Trojan Win32/MedfosX & Malware PackerGEN

Discussion in 'Malware Help (A Specialist Will Reply)' started by DigiOops2, Jul 17, 2013.

  1. DigiOops2

    DigiOops2 Private E-2

    Hi Guys! I'm hoping you can help. I accidentally downloaded a virus yesterday (Tuesday) morning, and it turned out to be a Trojan and who all knows what. I received a phishing email from Dun & Bradstreet that looked legit. Shame on me, I know. I've gone through the FAQ, and have attached the logs. I think that's all of them? I also did delete the problems in RogueKiller, because I didn't see the part that told me not to. However, I did nothing in TDSSKiller, Hitman Pro, or the MGLogs. Malwarebytes didn't find anything, but MS Security Essentials does (the Trojan). Any help you could give would be much appreciated!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have Hitman fix what it found. Now please attach the log for MGTools - C:\MGLogs.zip.
     
  3. DigiOops2

    DigiOops2 Private E-2

    Thanks for getting back to me so quickly! I'm actually out of the office until Monday (bad vacation timing), but will do these first. Sorry about the missing log! Do you want the first log, or run it again after I have Hitman fix the issues and add that log?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fix what Hitman found and then rescan with Hitman and attach that log. Don't forget to attach the MGLogs.zip.
     
  5. DigiOops2

    DigiOops2 Private E-2

    Thanks! I've attached the HitMan log, and it only had one thing on it this time. I've also attached the MGTools log. Weird thing when I turned my computer on this morning- instead of booting like normal, it took me to a page where I had to boot from the last known good version? I think. I skimmed the page, but can re-start and get more info if needed. Thanks again!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\WINDOWS\Tasks\At4.job
    C:\WINDOWS\Tasks\At5.job
    C:\WINDOWS\Tasks\At6.job
    C:\WINDOWS\Tasks\At7.job
    C:\WINDOWS\Tasks\At8.job

    Now tell me what issues remain, if any.
     
  7. DigiOops2

    DigiOops2 Private E-2

    Thanks Tim! I re-ran Malware, Rogue Killer, and TDSSKiller. Rogue still has some issues, I'm not sure if it should or not. I've attached the log, just in case. I'm also going to restart the computer, then let it run MS Security Essentials overnight. If there are any issues, I'll let you know in the morning when I come back in. Seriously, you guys are my heroes for the week!
     

    Attached Files:

  8. DigiOops2

    DigiOops2 Private E-2

    Morning! So, I ran the MS Security Essentials, but it said I was clean. However, my computer is still slower than normal. Also, when I turn the machine off, it has an issue. I either have to wait or force close explorer.exe before I can turn my machine off. From what I understand (and I may be wrong), I should only have 1 of those on my computer. However, a search of the computer shows I have 2. As I've never had to wait for that to close before I got the virus, I'm thinking they're related. I've attached a photo of what the search found, and where. Any more help is greatly appreciated!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your RogueKiller log is clean.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip.
     
  10. DigiOops2

    DigiOops2 Private E-2

    Thanks Tim! I wasn't sure. I've attached the new MGTools log.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean, however you need to run CCleaner to clean out your temp folders.

    Any issues that remain should be addressed in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

     
    Last edited: Jul 23, 2013

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds