Malware scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wild, May 6, 2009.

  1. Wild

    Wild Private First Class

    Here are malware scans one one of our comp. This computor works online,the other two do not.One other runs Vista of which if i may will post logs when i can find them.Thanks in advance.
    Wild.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Your Mglogs.zip is very incomplete, and I don't have enough to work off there.

    Please run MGTools.exe again making sure that you don't interrupt it, and also note down any error messages you may/ may have received. Referring to this if need be:

    Using MGtools (scroll about half way down to possible error messages section.

    Then once finished simply attach the new Mglogs.zip into your next reply here. Thanks

    Kestrel13!
     
  3. Wild

    Wild Private First Class

    Here is MGlogs zip. I ran MGtools.exe again and retrieved it from D/
    Thanks Wild.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there... the mglogs.zip is still incomplete :(
     
  5. Wild

    Wild Private First Class

    Heres another one Kestral,lets hope this works. Not know what is or isn`t complete on MGlog.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Incomplete again, you are meant to rerun it.

    Go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one. Run the new MGTools.exe and attach the new mglogs.zip that it generates into your next reply.

    Thanks
    Kes :)
     
  7. Wild

    Wild Private First Class

    Erm, that was run just before i posted it as the log has todays date on it.Ok i will post another.
     
  8. Wild

    Wild Private First Class

    Here is the very latest one. Can you tell me what Wild Tangent is for and what it does? Sure i remember years ago it was a dodgy prog?
    Thanks again.
    Wild
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    @Wild.....please tell Kes exactly what happens when you run the MGTools.exe. Do you get error messages? Did you look at the link she gave you for running MGTools and possible error messages? Are you making the agreement to run the HJT program? Are you waiting until the scan is finished and you get the message to press any key?
     
  10. Wild

    Wild Private First Class

    Hi, the MGtoolsexe. runs right through until `hit any key`. No error messages,
    agreement for HJT? Can`t see what i`m doing wrong,the prog runs right through until hit any key.Then i wait a while then do so and submit the log.
    Wild.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are obviously having some sort of problem.

    Please go to C:\MGtools\ShowNew.bat and doulbe click it. Attach the log.

    Now go to C:\MGtools\GetRunKey.bat double click and attach the log;

    Now go to C:\MGtools\analyse.exe double click and attach that log.
     
  12. Wild

    Wild Private First Class

    Here are the logs, hope they are the ones you requested.
    Thanks Wild.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Apparently you installed MGTools to the d drive...it needs to be on the C drive with all the other tools. Did you not notice where we were directing you?
     
  14. Wild

    Wild Private First Class

    This time i hope we got somewhere. The MGtoolsexe has always been downloaded and run from C:,and the zip always ends up in D: Why does it do that?
    I deleted more than once the exe.and MGfolder,the only part i could not find was pf MGtools.
    During one scan i noted that it stated;

    `process Dll exe -application error.` `0x00000135`

    After this i removed and downloaded the link from Kestral and it ran ok.
    But at the end it had `could not find C:\MGtools\procdll.txt`
    Wild.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Apparently I was brain dead again last night....you need to put MGTools on the root drive, which in your case is the D drive.
     
  16. Wild

    Wild Private First Class

    Ran this from D: and this time the HJ agree box came up,it did not before.Soon after a error box came up same `failed initionalise`
    could not find processdllexe.
    Im confused with all this,if need be will try again.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, now that we have that handled, your logs are clean. The only suggestion I have is that you run HJT and remove these ( but it is up to you):

    O1 - Hosts: 91.121.97.18 mininova.org
    O1 - Hosts: 91.121.97.18 www.mininova.org
    O1 - Hosts: 91.121.97.18 thepiratebay.org
    O1 - Hosts: 91.121.97.18 www.thepiratebay.org
    O1 - Hosts: 91.121.97.18 demonoid.com
    O1 - Hosts: 91.121.97.18 www.demonoid.com

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  18. Wild

    Wild Private First Class

    Hi TimW,i did the above and everything was ok but did a routine scan using SpybotSD. It came up with Vertimond. The comp.now runs very slow, it takes ages to go online and change web sites,load programmes.Worse is any type of scanner. The SpybotSD takes hour and half for one scan,followed everything in your malware removal section.Even the turning off TDss in plug and play which i dont seem to have. Some thing is slowing down the processes and it took a whole evening to run these scans again. Hope they are complete.Thanks for your time.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will have to tell me exactly what was found, as your logs are still clean. Your main problem is you are running AVG8 on a system that doesn;t have the resources to support it:

    Total Physical Memory 512.00 MB
    Available Physical Memory 246.79 MB
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds