rootkits or trojans?

Discussion in 'Malware Help (A Specialist Will Reply)' started by McFeist, Jun 22, 2009.

  1. McFeist

    McFeist Private E-2

    Hello, Avast has been detecting some bad stuff on my computer for the past couple of weeks during both routine scans and on startup scans with the following files: Win32Trojan-gen, Win32:RustNT, and Win32Rootkit-gen. Iin addition, Spybot detected Virtumonde.sdn and PWS.Small.bs. So I found this forum and have followed all the steps (I think) under Read and Run Me First.

    Of note, my computer is functioning normally at this point and has never shown any obvious signs of infection. As of right now, Avast and Spybot are not finding anything after going through Read and Run Me.

    I would greatly appreciate any help in cleaning my computer of these infections that may still be lurking. I'm trying to avoid reformatting the hard drive if possible. I am attaching the log files as instructed.

    Thank you so much.
     
  2. McFeist

    McFeist Private E-2

    Woops, here are the attachments. The last one to follow in a reply.
     

    Attached Files:

  3. McFeist

    McFeist Private E-2

    And the last attachment...
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome, McFeist!

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, McFeist


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up your Desktop immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.

    An observation - Ad-Aware is not as effective as SUPERAntiSpyware and Malwarebytes that we had you install. So we suggest that you uninstall Ad-Aware (unless you purchased it) to avoid wasting any system resources on it.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.


    Step 3:
    You have a left-over service from Norton. Please run the below, re-boot, then run it again.
    Norton Removal Tool (SymNRT) 2009.0.5.26


    Step 4:
    There is an update to SUPERAntiSpyware available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.

    Step 5:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 6:
    Now run a new full scan of your system with SAS

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • New updated SASlog.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  6. McFeist

    McFeist Private E-2

    Thank you. New logs are attached.

    I took your advice and cleaned up the Desktop (still have work to do on it) and removed Ad-Aware and the Spybot file you mentioned.

    I did install some software a few days ago before this was posted; my apologies. I installed IE 8 and Identity Finder Home Edition, and I had to re-install my firewall right after the first scanning session; for some reason I wasn't able to re-enable it, but now it is fine.

    I had no problems running scans, and my computer seems to be doing fine.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi!

    No harm done this time because you had nothing serious - we caution against this to prevent having to deal also with partial downloads, corrupted or broken applications.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    If you get a message that the fix was successful, then:

    Using Windows Explorer - navigate to and delete:
    C:\Program Files\Lavasoft

    *Your logs look good! It is time to do our final steps .
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  8. McFeist

    McFeist Private E-2

    Thank you so much. Everything worked in those last steps just as it was supposed to. Bless you for your help and taking the time to look at all those logs. This was a very interesting process; I am just so grateful that I don't even have the words to express it.

    Do you accept donations? I was trying to figure that out by looking around the site, but I can't find information on how to donate.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're Welcome!

    Perhaps you would like to purchase something from JINX to display your "geekiness". ;)

    If not - your "Thanks!" is quite enough!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds