Here are my logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by 24601, Jan 14, 2013.

  1. 24601

    24601 Private E-2

    I have run everything and encountered no problem in doing so. But I'm still worried. Would you please check my logs?

    By the way, SMADAV is the name of my antivirus, but one of the anti malwares detected it as suspicious.

    I'm so dumb in this, so please answer these, even when they sound ridiculous:
    1. If there's nothing, I can just re-enable the defogger, right?
    2. Did I install anything (apart from the MBAM) while doing the steps? Is that okay if I uninstall them?
    3. My problem is actually with bandwidth. Something seems to eat up my bandwidth. Suppose it doesn't happen again after I run all the checks does that mean everything is okay?

    Thanks a lot. I am not expert, sorry for any folly I write in this post.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you purposely set up to use a proxy?

    Rerun Hitman and have it delete: Potential Unwanted Programs



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\asus A42F\AppData\Local\iLivid
    C:\Program Files\Babylon
    C:\Program Files\Search Results Toolbar
    C:\Users\asus A42F\AppData\Roaming\Microsoft\Windows\Templates\3f83w6w33881l6t625fq32ykha6767
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. 24601

    24601 Private E-2

    I don't really understand what you mean by "set up for proxy." I usually use proxy for my campus internet connection every now and then, though.

    My computer situation right now is shown in two images below. I got mso.sys, System Volume Information, $recycle.bin, and autorun.inf in every drive. In C: I got Copy of links folder (1-4) but I think I put it there once as a part of Ramnit Virus removal.

    http://i50.tinypic.com/35mh93b.jpg

    On my Desktop I see files like in the image, I don't know what they are or whence they come from. They are just there when I turned on my laptop. It wasn't there before I run the Malware removal procedure.

    http://i45.tinypic.com/f4pnig.jpg

    Here are the logs:

    Thanks for everything. I really appreciate the time and effort you put in this.
     

    Attached Files:

  4. 24601

    24601 Private E-2

    I seriously don't understand. I have posted like 2 replies by now, but it doesn't show up in the thread, so if it's a double post please forgive me.

    I'd like you to know that there is no problem in running all the procedures. Nothing at all. But there are strange folders in each of my drives now.

    http://i50.tinypic.com/35mh93b.jpg

    They are $Recycle.bin, System Volume Information, mso.sys and autorun.inf. I don't know about the Copy of Shortcuts (1-4) because it might be dummy folders I created as one of Ramnit removal procedure once.

    On my Desktop I see strange files as well. They weren't there before I run the malware removal procedure. They appeared after I turn my laptop again after removal.

    http://i45.tinypic.com/f4pnig.jpg

    Is that okay if I delete those?

    Thanks in advance for everything. Thanks for helping me. I appreciate the time and effort you put in all this.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Leave them all alone ;)What do the shortcuts lead to? Just delete those if you wish.

    They appear to be word documents and windows media player related files. Hidden files are set to show at the moment, once we finish up here it will all be reversed again.

    I see no further issues. Ready for final steps?
     
  6. 24601

    24601 Private E-2

    Deleted the shortcuts. I'm ready for everything now~
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. 24601

    24601 Private E-2

    I've done everything. Thanks a lot for your help, really. Now things look better.

    Have a nice day. <3
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds