Help i think i have a malware and a bot

Discussion in 'Malware Help (A Specialist Will Reply)' started by andii0903, Apr 13, 2010.

  1. andii0903

    andii0903 Private E-2

    Hello,
    When I am on the internet it dont matter what site I get a screen that says windows internet explorer warning and then it begins a scan. In the top bar the address is 85.12.44.160. I have been notified by qwest that i am putting out bots and have reset my laptop 3 times back to factory setting also on another computer put in a new harddrive. I ran all the tests that you all requested and am including the logs. As far as I can tell there is nothing being detected. Thank you in advance for your help!!
     

    Attached Files:

  2. andii0903

    andii0903 Private E-2

    I dont know how to upload the MGtools log.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    The same way you did the other logs. The MGlogs.zip file is located in your root folder ( C:\MGlogs.zip ) just browse to it and select it and upload it.
     
  4. andii0903

    andii0903 Private E-2

    Thank you!! Is it possible that I can put up the logs for my desktop as well in this same thread?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    No. New PC = New Thread. Also a new problem on this PC in the future would mean a new thread too. Doing otherwise, always leads to confusion. ;)

    Your logs are actually clean which is what would be expected after a reset to factory condition. Perhaps your problem is not in your PC but rather in your router. At one point you possibly had a WareOut infection ( aka: DNS hijacker ) which are also known to infect router hardware. This would also possibly explain why your other PC has issues especially if the same issue. Try the below and see what happens.

    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.


    Also Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window

    And finally, delete the below file:
    C:\WINDOWS\Temp\patch.js


    Are you still having problems?
     
  6. andii0903

    andii0903 Private E-2

    First off Thanks for all of your help!! I have Trend Micro RU Botted installed on this netbook and was informed this am that it found a BOT. I am uploading my MGlog for you to look at. If there is anything else that I may need please let me know.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It has been too long since you last replied. You never responded to my previous message. You should have completed the thread. Now it is too late and an MGtools log alone is of no use to us. You will have to start the cleaning process all over if you are still having malware problems. Also if TrendMicro is finding something, you will need to attach a log from it..... that is if it is unable to fix the problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds