Malware removal - alvinhky - part 1

Discussion in 'Malware Help (A Specialist Will Reply)' started by alvinhky, Jun 19, 2009.

  1. alvinhky

    alvinhky Private E-2

    Hello

    I noticed my PC was infected two days ago after accessing a website

    I then scanned it using AVG and spybot but didn't find any issue

    I noticed a suspicious file in task manager (sever.exe)

    The first time, I ran superantispyware and malwarebytes anti-malware only and managed to remove some infections

    Now the second time, I ran the steps as per advised in the malware removal guide

    1. superantispyware
    2. malwarebytes anti-malware
    3. combofix
    4. rootrepeal
    5. MGTools

    I am attaching the logs that i have gone through

    After doing this, i scanned it using PC Tools Spyware doctor and I am still detecting

    Application.NirCmd
    Trojan-Proxy.Small.BO

    Please help to advise the next step I need to take to completely remove the viruses
     

    Attached Files:

  2. alvinhky

    alvinhky Private E-2

    Re: Malware removal - alvinhky -

    attaching another file MGlogs.zip
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per our instructions, you should only run scans once.

    Also per our instructions, you should not be running anything except what we ask you to run. Spyware Doctor is wrong! NirCmd is a valid tool used by many programs. See: www.nirsoft.net/utils/nircmd.html

    Your logs appear to be clean but you will need to reinstall WinPcap if you need it since ComboFix broke it.

    Also you should uninstall the below:
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    LiveUpdate 2.6 (Symantec Corporation)
    Spybot - Search & Destroy 1.5.2.20

    And then reboot and install the current version of Sun Java from: Sun Java Runtime Environment


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix and C:\QooBox folders from combofix (if it exists and note that you may need to substitute a different drive letter than C: if you have Windows installed on a different drive.)
      • Also delete the below two files that are left behind by ComboFix, some scanners falsely detect these as problems which they are not:
        • C:\WINDOWS\NirCmd.exe
        • C:\WINDOWS\PEV.exe
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Jun 20, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds