Trojan horse Dropper.Generic_c.MMI Help please i am also infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by the_fuzz, Aug 5, 2012.

  1. the_fuzz

    the_fuzz Private E-2

    Hi guys,

    I am new to this forum, but have been reading through a few posts where you have successfully helped to rid the virus that i have just been infected with.

    I have Windows 7 Home Premium 64 bit.
    AVG has found the Services.exe file to be infected.

    Please please can someone help me to get rid of this nasty virus so i can get back to some Diablo 3 :)

    I have downloaded and run the FRST64 in Recovery Console. Attached are the Search.txt (from searching for Services.exe)
    FRST.txt (from scan)


    I hope someone can help me.

    Many thanks

    Fuzz
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    --------------

    You must now follow these procedures to dig a bit deeper.

    READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:

  3. the_fuzz

    the_fuzz Private E-2

    Hi Kestrel13!,

    Many thanks for your reply.

    I have run FRST64 again from the Recovery Console and attached the
    created file fixlog.txt.

    I will go through and thoroughly read the Malware Removal pages now.


    Fingers crossed you can give me the "all clear now"

    Thanks again, i wouldn't have had a clue what to do nowadays about a virus of this kind, computers are far too complex. I grew up in the days of DOS and Windows 3.1 and 640k base memory lol

    Right, time to look at these cleanup and scan tools on your pages.

    Cheers again

    Fuzz
     

    Attached Files:

  4. the_fuzz

    the_fuzz Private E-2

    Please find attached Logs from the various tools.

    To me they look clean, but i also accept i am a noob and know nothing.

    Many thanks for your help.


    Fuzz
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:
    • [ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\oem\AppData\Local\{37aca053-6dc2-21a4-b9ff-fc9a2b8fc498}\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.
    Now run FRST like you did the first time - no fix, just a scan and attach the log.
     
  6. the_fuzz

    the_fuzz Private E-2

    Thanks again for your continuing help.

    Attached are the logs from Roguekiller (after selecting delete file as requested).
    and from running FRST scan again after reboot to Recovery Console.


    Many Thanks

    Fuzz
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Rogue Killer, just a scan - no fix and attach log.
     
  8. the_fuzz

    the_fuzz Private E-2

    Hi Kestrel,

    Roguekiller Scan rerun today, log attached.

    Thanks

    Fuzz
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything running well? Ready for final steps? :)
     
  10. the_fuzz

    the_fuzz Private E-2

    Hi Kestrel,

    PC seems to be running fine. no pop-ups anymore from AVG.
    I braved the internet and seems to be running fine.
    AVG full system scan today says "No Infections" :)

    One thing, i'm using AVG free edition. Would you recommend i switch to something else or is it sufficient ?
    Ive tried Norton before on PC and laptop and seems to slow everything down and rip you off with subscription prices.

    Yes, i am ready for any final steps. Whatever it takes.

    Many thanks

    Fuzz
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I use avast free edition.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds