Am I infected still?

Discussion in 'Malware Help (A Specialist Will Reply)' started by silas, Jul 10, 2009.

  1. silas

    silas MajorGeek

    I was infected while ago and got the newest logs to read. Thanks in advance and very much appreciated.:wave
     

    Attached Files:

  2. silas

    silas MajorGeek

    Second post for adding file.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any AV program installed on this machine, nor am i seeing any firewall, although these are listed in your logs:
    c:\documents and settings\All Users.WINDOWS\Application Data\avg8
    c:\documents and settings\mel\Application Data\PCToolsFirewallPlus
    COMODO Firewall Pro --> as running in combofix

    Is it because of this:
    Total Physical Memory 256.00 MB
    Available Physical Memory 67.98 MB

    I have no idea what these are and if you don't, delete them:
    c:\documents and settings\All Users.WINDOWS\Application Data\SIHKZFQAYG
    C:\Documents and Settings\All Users.WINDOWS\Application Data\1D157
    C:\Documents and Settings\All Users.WINDOWS\Application Data\437A

    And use windows explorer to find and delete:
    C:\WINDOWS\Ausba4.ini
     
  4. silas

    silas MajorGeek

    I tested Combo firewall and I tested PC tools fire wall. And I deleted uninstalled and deleted everything before scanning. Then after the scans I add them back. And I don't know what those files are (can I delete them sense there in windows folder, an important folder) and be okay? Or will it mess it up and make it stop running? In that folder is a bunch of folders of all kinds of virus protections and firewalls.. spybot , avg, etc and plus those.. and I don't use any of them. That is why I asked about cleaning out folders before.. Because I got many folders(i have no ideal what they are or use) but they said its safe to not touch unless I want to come across trouble.. so just keep them
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should not be using two firewalls, just as you should not use two AV programs. It causes conflicts. Are you using PCTools Firewall Plus with the AV program included?

    Yes, delete what I asked you to delete.
     
  6. silas

    silas MajorGeek

    I got rid of the 3 files that we don't know what they are. And the Ausba4.ini was also deleted and I restarted computer and it still working. Also there was more Asuba3.dll or something like that aswell.. in the folder but I kept it alone.. I was just wondering what that Ausba4 was that I deleted? Also anymore scans or anything else I need to do? And if were all done.. How do I get rid of combix and mgtools and its misc files that are in the c: drive thanks
     
    Last edited: Jul 16, 2009
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have an Artec USB scanner...if so then Ausba4.ini is related to that.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. silas

    silas MajorGeek

    Yeah I hook a scanner up once in a while thanks very much for helping
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome and I apologize if you somehow slipped in my work queue.
     
  10. silas

    silas MajorGeek

    lol No problems its your time you guys give not mine :( Thanks tho
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your welcome Silas....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds