Still have Virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by John126w, Dec 24, 2012.

  1. John126w

    John126w Private E-2

    I started with random website coming up when I was using Google. Then Microsoft Security found I had the DOS/Alureon.A trojan. I followed instructions on here to eliminate it and believe I have done so. Then followed all of the other malware clean-ups and have attached the related log files. Only one I couldn't get was the MGlogs.zip because my computer couldn't create it. I have 7zip installed but at the end of the scan it said it couldn't create a zip file.

    Does it look like I'm clean now?

    Thanks,
    ~John
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run the C:\MGtools\ReZip.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). .

    It should take a couple seconds to run. You will see a black command prompt window while it is running and it should tell you that the C:\MGtools\MGlogsR.zip file as been created. Attach this ZIP file.


    Do you recognize what the below is for?
    [RUN][SUSP PATH] HKCU\[...]\Run : vCommsIde (rundll32.exe "C:\Users\John&Rebecca\AppData\Roaming\vCommsIde\vCommsIde.dll",lanUserAgent LibMousenet) -> FOUND
     
  3. John126w

    John126w Private E-2

    No, I don't recognize what that is for.

    Still couldn't get the logs to zip. Tried running what you asked and it flashed a black dos prompt and then went away almost immediately and no log created. I zipped all of the txt files from the C:/MGTools/ folder and have attached them.

    - John
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's remove the item.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Users\John&Rebecca\AppData\Roaming\vCommsIde\vCommsIde.dll
    C:\Users\John&Rebecca\AppData\Roaming\vCommsIde
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "vCommsIde"=-
    [HKEY_USERS\S-1-5-21-1658545280-3836653751-3957055406-1000\Software\Microsoft\Windows\CurrentVersion\run]
    "vCommsIde"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Also tell me if you are having any problems with your PC.
     
  5. John126w

    John126w Private E-2

    Thanks for the help, it's been greatly appreciated. I've run the scans and attached the logs as requested.

    My PC 'seems' to be working fine. I'm mostly concerned of what damage was left from the Alureon.A trojan because it was stubborn to remove. That's why I ran all of the scans and posted here with hopes that I could get some advice on what else might have been messed up. Are these scans going to fully reveal what damage might still be lingering?

    - John
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're log is clean.

    I'm not noticing any of the typical damage that this infection may cause. Frequently it breaks services related to internet connection and also the Windows Firewall but yours look okay.

    Are you noticing any problems going to Windows Update and getting updates? This is another area where it could break things.

    Any other problems being noticed?
     
  7. John126w

    John126w Private E-2

    No, there is only optional Windows Updates but no errors doing any of that. I haven't had any issues since Monday. Thank you very much for your help.

    One last question, I've read that it is reccommended to delete old restore points and start a fresh new point. Can you give me some help doing that?

    - John
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. The below should address your concern about System Restore.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. John126w

    John126w Private E-2

    All is well except for one problem. I can't uninstall GFI Backup 2009. Windows installer doesn't fully delete it. I was going to remove it and try something different for my back-ups but I can't seem to get rid of this one. Also have some files stuck in a folder that "are to long for Windows to delete". Those are my last two issues.

    - John
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For non-malware issues please post in the Software Forum. However you may be able to use the below to complete the uninstall:

    Revo Uninstaller

    And for the file name too long to delete problem, you will have to explain to the Software Forum exactly what you mean and where and what the names are. Like are you talking about to many folder levels and do you want to delete the whole folder? Or is it just a very long filename? Normally a command prompt can be used where shorten filenames can be used for files, but if you have too many levels of folder nesting, you may need to remove the whole folder using a rd /s foldername from the command prompt.
     
    Last edited: Dec 29, 2012
  11. John126w

    John126w Private E-2

    Thanks very much for your help. I will move my questions over to that section. I have filenames that are too long and won't let me rename them or delete or move them.

    Again, I appreciate your help with everything.

    - John
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Using the rd /s foldername from the command prompt should be able to help you out but you will have to provide the complete full path to the folder. And if it is not on the Windows boot drive, be sure to include the drive letter too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds