Thank you!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maegi, Mar 11, 2010.

  1. Maegi

    Maegi Private E-2

    Good afternoon! I wanted to take a moment to thank you for the great instructions on how to get rid of malware from my computer. I am not computer savvy, but I can follow directions and it seems to have worked! :) However, before I do a toggle of my system restore points, how do I know that all trojans, etc are removed?

    Again, I appreciate your help more than you could know!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the requested logs so we can review them and see if you are clean.

    Attach:
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGLogs.zip
     
  3. Maegi

    Maegi Private E-2

    Thanks for taking the time to look at these! I didn't know if there was an easier way, and I appreciate your help! The other logs will be coming in a minute.
     

    Attached Files:

  4. Maegi

    Maegi Private E-2

    Last, but not least!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo said it fixed a system file, but I want to be sure, so:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Now:
    Click on the following link and use the below steps to scan a file: Virustotal
    Click the Browse... button.
    Navigate to the file c:\windows\8088984.dat

    • Where c:\windows\8088984.dat is the actual file to be scanned.
    • Do the same for this file: c:\windows\system32\stu2.exe


    Tell me the results.
     
  6. Maegi

    Maegi Private E-2

    for the c:\windows\8088984.dat I got the following:
    Antivirus Version Last Update Result
    a-squared 4.5.0.50 2010.03.12 -
    AhnLab-V3 5.0.0.2 2010.03.12 -
    AntiVir 8.2.1.180 2010.03.12 -
    Antiy-AVL 2.0.3.7 2010.03.12 -
    Authentium 5.2.0.5 2010.03.12 -
    Avast 4.8.1351.0 2010.03.12 -
    Avast5 5.0.332.0 2010.03.12 -
    AVG 9.0.0.787 2010.03.12 -
    BitDefender 7.2 2010.03.12 -
    CAT-QuickHeal 10.00 2010.03.12 -
    ClamAV 0.96.0.0-git 2010.03.12 -
    Comodo 4239 2010.03.12 -
    DrWeb 5.0.1.12222 2010.03.12 -
    eSafe 7.0.17.0 2010.03.11 -
    eTrust-Vet 35.2.7357 2010.03.12 -
    F-Prot 4.5.1.85 2010.03.12 -
    F-Secure 9.0.15370.0 2010.03.12 -
    Fortinet 4.0.14.0 2010.03.09 -
    GData 19 2010.03.12 -
    Ikarus T3.1.1.80.0 2010.03.12 -
    Jiangmin 13.0.900 2010.03.12 -
    K7AntiVirus 7.10.996 2010.03.12 -
    Kaspersky 7.0.0.125 2010.03.12 -
    McAfee 5918 2010.03.12 -
    McAfee+Artemis 5918 2010.03.12 -
    McAfee-GW-Edition 6.8.5 2010.03.12 -
    Microsoft 1.5502 2010.03.12 -
    NOD32 4940 2010.03.12 -
    Norman 6.04.08 2010.03.12 -
    nProtect 2009.1.8.0 2010.03.12 -
    Panda 10.0.2.2 2010.03.11 -
    PCTools 7.0.3.5 2010.03.12 -
    Prevx 3.0 2010.03.12 -
    Rising 22.38.04.03 2010.03.12 -
    Sophos 4.51.0 2010.03.12 -
    Sunbelt 5842 2010.03.12 -
    Symantec 20091.2.0.41 2010.03.12 -
    TheHacker 6.5.2.0.232 2010.03.12 -
    TrendMicro 9.120.0.1004 2010.03.12 -
    VBA32 3.12.12.2 2010.03.12 -
    ViRobot 2010.3.12.2224 2010.03.12 -
    VirusBuster 5.0.27.0 2010.03.12 -

    Additional information
    File size: 230 bytes
    MD5...: d14e60120aca673adfb390bfdd65d8e3
    SHA1..: 92f1715731f16925583ed4c21658777a78ac6aba
    SHA256: 9d20803277af829f25d2283b0b84f7d74955bfbeccd3802e6d10dea762abd15a
    ssdeep: 6:0uGeijYes0Zl3ZHpxaZZMmBJJSZDZLgkst3ZHpP:0fvs0DpHpxaM+AFLZ+pHpP<BR>
    PEiD..: -
    PEInfo: -
    RDS...: NSRL Reference Data Set<BR>-
    pdfid.: -
    trid..: Unknown!
    sigcheck:<BR>publisher....: n/a<BR>copyright....: n/a<BR>product......: n/a<BR>description..: n/a<BR>original name: n/a<BR>internal name: n/a<BR>file version.: n/a<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>


    For the c:\windows\system32\stu32 file I got the following:
    MD5: 39b1ffb03c2296323832acbae50d2aff
    First received: 2007.11.19 23:54:56 UTC
    Date: 2010.03.10 23:26:42 UTC [+1D]
    Results: 0/42
    Permalink: analisis/5b5d71718108e132d10bafb0c217f469a1e3cc13f79ff8d9cbe3bf4918aff7b7-1268263602

    I have also attached the requested log, but never got any commands to enter delete.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Apparently those files are legit. What issues are you still having?
     
  8. Maegi

    Maegi Private E-2

    I don't believe I have any other problems. My IE is working fine, as well as my FF. Nothing is slow. A couple weeks ago my 19 month old hit a bunch of buttons on the computer, it started acting funny, the background changed, and at first I thought she was a genious who knew how to navigate the computer to change the background. I'm pretty sure in her keyboard banging she turned something off that allowed us to be "attacked." I quickly figured out that it was a trojan, did all of your steps, and I haven't had any other issues. :) I assumed that when all was clear my background would go back to what it was and I would know it was free and clear, but it didn't, so I wasn't sure how to tell if everything was gone.

    I sincerely appreciate all of your help. Your directions were clear, I was able to follow them, and it appears the computer is free of infections! YAY!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds