Desktop Hacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by baylock1, Aug 30, 2008.

  1. baylock1

    baylock1 Private E-2

    Hello Guys,

    I need some help with trying to remove a virus from my PC. I have found what it is, but I can't seem to get rid of everything. I have read the Malware removal forum and I have run the applications in order as requested and I have a copy of the scan logs. Please help me get rid of this pesky virus.

    Baylock
     

    Attached Files:

  2. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello baylock1,

    Do you have the MGTools logs as well?
     
  3. baylock1

    baylock1 Private E-2

    Here are the MGTools logs.
     

    Attached Files:

  4. baylock1

    baylock1 Private E-2

    Cont.
     

    Attached Files:

  5. baylock1

    baylock1 Private E-2

    I have Posted the rest of the logs. I am kind of new to forums.
     
    Last edited: Sep 3, 2008
  6. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello baylock1,

    Using Add Or Remove Programs remove the following entries (if present): (To get into add Or Remove Programs press the START button > Control Panel > Add Or Remove Programs. ))

    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) SE Runtime Environment 6 Update 1"


    Please run the F-Secure Online Scanner

    Note: This Scanner is for Internet Explorer Only!
    • Follow the Instruction Here for installation.
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
     
  7. baylock1

    baylock1 Private E-2

    Here is the file.

    Thanks for all the help,

    Baylock
     
  8. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello baylock1,

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    5. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    6. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    7. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    8. If we had you run Avenger, you can delete all files related to Avenger now.
    9. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    10. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    11. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    12. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    13. Go to add/remove programs and uninstall HijackThis.
    14. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    15. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    16. After doing the above, you should work thru the below link:
     
  9. baylock1

    baylock1 Private E-2

    Thanks for all the help. I was able to rid my PC of the malware.
     
  10. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Excellent, I'm very glad to hear of it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds