Combofix - hosts.ics

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Klienfelt, Jan 15, 2012.

  1. Klienfelt

    Klienfelt Private E-2

    My laptop kept freezing up so I ran combofix and it deleted the above file. Do I need to run more scans or has combofix sorted the problem?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It depends. What problems are you having and what prompted you to run Combo?
     
  3. Klienfelt

    Klienfelt Private E-2

    Hi Tim
    My laptop kept freezing up and was unresponsive. I have since run the MGTools and Root Repeal programs not sure if they show anything?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\bltofzsb.qlf

    Adding a stick of Ram might be a step in the right direction, but I suggest you post in the software forum regarding your freezing issue.
     
  5. Klienfelt

    Klienfelt Private E-2

    Yes 1 Gig of RAM is not ideal, it's just when I am able to run the same programs everyday without the lag and one day I start to get lots of lag, usually its due to some form of malware running. Things have certainly sped up since I ran Combofix anyhow, so hopefully that cleared it.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have also removed that one file, then I guess you are good to go.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. Klienfelt

    Klienfelt Private E-2

    I deleted it yesterday as described but today the file reappeared :confused
     
  8. Klienfelt

    Klienfelt Private E-2

    Edit: I have noticed this file gets created everytime I run pokertracker3.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Interesting.
     
  10. Klienfelt

    Klienfelt Private E-2

    lol yeh, I'm kinda getting paranoid that someones spying on my cards! Any advice?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not familiar with that program. All I can suggest is you clear your internet cache after each session. I wasn't seeing any malware.
     
  12. Klienfelt

    Klienfelt Private E-2

    any idea what the function of the file is that is created?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No I don't, but I am finding that most all malware sites remove it.
     
  14. Klienfelt

    Klienfelt Private E-2

    ok well i will post on their forums and let u know what they say.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good idea, as I am curious as to what they will tell you. ;)
     
  16. Klienfelt

    Klienfelt Private E-2

    "This file is related to our anti-piracy software. It is not a threat and will be re-created whenever necessary in order to ensure you have a valid and legal copy of PT3."
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds