Win32.TrojanDropper.Small & Hijack This Review

Discussion in 'Malware Help (A Specialist Will Reply)' started by solidesign, Mar 29, 2009.

  1. solidesign

    solidesign Private E-2

    I spent a whole night going through all the instructions on the "Do this first Post." I have actually used it quite religiously to remove virus's in the past from family and friend's computers never thinking I would need it for mine because I had been so good about already having everything in place to keep that stuff out. However last night I got a virus that wouldn't let me start a lot of the programs that were listed to run first. The only one that got up and running actually was "Combofix.exe" AVG and Ad-Aware saw them and removed the "autostart" part of the worm/trojan but couldn't get at the main issue which Combofix said was a rootkey issue.

    Anyway. I just wanted to post a "HijackThis.log"/Mglogs.zip from both programs to make sure I got everything.

    Could someone please let me know if for one I'm posting this correctly (I apparently don't have permissions to "reply" to anyone's existing thread and therefore had to start my own) and whether I have gotten all of the bad stuff off my computer.

    Thanks Sincerely Scott
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    HJT is embedded in the MGLogs.zip..so unneccesary to attach it. What we ask you to attach is:
    SAS
    MBAM
    Combo
     
  3. solidesign

    solidesign Private E-2

    Well shucks,
    I actually embedded the Combo Fix log into the zip of the MGlogs.zip
    so I guess all i need to put in there is the SAS (I'm assuming thats the superantispyware log, and the malwarebites log)

    I have since erased those because I have since run those again, and a few other spyware removal tools that were on the list, and I have not found or seen any issues, however I am running windows xp sp3 on my Intel Dual Core Mac, and I've found that ever since the original autostart and trojan was noticed after going to a site proclaiming to have the last episode of Battlestar Galactica available to watch online gave me these virus (which my previous firewall (another program on the list from major geeks "do this before" under the malware removal thread) didn't catch... I think it was sy... something. I'm in my mac right now so i can't see the names of all of these programs off hand. Anyway I'll have to do those two over again... The SAS and the MBAM. SAS was taking too long as I have 4 internal hard drives, and 5 external. Most are filled with photos, music, and movies. So I had it running for over 24 hours and it still wasn't done. And since I had run every other software on the list and at this point they were all coming up negative on any bad stuff...I stopped it. It was having a really slow time with my *.NEF files (nikon raw files). I hadn't seen any virus's on any of my PC drives for the first part of the scan so maybe I can just send you the unfinished log for it. As for the MBAM I might still have that on the PC partition. I'll look and see what we come up with. Is there any way though to do a partial on what I have sent or is this sort of a "scripted thing." That runs through all of those logs automatically?

    Thanks again for your response. I am very grateful for this site. It has helped me numerous amounts of time.

    P.s. Not a subject for this thread but I just thought you might know of a good program free or otherwise that would take Video_TS folders full of what is in them and convert that to one avi file (per folder) in a batch sequence?

    p.s.s. I'll try to find SAS and MBAM when I log back into my pc and I'll upload those hopefully by tonight.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system.

    You can clean up this by deleting it:
    c:\windows\S3E692A80.tmp

    If SAS or MBAM come up with something, let me know.
     
  5. solidesign

    solidesign Private E-2

    Thanks very much again. I am back in pc world windows xp world to be exact.
    Here are my two logs MBAM and SAS (both are pretty short and pretty much say nothing is on there) I'm redoing the SAS but It's gonna probably take two days to scan everything.

    The last one just scanned my two drives I start up with..

    sincerely scott
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds