success or not?

Discussion in 'Malware Help (A Specialist Will Reply)' started by denarfra, Sep 15, 2007.

  1. denarfra

    denarfra Private E-2

    i have had troubles with malware....it came to my attention after my internet provider alerted us to our e-mail address being used for spamming..i scanned my pc with nortons 360, and spyboot and found no infection....the problem still persisted and so i followed the read and run page.....some of the scans found infections. i also tried alternative scans which varied in theie success

    here are the logs for avg, bit defender and pando
     

    Attached Files:

  2. denarfra

    denarfra Private E-2

    here is bitdefender, hijack this, kaspersky...other scans i ran a-squared counterspy were negative but i couldnt generate a report...
     

    Attached Files:

  3. denarfra

    denarfra Private E-2

    finally i scanned with spy doctor which identified 37 infections...i purchased the program...ran it and found only 33 infections..attached are the two logs...

    have i cleaned my pc of the spyware and/or trojans...thanks for your help
     

    Attached Files:

  4. denarfra

    denarfra Private E-2

    sorry here are the runkey and newfile logs
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I see the below in your HJT log:


    O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\cmd.exe /c cd /d C:\ComboFix\ & Combobatch.bat

    Were you running ComboFix while using HijackThis to get a log?
    Do you have the log from ComboFix? If so, please attach it.


    Per the READ & RUN ME, Spybot's Teatimer must not be run. Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Also uninstall the CounterSpy trial program now!

    Also please perform step 2 of the READ ME properly now!
     
    Last edited: Sep 15, 2007
  6. denarfra

    denarfra Private E-2

    i am not sure if i was running combofix when running hijack this.....

    i repated the steps in read and run making sure i opened the hidden files....
    i have appended the logs.....
    all scans look good indicating no infections except for 1 item in activescan...
    thanking you in advance....
     

    Attached Files:

  7. denarfra

    denarfra Private E-2

    here are more logs.....
     

    Attached Files:

  8. denarfra

    denarfra Private E-2

    i also ran two extra scans.......
    here is the log for one i ran spydoctor which found no infections but could not get a report saved as txt file...
     

    Attached Files:

    Last edited: Sep 18, 2007
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below in your HJT log:

    O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\cmd.exe /c cd /d C:\ComboFix\ & Combobatch.bat


    What is this that you are running?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have a feeling that you did something like clicked your mouse in the ComboFix window while it was still running and you cause it to stall. And that the O4 line I'm mentioning is due to this.

    Please attach the C:\ComboFix.txt log file to your next message.



    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old Sun Java version.
    Java 2 Runtime Environment, SE v1.4.2

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\cmd.exe /c cd /d C:\ComboFix\ & Combobatch.bat

    After clicking Fix, exit HJT.
    Now use Windows Explorer to delete the below folder
    :
    C:\Documents and Settings\Owner\Application Data\Sunbelt Software

    Now attach a new log from HijackThis.

    Make sure you tell me how things are working now! If you are having malwar problems, please describe them in detail.
     
    Last edited: Sep 18, 2007
  11. denarfra

    denarfra Private E-2

    I have attached the combofix log as requested......
    I also have attached he hjt log after following the directions outlined.....
    should i reinstall java

    I never noticed any problems on my lap-top....trojans were found on my lap-top durinf scanning which was precipitated with problems on my desktop...

    the problems on my desktop appear to be related to my e-mail...according to my intrernet provider our e-mail address was being used to send spam....i scanned my desk top with kaspersky which found a trojan (win32....). I looked up your guide for malware removal....first starting on my laptop....now i will try it on the desk top

    again thanks for your help.....
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only talk about one PC in a thread.

    Whatever PC we are working on in this thread appears to be clean based on the logs.

    No you don't need to reinstall Java because you already have the correct version installed. We uninstalled an old version which should not have been installed.


    Since this PC appears to be clean and if you are not having any other malware problems with it, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds