Seriously?!?! Malware AGAIN!

Discussion in 'Malware Help (A Specialist Will Reply)' started by insan_art, Dec 29, 2010.

  1. insan_art

    insan_art Private First Class

    Aye! I was just here about two weeks ago with some sort of drive-by from Facebook. Today, got another one from a news site (trusted, or so I thought!). I'm quite disappointed about this - I just started using Avast and I'm not sure how confident I am with it at this point.

    Logs are attached. Had no problems with anything. Please check me out - I've been trying to back up my computer for months but I keep getting interrupted by moving, health issues, computer viruses, the holidays, etc. etc. There is no way I'm about to dump a huge load onto my terabyte external drive if something is infected!

    A couple questions... First, is there possibly a known vulnerability with the latest Java? (6.23) I ask because the tray icon popped up during today's attack and possibly the last one, too.

    Second, which free firewall do you suggest - I'm looking for the most lightweight one. I started to use Online Armor last year but discontinued using it due to a variety of problems and the fact that it was a huge resource hog.
     

    Attached Files:

  2. insan_art

    insan_art Private First Class

    Forgot to say.....THANKS in advance.

    And, MGlogs.zip is attached.

    Thanks again! :)
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh, so you were indeed. Hello again.
    No, I doubt it.
    I think this is something you could discuss in the software forum afterwards. Or you can read through the how to protect yourself from malware link at the end, in final steps for some suggestions.

    Now run this and then you must tell me how the machine is behaving.



    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. insan_art

    insan_art Private First Class

    Hello again Kestrel! Pleasure to be working with you again, though sorry it is on my own machine again! I do a lot of work on friends computers, so I am here fairly often...but, no matter how many infected computers I work on or how much I learn about internet safety, it still freaks me out (and angers me that viruses are SO prolific) when I get an attack on a personal machine.

    Anyways, ran TDSSKiller and rebooted as instructed - the log is attached. Things seem to be running quickly and I browsed around a few sites before coming here to reply - no redirects so far!

    I guess I'll post in the software forum about firewalls. I've read the recommended list several times - I wish there was more info provided about performance for each product. Hopefully the forum can help with that. :)

    Thanks!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So, I think that may have been an easy fix which was lucky for you. Things running sweet after what TDSSKiller found and removed?
     
  6. insan_art

    insan_art Private First Class

    Things seem ok. Was just watching some streaming tv and the stream was kind of choppy. I thought it might be because some virus crap might still be running in the background, but maybe it was just that particular site. Also, system seems to be processing more than it should be, but again, that could have been a result of the choppy video stream.

    :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  8. insan_art

    insan_art Private First Class

    Ran MBRCheck. I saved a log as you requested - when I went to upload it I found that another log (the one with the longer name) had already been saved and contains way more info. Both logs are attached, as I assume you might want the one with more info.

    Thanks!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, those logs are all good. You are now ready for final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds