win32.banker.FS

Discussion in 'Malware Help (A Specialist Will Reply)' started by iamadam, Dec 28, 2008.

  1. iamadam

    iamadam Private E-2

    Hello! I've followed the removal steps in this forum. Everything feels OK for the time being but can you check to see if my computer's clean?

    I originally got a popup saying that I had a win32.banker.FS. The desktop wallpaper also changed to a bunch of coloured squares and rectangles. I was unable to change the wallpaper through display properties or access the task manager. It also opened up lots of popups if my computer was connected to the internet.

    Now I am able to access the task manager and display properties. However, during startup I am receiving the following messages:

    "Runner file name (Update From HP.exe) lacks a '-' (the app id separator)"
    "Runner file name (LogitechDesktopMessenger.exe) lacks a '-' (the app id separator)"

    I've attached the required log files. Thanks for your time!

    -Adam
     

    Attached Files:

  2. iamadam

    iamadam Private E-2

    Attached is the fourth log. Thanks.
     

    Attached Files:

  3. iamadam

    iamadam Private E-2

    I've also noticed just now that windows can't find msconfig. Does this mean i'm still infected?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a few item left to deal with:

    If you haven't already, please disable the Guest account in User accounts.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):


    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\1197113067.dat

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and tell me how things are running.
     
  5. iamadam

    iamadam Private E-2

    Thanks for your response. I've attached the MGTools log as requested. Everything seems to be running fine. However on startup, I get a series of error messages like the one I've attached to this post as well.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean....but do this:

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now tell me exactly what the error messages say as that screen shot is not telling me anything (unless it is referring to your Net frameswork files.) Your hp updater and the desktop messenger can be deleted (uninstalled).
     
  7. iamadam

    iamadam Private E-2

    I ran ATF Cleaner as instructed. I think the error message was a result of the HP Photosmart Premier application that was installed. I disabled the process from the startup menu and it seems to be doing fine for now.

    Thank you for your help. Greatly appreciate it! :)
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds