PC infected after opening DHL Email

Discussion in 'Malware Help (A Specialist Will Reply)' started by gcpower, Mar 9, 2010.

  1. gcpower

    gcpower Private E-2

    Good evenning and thnak you for the comprehensive set of tools. I have followed the thread as directed.

    The problem commenced about ten day s ago when an email from DHL was received saying they wanted to deliver a parcel and needed my address. Unfortunately, the anti virus program as not operating and well out of date.

    I received countless messages from vista antivirus saying the comuter was infected. I was unable to use my browser. I created another user and was able to proceed. I have been able to run all procedures. The mgtools did not run as instructed. I re-downloaded it and copied it to the root and it ran automatically when started.

    I am including the logs in two posts, as requested. I would really appreciate your help. Regards Graham
     

    Attached Files:

  2. gcpower

    gcpower Private E-2

    Second set of logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. You do need to put ComboFix directly on your desktop, not here:
    Running from: c:\users\Grahamc\Downloads\ComboFix.exe

    What issues are you still having?
     
  4. gcpower

    gcpower Private E-2

    Thank you for your very quick response. I have now run comboFix from the desktop, as instructed and I am posting a fresh log. The only problem I am now experiencing is a report from Avira identifying a trojan. This has now been quarantined. I will enclose a screen shot of the report screen shortly.
    Best wishes
    Graham
     
  5. gcpower

    gcpower Private E-2

    Not sure the combofix log was attached. I enclose it, just in case.
    Graham
     
  6. gcpower

    gcpower Private E-2

    I am afraid I am still experiencing problems. I logged on to the original account and IE could not connect. I found that a proxy had been created, which i took off. Automatically detect settings was unticked, so I ticked that. I was then able to connect to the internet. I tried to start Firefox from the desktop icon and was asked which file should be associated. I enclose a screen shot. I then tried to download a new copy of Firefox. I selected run, rather than saver and was presented with the message about association. I redownloaded and selected save rather than run. This seemed to load. I closed it then tried to restart via the desktop icon - same message. I deleted the icon and tried to recreate. I then had a rundll error and a further error message. All screenshots are enclosed, together with the report on the trojan.
    Regards
    Graham
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't attach a new ComboFix log. Are you trying to tell me that no exe files will run? Plus, I cant read what it is Avira is complaining about. Could you type it out for me on your next reply?
     
  8. gcpower

    gcpower Private E-2

    Sorry that I did not post the updated combofix log in my last update. I now enclose it. The report from avira which you could not read showed TR/Spy.Zbot.afhn found on the scan. I have now quarantined this.

    For the main user graham I cannot run any exe files. I checked from the desktop shortcuts, all programs and running through the program folders. None will run. This was the logged on user when the first problem hit. The other existing user amanda and the new user grahamc are unaffected and all programs operate correctly.

    I hope that answers your query.
    Thanks for your continued help
    Kind regards Graham
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Three things to try on that messed up account:
    1) Download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    2) http://www.dougknox.com/xp/file_assoc.htm --> scroll down to #9 ( not sure if this works in Vista)

    3) copy all your personal settings and data into the new user account and delete the corrupted account.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds