Need help with logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by mxcj, Feb 18, 2009.

  1. mxcj

    mxcj Private E-2

    Please could I get some help with the following logs? I got infected with a virus and performed all the steps given in the READ and RUN ME malware removal guide. However, I believe I may still have the ntos.exe trojan which I am unable to remove from my system. Thanks.
     

    Attached Files:

  2. mxcj

    mxcj Private E-2

    Here is the reminding log.....
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your newfiles log is virtually empty....did you get any error messages when you ran the MGTools? Because your log is empty, the only place I see ntos is here:
    c:\application data\ntos.exe

    I also see that the log for MBAM indicates that no action was taken regarding what it found. Is this true?

    Your system is very much in need of more RAM as well as a bigger hard drive:
    Code:
    Total Physical Memory    256.00 MB    
    Available Physical Memory    55.27 MB
    
    Drive    C:
    Size    9.31 GB (9,993,678,848 bytes)    
    Free Space    592.93 MB (621,731,840 bytes)    
    
    Drive    D:        
    Size    9.32 GB (10,001,907,712 bytes)    
    Free Space    6.49 GB (6,968,561,664 bytes)
    
     
  4. mxcj

    mxcj Private E-2

    The only message I got while running the MGTools was one about the dotnet framework. When I ran the MBAM program, I removed all the selected items that were found(clicked remove selected). I dont know why the logs state that no action was taken. In any case, I ran both programs again and I did not find any thing out of the ordinary....please see the attached logs.

    Yes, I definitely need more RAM/HD.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was much better....the only thing I see in your logs is this:
    C:\WINDOWS\system32\4242372442.dat --> delete it.

    Tell me what problems you still may have.
     
  6. mxcj

    mxcj Private E-2

    I deleted that file and I also deleted the ntos.exe from the application data folder. I rebooted the machine and everything seems alright. I guess it would be safe to say that the virus is gone right? Thanks for your assistance.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome........If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds