Please make sure I have goten the virus off

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nightowl_80, Jul 21, 2011.

  1. nightowl_80

    nightowl_80 Private E-2

    I am fixing my mother's computer and everytime she turns it on it tells us that STService.exe has stopped working. attached are all of the logs.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hi, I will review your logs. Please be patient as there is a lot of information to review :)
     
  3. thisisu

    thisisu Malware Consultant

    Uninstall the following from Add/Remove Programs:
    • Dogpile Bundle Toolbar
    • Java(TM) 6 Update 4
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7
    • Java(TM) SE Runtime Environment 6
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  4. nightowl_80

    nightowl_80 Private E-2

    Here are the reports as requested
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    Please do this step again:

     
    Last edited by a moderator: Jul 22, 2011
  6. nightowl_80

    nightowl_80 Private E-2

    Here are the files that are requested.
     

    Attached Files:

  7. thisisu

    thisisu Malware Consultant

    Thank you, evaluating now.
     
  8. thisisu

    thisisu Malware Consultant

    Please Disable Spybot's TeaTimer again - http://forums.majorgeeks.com/showthread.php?t=103692
    Don't re-enable it until requested!

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    This will automatically update all the logs in MGlogs.zip!
    Make sure you click "Accept" on the License Agreement by HiJackThis!/analyse.exe twice (yes twice).

    What malware problems (if any) are you still having?
    Answer this question and attach the below logs:

    • C:\MGlogs.zip
     
  9. nightowl_80

    nightowl_80 Private E-2

    I am still getting the ST service error when i boot up the computer. Here are the files as requested.
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    nightowl_80,

    Your logs are clean

    The message you are still receiving is not due to malware, it is software related. You can try our Software forums for additional help on this matter.

    Before you go though, you may want to read this: Solved: ST Service.exe ,View post #12
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds