Trojan issue Pleas see attached logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by enttboy1, May 1, 2009.

  1. enttboy1

    enttboy1 Private E-2

    Please see attached logs. Trojans found. Appreciate any help you can give so I can make sure there are not any more infections left.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like the scans removed your malware but I do see some issues.

    You have Online Armor and McAfee firewalls installed. As stated in the READ & RUN ME, you must never do this. You need to uninstall one of these immediately.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Do you know what the below file is for? This is not a place that a .bat file would be expected.
    Code:
    2008-10-20 23:19 10596 ----a-w c:\program files\Common Files\sahonez.bat
     
  3. enttboy1

    enttboy1 Private E-2

    Although I do not run Online Armor and have had it disabled, I have removed it from the system as you have asked.

    I have also removed Windows Messenger.

    I however do not know what the batch file is for. I also do find it quite odd to see a batch file in the common files. I have researched the file name but cannot find out anything about it.

    Any ideas as what I should do. I could setup a restore point and then remove it. and if I see problems and I can then go back??

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it wasn't! You can see the service for it running in your last logs. You cannot so simply disable things like this and it is not an adequate approach as security center and other tools still see both of them installed and they are fighting for control in security center and literally hundreds a registry keys are still inplace unless uninstalled.

    Rename it to sahonez.txt then attach a copy of this txt file here. Reboot your system and see if you have any problems or get any error messages about not finding the original file name.
     
  5. enttboy1

    enttboy1 Private E-2

    Thanks Chaslang. I though just disabling OA would be fine. Learn something new everyday.

    Please see attached txt file. On reboot there were no problems or errors on finding the file.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Okay you should delete this file because it was not a batch file anyway.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds