One of my work terminals

Discussion in 'Malware Help (A Specialist Will Reply)' started by mdj1281, Feb 3, 2009.

  1. mdj1281

    mdj1281 Private E-2

    One of my terminals where I work became infected... or finally started to show that it was. Since I am the only one in the office under 40 they call me "the IT guy"... lucky me :(

    Whatever the files were are re-directing Firefox to a site that wants you to buy and install a "windows defender" looking program... First it opens with the security page telling you the site may not be secure and then re-directs, looks good too.

    When the window closes because "of an unexpected error" it has a submit information box to fill in e-mail etc that also looks like it is Firefox generated... but looking closely you can see it is a fake.

    I ran CCleaner, SUPERAnti Spyware, Spybot Search & destroy, Malwarebytes Anti-Malware, Combo Fix and MG Tools and followed the instructions in the thread located HERE

    Here are the logs...
     

    Attached Files:

  2. mdj1281

    mdj1281 Private E-2

    More logs... :major
     

    Attached Files:

  3. mdj1281

    mdj1281 Private E-2

    ...last one...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future, please only attach the logs requested in the instructions. You should not be attaching any of the individual logs from the C:\MGtools folder which we stated in the instructions. You should have only attach the C:\MGlogs.zip file which contains all of the logs from MGtools that we need.

    Your newfiles.txt log actually is incomplete which would mean that it did not run properly or you attached an intermediate log. Let's do the below and get a new log and see how things are working.

    Make sure you disable McAfee before doing the below.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6 <-- should have been uninstalled in step 1 of the READ ME


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.


    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds