even read well what it says. I just see theres a few "options" (around two or three of them) on it and one of them says something like "Windows XP Professional" and thats it.

    I didnt have any crashes when I did the "Read & Run Me First" either, but after I completed that one, my computer didnt flash the black screen. It only started doing that after this last time you had me run ComboFix and MGtools.
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    That is caused by the Recovery Console having been installed.... no worries there.

    If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  11. ragexzero

    ragexzero Private E-2

    Thanks for all the help. I did the last steps, but I confess that for a while I thought about keeping ComboFix and MGtools, just in case I get infected again. Heh.

    I had to switch the "Desktop" part in ("%userprofile%\Desktop\combofix" /u) to "Escritorio" since my Windows is in Spanish, but after that it worked perfectly.

    I realized that when you enable hidden files, the RECYCLER and System Volume Information dont show, and they only do when you choose to show "protected system files". Good to know that.
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're Welcome, ragexzero!

    It would be a good idea to always come back and get a fresh set of tools [when needed ] as they do get updated.

    Enjoy your pc!
     
    Last edited: Dec 9, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds