Please review my logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by gin5ny, Mar 7, 2010.

  1. gin5ny

    gin5ny Private E-2

    Hi all,

    This board was a great help to me last year when we had malware issues. Thank you all so much for your time! It is so reassuring to know that there is somewhere to go with computer troubles!

    So now we are having new issues. No symptoms to speak of other than a sluggish computer, but Antivir has been beeping about once per hour. I always click on "do not allow", but that doesn't seem to have caught everything.

    I have run all the programs in the "read me", logs are attached below. There were about 20 malware that were successfully deleted via these programs, could you please review the logs and let me know if there is anything else that I am dealing with?

    I will be away from Mar 11-20, and unable access this computer (but will follow any recommendations as soon as I return!!)

    Thank you all again for all of your support :)
     

    Attached Files:

  2. gin5ny

    gin5ny Private E-2

    Here is the final log
     
  3. gin5ny

    gin5ny Private E-2

    Hmm, didn't work. Try again :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The cleaning procedure appears to have removed your malware, but I have a couple things I want you to do anyway.

    First delete the below folder from the infection:
    c:\documents and settings\Autumn\Application Data\lowsec


    Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  5. gin5ny

    gin5ny Private E-2

    Wow, thanks for getting back to me so quickly!!

    I followed your recommendations and the log is attached. Much thanks for your support! Let me know if there is anything else I should do.

    Ginny
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. gin5ny

    gin5ny Private E-2

    Hello again!

    I was away for about 10 days, so that is why I haven't been able to get back to you.

    When I returned home, I started getting warning messages from Avira once again about viruses. They are TR/Drop.Agent.bsiw Trojan, TR/Trash.Gen Trojan, & TR/Patched.Gen Trojan

    Some of it was a false positive for MGtools, the others were coming from C:\System Volume Information\restore (then a whole bunch of characters in squiqqly brackets) as well as C;\WINDOWS\system32\drivers\atapi.sys

    These may also be false positives for all I know, but to be on the safe side I ran the scans once again. Logs are attached below.

    Is there anything else that I should do, or should I just go ahead and finish up as per your last message? And if these are false positives, is there a way that I would easily be able to recognize this as they pop up?

    THanks so much once again for all your support!

    Ginny
     

    Attached Files:

  8. gin5ny

    gin5ny Private E-2

    Last log
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you completed 100% of my final instructions? If not, it was not a good idea to pay any attention ro Avira. You needed to finish my final instructions immediately without delay to cleanup all quarantined items and to flush System Restore. Not doing so, results in wasted time and effort for both of us since protection software will start telling you about things that are not problems.

    I'll take a look at your logs anyway just to be safe.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Please waste no time in completing 100% of my final steps. Then reboot your PC. Then if Avira is still detecting problems, please attach a current log file from Avira.
     
  11. gin5ny

    gin5ny Private E-2

    Hi again....I have now completed all of the steps in your last post. I apologize for jumping ahead, after being away from the computer for a week it just freaked me out to have all these warnings pop up (especially when the computer was just "sitting" and I was in the other room!!). If I am still getting warnings from Avira over the next few days, I will scan and send you a log.

    Thank you again for all of your help and support! I tell all of my friends about this website whenever they are having problems with their computers. What a great resource to have available!! Much thanks,

    Ginny
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds