webhost thinks my computer is infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by 95do, Feb 26, 2013.

  1. 95do

    95do Private E-2

    hi there

    I have couple websites i made and they got infected. My webhost told me to come here and go through this procedure of scanning my computer as they think my computer is infected.

    they think the site files have been infected on my website from Aug 2012 and that is actually when I created the sites and uploaded them. I scan my computer everyday with avast so i'm not sure what is going on.

    Can you please look at my logs and see if you see anything on my computer?

    Thank you very much
     

    Attached Files:

  2. 95do

    95do Private E-2

    here is the other tds file with the object detected(I wasn't sure which to upload)
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoW3i&dpid=SnapdoW3i&co=CA&userid=405f16b6-53d6-43c6-b41b-26103fa0e215&searchtype=ds&q={searchTerms}
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoW3i&dpid=SnapdoW3i&co=CA&userid=405f16b6-53d6-43c6-b41b-26103fa0e215&searchtype=ds&q={searchTerms}
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    After clicking Fix exit HJT.


    Delete this if it exists:

    C:\Users\creamsoda\AppData\Local\Temp\937F8BA0-61A3-4119-81A2-2D0504E74191.exe

    Re run TDSSKiller, attach latest log.

    How are things running.
     
  4. 95do

    95do Private E-2

    Hello , I did those steps , ran TDSkiller but it is not creating a log on the desktop like the others I attached. I tried to copy the log and paste it to a texfile but it doesn't allow an option for right click copy on the log.

    I don't see any option for manually creating the log?



    The computer has always run ok , I scan all the time with avast and malwarebytes and never get any alerts.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    TDSSkiller removed a rootkit. When you re run it, does it find anything like:
    now or not?
     
  6. 95do

    95do Private E-2

    Hi there when i run TDSSkiller now there are no threats found
     
  7. 95do

    95do Private E-2

    would this mean i am clean now? do you think i should change passwords for everything now?

    thanks for the help
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, changing your passwords wouldn't be a bad idea. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. 95do

    95do Private E-2

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I can't see everything listed there properly, you will have to attach a proper log, but I don't think there's anything there that should be deleted, no.
     
  11. 95do

    95do Private E-2

    oh today someone used my criedt card for $3000 so i had to contact company to cancel it , they said it was used on internet :( but it sounded like local charges like companies around my area. Do you think they got it from my intenet activites where i buy stuff from internet or they got it from local where i buy at gas station or something?

    Thanks
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You may want to take the extra precaution of backing up your personal data and files only and then doing a complete reformat and clean install. That is the only way to be 100% sure you are not having any issues with your security.

    You need to use a different computer and change all your online passwords. Then you need to contact your bank and all credit card accounts and just alert them to the fact that your personal info may have been compromised.
     
  13. 95do

    95do Private E-2


    Hi thanks again for the help. I was thinking I should do that as well. Now the question i have is I have 3 drives I use as storage (pictures, files etc) and then I have the C drive. So what would you recommend in this instance? format all the drives or only c drive?

    Thanks
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You only need to reformat drive C.

    You didn't attach the RogueKiller log as Kes asked.
     
  15. 95do

    95do Private E-2

    hi sorry here is another RogueKiller log from just now
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log is fine. You need to tell Kes if you are having any other issues.
     
  17. 95do

    95do Private E-2

    Hi , formated my C drive, then I reset my router and changed the password as i was hitting bandwidth limits very fast and never thought about maybe something to do with the router.

    I was wondering I saw this in the router security log should i worry about this? I downloaded the program Wireshark and did a log and there is a bunch of red lines ...but i'm not sure how to interpret them as i don't know what i'm doing lol, should i attach the log

    06/02/1936 20:53:11 **TCP FIN Scan** 192.168.2.5, 56069->> 72.21.91.121, 80 (from WAN Outbound)
    06/02/1936 20:45:45 **TCP FIN Scan** 103.246.148.192, 80->> 192.168.2.5, 55690 (from WAN Inbound)
    06/02/1936 20:45:45 **TCP FIN Scan** 103.246.148.160, 80->> 192.168.2.5, 55685 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 216.52.242.80, 80->> 192.168.2.5, 55625 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 184.31.63.139, 80->> 192.168.2.5, 55470 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 173.194.64.94, 80->> 192.168.2.5, 55444 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 74.125.226.91, 80->> 192.168.2.5, 55492 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 204.144.141.26, 80->> 192.168.2.5, 55679 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 204.246.169.6, 80->> 192.168.2.5, 55612 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 23.13.181.231, 80->> 192.168.2.5, 55604 (from WAN Inbound)
    06/02/1936 20:45:44 **TCP FIN Scan** 176.32.100.68, 80->> 192.168.2.5, 55586 (from WAN Inbound)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds