Combofix logs with *.vir seem I got the wrong version.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by szeto, Jan 4, 2012.

  1. szeto

    szeto Private E-2

    Got the system fix virus on christmas day and bowsing the web came across using Combofix.
    From reading threads, it seem that I got the wrong version.
    I have the Qoobox log. In the folder there are a lot of files ending in *.vir
    I have empty folders in my start up section and still missing some shortcuts on my desktop.
    Have run pctools spydoctor with antivrus and gone through unhiding my folders and still not working.
    my autorun functions seems not to work.
    I was hoping to get to my restore point and restore system to before the infection which will be before the 24th of December.
    I tried safe mode and the lastest date I have is the 27th after runing the combofix.
    Any help will be appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. szeto

    szeto Private E-2

    Hi,
    I did download and run the unhide software. Still have shorcut on start menu indicating empty. Example of shortcut folders are Microsoft Office, HP printer, Roxio, Adobe etc.
    Also the printer shortcut on desktop is still not available.
    Went through the removal/cleaning procedure and have the logs.
    Did not run the MGtools and the RootRepeal yet since I did not run the Combofix again. Had run it previously and have the logs attached.
    See all attached logs.
    Thanks
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put Combo directly on your desktop, not here:
    Running from: c:\users\AHIEKPOR\Downloads\ComboFix.exe

    Please run the MGTools.exe and attach the C:\MGLogs.zip.
     
  5. szeto

    szeto Private E-2

    Hi,
    I have attached the MGlogs.zip.
    Apppreciating the quick responses.
    Thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. szeto

    szeto Private E-2

    Hi,
    Yes it seem that I do not have any malware.
    A few things that concern me is this.
    1. Please refer to a posting by dkingery and the response to his posting.
    I am having similar effect.
    The folders when you point to when you click that start bottons all shows empty.
    I know that they represent shortcuts but they were there before I ran combofix.

    2. I have not run the uninstall combofix yet. I want to make sure that the quaratine folder Qoobox by combofix is not needed at this time since from the refered post will be deleted when uninstall is run.3. When I put a cd in the drive I do not get the autorun initiation.
    I have to open it and look for the exceutionable file in the folder and manualy run it from there.
    Thanks.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can see in the Combo log that none of your short cut icons were removed or compromised by Combo. This is a result of the infection. You just may need to either reinstall those items or recreate the shortcut.

    The rest of your issues should be addressed in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  9. szeto

    szeto Private E-2

    Hi,
    I have done the final steps. Wanted to make sure that no issues have been left.
    Two things remained after the various steps to remove the installed programs.
    There is still a folder for MGtools with a swreg.exe file in it.
    Also there is a Malwarebyte folder with mbamext.dll file in it.
    Everything else is clean.
    I have been able to manually install the window start folders.
    I can not thank you enough. You all are doing a great job.
    Thanks so much for the time you all take to help us online.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to just manually remove those folders.

    And you are most welcome. ;)
     
  11. szeto

    szeto Private E-2

    Done.
    Manually removed. Thanks
    Have a great day and happy New Year to all administrators.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds