Need your help confirming computer is clean after malware/spyware attack

Discussion in 'Malware Help (A Specialist Will Reply)' started by gmspider, Feb 10, 2014.

  1. gmspider

    gmspider Private E-2

    Opened a zip file from relative. Realized too late he had forwarded and not created it. Immediately close file, sent to recycle. Windows alerts began to pop up immediately asking if I wanted to give permission to make changes to my computer. Continued to deny permission until messages stopped. Checked McAfee Total Protection. It appears to have stopped multiple attempts to download PWSZbot-FLM!B07BA79EC303 to C:Users\Gary\AppData\Local\Temp\UpdateFlashPlayer_393e5fc3.exe."

    Before finding your forum, did the following:
    Downloaded and ran free version of Malwarebytes and Spybot Search and Destroy. Ran Malwarebytes, full scan with updated definitions. Found this: "C:\Users\Gary\AppData\Local\qkdbonai.exe (Spyware.Zbot.ED) -> 5248 -> Delete on reboot." The next morning, ran again, and caught this: Files Detected: 1
    C:\$Recycle.Bin S-1-5-21-4208881228-2746468126-2523380943-1001\$R5J2XUO.exe (Trojan.Inject) -> Quarantined and deleted successfully.

    Have been clean ever since on several full scans with McAfee Total Protection and Malwarebytes. Next went to each running process in Task Manager to confirm they are legit. All appeared to be.

    Found your forum and followed rules and steps outlined in READ & RUN ME FIRST malware guide removal. Created logs and have them available for attaching. Note: all tools ran fine, but ust before running MGTools, I realized I had forgotten to check if teatimer was running on Sypbot. Opened and couldn't find that it was running (not running it Processes) and since I downloaded the free version of S&D I didn't see where teatimer was an option.

    Scan results of MBAM and TDSSKiller said no threats found (I saved but did not review logs). RogueKiller found some PUM's (?) but I didn't read log. Did not attempt to open MGTools zip logs.

    I hope I am good but would need some assurances of same. Can you help. Let me know what you wish me to do next.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs did not attach :)
     
  3. gmspider

    gmspider Private E-2

    Was waiting for your response before attaching. Sorry for the follow up post also. Didn't see the splash screen message about the post delay pending approval. So posted again. My bad. Here are logs generated from following your instructions. Let me know if you want the MBAM logs from scans done before I found your forum and instructions in the READ & RUN ME FIRST.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'd like to see the log from Hitman Pro please. :)
     
  5. gmspider

    gmspider Private E-2

    Good morning Krestrel13! I don't recall having been given the option to save a log to the desktop, I remember the scan coming up clean and returning to the green splash screen. The button options were Next and Close. I am sure I selected Next and I think the program closed out. I just don't recall the save log option. Do I run again?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can if you like, just to be thorough. All your other logs are clean. :)
     
  7. gmspider

    gmspider Private E-2

    My bad re Hitman log. Ran it again and have attached the log. If all is clean and no further action is needed, are there any "restart" protocols other than enabling UAC, McAfee firewall, and McAfee AV protection, and reboot? I will probably keep Malwarebytes. You think I should I buy the full version? What about other downloaded tools. Save or discard? Thanks for taking time to help.
    gm
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will post final steps further down.

    It wouldn't be a bad idea. Your choice though!

    Final steps will cover these.
    Most welcome, safe surfing! :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds