did i get rid of them all?

Discussion in 'Malware Help (A Specialist Will Reply)' started by madjag, Jun 16, 2010.

  1. madjag

    madjag Private E-2

    About 2 weeks ago, i ran spybot search & destroy and it picked up the Opacki.ru trojan. deleted it and it hasn't come up in subsequent scans.
    last week, i clicked on a search result link in google and got all these pop-ups appearing. ran my antivirus (Macafee) and it found and quarantined the Artemis! virus. i deleted it.

    decided to go through and see if i got everything out of my computer, so went through the read & run me first steps. was unable to remove Java 6 update 12. got the following msg: Error 1606. Could not access network location." Got the same error when trying to install update 20.

    when i went to msconfig to change it to normal setup (was on selective), got the following: "An access denied error was returned while attempting to change a service. You may need to log on using an administrator account to make the specified changes." the changes took effect in any event. Don't know if this is a standard message, but i only have one acct on my pc.

    i then ran the tools. Originally, i forgot to disable disk emulation and ran SuperAntiSpyware and Malwarebytes. Upon realizing my mistake, I disable disk emulation and started all over. (so there are 2 versions of those logs).

    upon running root repeal, got the following msg: "Invalid PE image found." was still able to run it. MGtools would not run. Upon double-clicking, it created the MGTools folder on C:\, but nothing else happened.

    just wanted to make sure that it's all gone.

    Also, I noticed LSA Shell (Export Version) on my program permissions for macafee? is this an ok program?

    lastly, would any of the items i had, or that the programs picked up, transmit info like passwords/acct #s over the internet if i was accessing sites i had to log into or did internet banking, etc...

    thanks very much.
    Mike
     

    Attached Files:

  2. madjag

    madjag Private E-2

    the rest of the logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If the C:\MGTools folder was created, double click the C:\MGtools\GetLogs.bat. Tell me what happens. (Note: if using Vista, don't double click, use right click and select Run As Administrator). Does it produce a log at C:\MGLogs.zip?
     
  4. madjag

    madjag Private E-2

    worked this time. attached the logs.

    also - noticed a typo in my initial log. the trojan was opachki.ru (not opacki.ru)
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would appear as though the scans took care of the malware. Let's just clean up a few dead items.

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. madjag

    madjag Private E-2

    followed all the steps and they seemed to work fine. i got the message saying that those items were successfully entered into the registry.

    when i tried to reply to your post initially, lost my internet connection. tried to repair it, but had to restart instead. got a message: End Program - n. whatever program that is was not responding. shutdown took a bit longer than usual.

    aside from that, everything seems to be working ok - no weird occurrences or pop-ups.

    attached are the latest logs.
     

    Attached Files:

  7. madjag

    madjag Private E-2

    The only weird thing i've noticed is that when i go into mcafee to view my network, my router is now labeled and treated as an ICS host computer. before, it was just a router. (File sharing is not checked in the local area connections properties.)
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. As to why McAfee has renamed your router is a question for the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  9. madjag

    madjag Private E-2

    Tim,

    thanks for all your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds