System came up clean...Thanks!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by vanheijzen, Jan 1, 2010.

  1. vanheijzen

    vanheijzen Private E-2

    I ran the tools that you recommended in the readme. I had clicked on a link that my buddy sent to me but apparently his account got hacked and it was not a legit email from him. Thanks guys! Just out of curiosity, I have the email that was sent to me with the malicious (suspected - I don't actually know if it did anything) link in it. Is it kosher to post that so that you guys can tell me what the link was trying to do to my system? I am a little hesitant to just go ahead and post a suspected link in a public forum but like I said, I would like to know what it was trying to do.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    No we don't want to see the link. The logs we ask for provide us the information we would need to see what was done to your PC and to also tell us if you are really clean or still need work. Lack of symptoms does not mean a PC is clean. In addition, are you an expert at reading ComboFix, RootRepeal, and all the logs in the MGlogs.zip file? If not then how do you know you are clean.
     
  3. vanheijzen

    vanheijzen Private E-2

    1 of 2
     

    Attached Files:

  4. vanheijzen

    vanheijzen Private E-2

    2 of 2. I guess I jumped the gun. When I scanned my computer again it did not come up clean this time. I included a log from Panda Cloud Antivirus because it found something as well.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On the contrary, your logs are clean. There were no valid detections in your logs. Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  6. vanheijzen

    vanheijzen Private E-2

    Thanks. I have been anal about protecting my system since I thought I got infected and have run Panda Cloud Antivirus every couple of days. Now it is telling me that I have been infected by:

    Nabload.DPS

    which really pisses me off. How could I have been infected by this? I hardly go on the internet at all with this computer and when I do it is my work web site, email or something similar. I will repost all of my logs in the morning.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Giving us just a useless name of an infection is not helpful. We need to know exactly what files or registry keys....etc are being indicated. For all we know Panda is not detecting anything valid since you were clean. Had you finished my final instructions????? If not, it is a waste of time to tell us anything about any detections since you might just be detecting what we already cleaned up and have quarantined. You need to finish final steps before any other scans are run and they final steps need to be be finished quickly.

    On the other hand it is possible you reinfected your PC and would have to run the cleaning process again and post in a new thread.
     
  8. vanheijzen

    vanheijzen Private E-2

    1 of 2
     

    Attached Files:

  9. vanheijzen

    vanheijzen Private E-2

    First off, I want to thank you for taking the time to look into this for me. I truly appreciate it. I realize that just posting a virus name doesn't give you a whole lot to work with. I had posted that at night and intended to follow up the next morning with all of my logs and everything but I had to go on a business trip at the last minute. Anyways, I had gone through the steps that you outlined as far as cleanup. Just to be sure I double checked that all of the things you mentioned were indeed uninstalled. Then I ran ALL of the steps again (all of the scans and all of the cleanup). The ones that I could read came back clean. Then I redid all of the scans. At this point I have not done a cleanup. I will wait to hear from you before I do anything. I think I should mention that the reason I got spooked after the original scan/cleanup was because I started having errors with my system. I got the typical 'Do you want to send a report to Bill Gates?' greeting whenever my system booted up for Microsoft Intellipoint and Microsoft Intellitouch. I uninstalled them but I still wanted to scan my system. I included my scan from Panda antivirus because it thinks that it found something.

    Thanks again, sorry for the novel email.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it did not find anything valid. You need to complete my final instructions properly so that System Restore is emptied. Do all of my final steps from beginning to end? Do not run any scanning tools until you have finished final instruction? Until final steps have been completed, you are not supposed to be doing anything except what we request and the false problem you had is one reason why.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds