Am I safe?

Discussion in 'Malware Help (A Specialist Will Reply)' started by odeonduo, Sep 11, 2008.

  1. odeonduo

    odeonduo Private E-2

    Hey,

    This is a great forum and I hope to be able to explore it fully later but right now I need an epxert opinion on my situation so I'm minimising my browsing.

    The story so far: Recently AVG picked up a trojan but wouldnt delete it saying it was too big for the archive limit so I just placed the files it identified in the recycle bin before emptying it. Subsequent scans have come up clear but i'm worried the only reason their not picking it up because its been "deleted".

    From the very little technical knowledge I have I know that it hasnt really been deleted form the hard drive, just hidden, so my question can it still cause damage or is it as good as gone?

    Thnak you in advance for any help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    "It" may be deleted ( as in long gone ) , but that does not mean you are necessarily clean.

    We can only determine that if you run the READ & RUN ME FIRST. Malware Removal Guide and attach the requested logs.
     
  3. odeonduo

    odeonduo Private E-2

    Thank you for the quick response and apologies for the delay on my part but this was beacuse I was trying to get hold of the Vista CD (I'm sorting this out for a friend) which I still havent, so I havent run combofix yet. However I've got the logs for the three other steps and I have attached them. I would be very grateful if you could have a look through.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you get an error message when you ran MGTools? Your Newfiles log is empty.

    Let's just do this for now:

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and be sure to tell me if you get any error messages.
     
  5. odeonduo

    odeonduo Private E-2

    Sorry about the empty log! I have attached a new one, which had some error readings come up with in the DOS prompt window but nothing from windows as an external pop-up.

    Should I still post a combo-fix log, I should be able to get the cd in 12-14 hours time?

    Thanks for your continued assistance and quick replys
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me what the pop up dos window said......your log is only showing one file....You do not need to do the recovery console part of COmboFIx instructions..you just need to run it.
     
  7. odeonduo

    odeonduo Private E-2

    Hey, thanks for the quick response.

    When I ran MG tools again, it came up with the message:

    "The system cannot find the file specified" for a whole list of items of which the first few were "beep.sys, crss.exe, ctfmon.exe, explorer.exe, lsass.exe,services.exe, spoolsv.exe" even though i disabled UAC

    However I have still attached the logs it came up with along with a combofix log.

    One added problem is that I was connected to the net for a very short while after running the combofix with having the firewall turned on. It was only for 10-20 seconds max, so should be ok, right?:confused
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have multiple av software:
    C:\Program Files\Trend Micro ---> this appears to have been uninstalled at some point
    C:\Program Files\Panda Security --> this is still installed
    C:\Program Files\AVG ---> this appears to be your main av program

    Please remove all but one ( I assume you wish to keep AVG).

    The services patch did not work.....when you ran it, did you get an error with doing that?

    We will try doing it with HJT.....

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to EDPPPH
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    Do this for all of these:
    SGIM
    UGWIMG
    YDLTEJUX

    * Click OK until you get back to Windows.

    * Next, run C:\MGtools\analyse.exe, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste:
    EDPPPH
    SGIM
    UGWIMG
    YDLTEJUX

    into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run C:\MGtools\analyse.exe and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O23 - Service: EDPPPH - Unknown owner - C:\Users\Noreen\AppData\Local\Temp\EDPPPH.exe (file missing)
    O23 - Service: SGIM - Unknown owner - C:\Users\Noreen\AppData\Local\Temp\SGIM.exe (file missing)
    O23 - Service: UGWIMG - Unknown owner - C:\Users\Noreen\AppData\Local\Temp\UGWIMG.exe (file missing)
    O23 - Service: YDLTEJUX - Unknown owner - C:\Users\Noreen\AppData\Local\Temp\YDLTEJUX.exe (file missing)

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  9. odeonduo

    odeonduo Private E-2

    Hey Tim,
    I removed the panda security. I had no error messages with the sevices patch.


    Unfortuantly I re-booted right after deleting the NT services adn when I ran the HJT log, the entries were not there, however I have still produced the MG logs and no errors came up ths time! (I should have read it all the through before acting on it , sorry)
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do it again and make sure you have ALL anti-virus and spyware programs disabled.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds