Is my computer free of malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by misko1099, Aug 11, 2008.

  1. misko1099

    misko1099 Private E-2

    On 8/6/08, while visiting websites I shouldn't have been visiting, my antivirus program (McAfee) notified me that at least 3 trojans were detected on my computer and were supposedly removed. However, everytime I would start IE they would be detected again. McAfee identified the trojans as Generic Backdoor.t (server.exe), Generic PWS.y (sss.exe) and PWS-MMorpg.gen (sl.exe). On 8/9/08 I ran LSPfix and removed a file called mmchost.dll. I also deleted a file called syspilog.pil. Since then, I haven't had any indications that the trojans are still on my computer.

    From 8/6/08 to 8/8/08, my firewall (McAfee) stopped programs called sss.exe and c.exe from accessing the internet; I have had no indication since then that they have attempted to access the internet.

    On 8/6/08, a program called beauty.exe installed a Windows Shell Execute Hook.

    On 8/9/08, a change was made to the Win.ini file.

    On 8/10/08, two other programs, downer.exe and dwbin.exe tried to access the internet, but were blocked (deleted both these files as well).

    I came across your site on 8/9/08 and have tried to run the cleanup process that was recommended over the course of a few days.

    Since 8/6/08, when I first received warnings, I haven't had any problems with my computer. I am concerned though that I may have compromised my computer in a major way without having any ability to detect it. I would appreciate any assistance you could offer.
     

    Attached Files:

  2. misko1099

    misko1099 Private E-2

    Here is my MGlogs.zip
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what these are:
    C:\Program Files\D166SDS1C.zip
    C:\Program Files\R526S0F.zip

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Drivers::
    Pandrv
    SEICTRL
    
    File::
    C:\WINDOWS\system32\3421AB00
    C:\WINDOWS\TEMP\Pandrv.sys
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "DelayShred"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  4. misko1099

    misko1099 Private E-2

    These are drivers for my DVD-Rom (which doesn't work) and my CD-Rom.

    I followed your instructions, but I'm not sure that I fully disabled my anti-virus.

    Thanks for your help.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer and tell me if you find this file:
    C:\WINDOWS\TEMP\Pandrv.sys
     
  6. misko1099

    misko1099 Private E-2

    I did a search of my hard drive and didn't find it. I also looked for it in the Temp folder but didn't see it there.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
     
  8. misko1099

    misko1099 Private E-2

    Thanks for your help, Tim.
     
  9. misko1099

    misko1099 Private E-2

    Sorry... I have one more question.

    Do you think I may have seriously compromised my computer? Basically, considering the types of trojans that McAfee identified, should I be concerned that my computer is no longer secure?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I doubt that you were, however....you should always change your passwords whenever you suspect that you could be.

    And you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds