Please Read Logs - Thanks! *low priority*

Discussion in 'Malware Help (A Specialist Will Reply)' started by basstom1, Dec 27, 2008.

  1. basstom1

    basstom1 Private E-2

    Thanks so much for providing all this great info! My computer life would be in the toilet if it wasn't for you majorgeeks!

    My computer somehow got infected with all sorts of stuff, mainly Spywareguard 2008 and winscenter.exe. They were popping up every minute and a half, reinstalling themselves, draining resources, etc. Also, something was toggling my windows firewall and security settings. Also, other trojans and rootkits. I'm sure my logs will divulge everything I had. I run AVG8 and update and run Spybot every month. WinXP Media SP3.

    I put the low priority in the subject because I *believe* I'm in the clear..but just don't know for sure. I went through all the steps and now all symptoms are gone..AVG and Spybot both come up clean. I just wanted to know for sure. If what I had was a little less severe, I wouldn't waste your time. I just don't want to chance it. I would really appreciate it if you could let me know where I stand.

    Thanks again so much!
    Tom

    PS - Also, and info on properly cleaning an external hard drive and an SD card that were attached to my machine when I got infected would be greatly appreciated. Can't remember I if wrote any data to them when I was infected..srry.
     

    Attached Files:

  2. basstom1

    basstom1 Private E-2

    one more. Thanks!

    Lemme know if your ever in Long Beach. Sushi on me! Cheers.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, basstom1

    I'm currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    dr.m
    PS: Thanks for the invitation, but I prefer my fish cooked! :-D
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you having the scans look at the external drive when you run them?

    Let's do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. basstom1

    basstom1 Private E-2

    Tim,

    Thank you for helping me!! I am so grateful!
    I've done what you asked and will attach the logs. To answer you question, I have not run the scans on the external drive. I will do so, and report back to you with what I find.

    How does one run Combofix on the external drive? Do you simply copy the exe file to the root folder of the drive and run it from there?

    Thanks again!
    Tom
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will check your logs in the morning....but there is no need to run combo on the external...just jave SAS and MBAM include it in their scans.
     
  7. basstom1

    basstom1 Private E-2

    Tim,

    Not meaning to bump, just saw something...

    My laptop was closed and sleeping. I just opened it up and saw an AVG message (attached). Did something infected one of my system restores? That sucks. I noticed that AVG had not updated because something disabled my wireless connection. It was missing from the sys tray. It's usually there after I open the screen, just with a red "x" through it, not missing.

    Also, I've run both scans on my external drive and both came up clean. Do I need to run the scans exe file from the drive itself? or can I simply just tell the prog to scan that particular drive? in safe mode perhaps? sorry so many questions.

    Thanks again for your help!
    Cheers,
    Tom
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) basstom1

    A restore point could have been made while your machine was infected. This presents no problem at the present and will be fixed during the final cleanup instructions.

    MBAM should detect all drives when it scans...and with SAS --- just be sure to have the Scan Location boxes ticked for all drives. The scans should be run while in Normal Start-up Mode if malware doesn't prevent that.

    Tim should be reviewing your logs later this morning.

    dr.m
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You can also right-click whichever drive from My Computer and have MBAM scan that drive only.

    dr.m
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. Have you gone to "My Network Places" / view network connections and re-enabled the wireless connection?

    You can also try opening SAS / preferences / Repairs and see if you can repair your connection thru that method.

    In the meantime, If you are not having any other malware issues, then:

     
  11. basstom1

    basstom1 Private E-2

    :majorThanks Tim & Dr.Moriarty!!:major

    I truly appreciate your help and advice. I've completed all steps and will be purchasing both SAS and Malware Bytes. I can't thank you enough!

    If I have any questions, or if anything else pops up I will let you know.

    Thanks and cheers,
    Tom :wave
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds