Malware or Vundo problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by TrojansRlame, Oct 15, 2008.

  1. TrojansRlame

    TrojansRlame Private E-2

    Hey, think im having some sort of vundo problem or malware problem any help here are a few logs i saved from running the programs located in the Malware Removal thread.
     

    Attached Files:

  2. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello TrojansRlame,

    You got a good start going there, but I also require the MGTools logs. Do you have them available to post?
     
  3. TrojansRlame

    TrojansRlame Private E-2

    Ya, sorry about that. I added another log from Smitfraudfix. (Not sure if needed but figured i'd let you check it out)
     

    Attached Files:

  4. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello TrojansRlame,


    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    3. Open notepad and copy/paste the text in the quotebox below into it:

    Save this as CFScript.txt, in the same location as ComboFix.exe


    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
     
  5. TrojansRlame

    TrojansRlame Private E-2

    Hows it going? Ran Combofix and heres the log.
     

    Attached Files:

    • log.txt
      File size:
      12.4 KB
      Views:
      1
  6. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello TrojansRlame,

    The CF log looks ok, let's take another look at the MGlog set. How is your computer currently running?

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. TrojansRlame

    TrojansRlame Private E-2

    Here's the new MGlog.zip
     

    Attached Files:

  8. __RiP_ChAiN_

    __RiP_ChAiN_ Private First Class

    Hello TrojansRlame,

    your logs look good, unless you notice anything else let's finish up here.

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. TrojansRlame

    TrojansRlame Private E-2

    Ok, thanks RiP_Chain you were a big help! appreciate it. Ill be stopping in with questions frequently.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds