Quick Question

Discussion in 'Malware Help (A Specialist Will Reply)' started by jackyaz, Jun 9, 2008.

  1. jackyaz

    jackyaz Private E-2

    I had Virtumonde infect my system a few weeks ago, and was able to remove thanks to the excellent guys here. While i was doing a full system scan using Malwarebytes Anti-Malware, a text file was found in windows/system32 called clkcnt.txt. Can anyone tell me what this is? I've included the log of the scan
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. jackyaz

    jackyaz Private E-2

    Read and run me completed as requested. SAS turned up a file, which i think was deleted. However, after running CF, my google toolbar has vanished, cannot even see under view-> toolbars, but apparently is still installed :confused, i hope this can be fixed :)
     

    Attached Files:

  4. jackyaz

    jackyaz Private E-2

    MGLogs attached
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Humm...Combofix did not remove it. It is still showing in your add/remove programs. Your logs are clean...so let's do the final cleanup and then you can try uninstalling the toolbar and reinstalling.

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. jackyaz

    jackyaz Private E-2

    Thanks Tim, i have followed the steps. Hidden folder options didnt reset when i uninstalled combofix, but i know how to change this. Your tip for google toolbar worked, I have it back. Thanks for helping me with my computer again, you guys are great!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds