Still infected?

Discussion in 'Malware Help (A Specialist Will Reply)' started by mountainmama, Feb 10, 2011.

  1. mountainmama

    mountainmama Private E-2

    A couple of weeks ago, my firewall started giving me this message:

    Some of the firewall initialization files have been tampered with by an external source. These files have been restored to provide maximum security for your system. You are advised to run an Anti-Spyware product to make sure your system is clean from malware.

    It said that the affected file was C:\Program Files (X86)\PC Tools Firewall Plus\Networks.ini

    I noticed that this only happened when I logged in after my daughter had been logged in on her account. I also noticed that my computer had slowed down somewhat. Then a couple of days later I got an email from a contact saying that he had received a spam email from my Yahoo email address. I checked my sent folder, and it had sent spam emails to some of my other contacts too. I ran AVG and Malware Bytes scans, and they found nothing.

    I followed the instructions in READ & RUN ME FIRST (except for running Root Repeal since I'm running Windows 7), and it seemed to put everything back to normal. But today I got that message from my firewall again. Since I installed Intuit SiteBuilder yesterday, I reran everything. My logs are attached. Thanks in advance for your help!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds like you firewall is doing its job. I am not seeing any malware on your system. As far as your emails, you need to save those you know are not infected and delete all the rest. You also might try adding to you contact list this dummy address: aaa@aaa.com.

    What issues are you currently having?
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Additionally, you need to run both SAS and MBAM on your daughters account.
     
  4. mountainmama

    mountainmama Private E-2

    Thanks for taking a look at my logs. I'll run SAS and MBAM on her account. Should I post the logs when I'm done?

    The only problem I'm having right now is the message from my firewall popping up when I log in after my daughter has. And I forgot to mention this earlier, but I also keep getting an alert from my firewall saying that a new network named WORKGROUP has been detected and asking me to select a trust level. I've been choosing Untrusted until I see what's going on, since I don't have a home network anyway.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, attach any logs that show infections. Most home networks, if you have set one up with other computers in you home, use the workgroup name. If you have no other computers running, you should just keep doing as you are doing, though you may want to pursue that in the software forum.
     
  6. mountainmama

    mountainmama Private E-2

    I ran the SAS and MBAM scans on my daughter's account, and then on my husband's for good measure even though he rarely uses it. They found nothing. So I guess this means I'm good to go?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds