Author Topic: Help cleaning infected computer  (Read 14689 times)

0 Members and 1 Guest are viewing this topic.

wilky

  • Guest
Re: Help cleaning infected computer
« Reply #30 on: October 06, 2013, 08:46:16 PM »
So I should be able to "report as false positive" these items coming from windows/system32 and trying to access sites like http://jaxzone17.info/task/6/ or http://kaylith5.org/task/6/  ???
That doesn't sound quite right. I just had the computer disabled by changing properties of certain objects while we scan through the rootkit, that sure sounded like a virus to me.
the log is attached but the warnings are still happening.
thanks for your help and time

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help cleaning infected computer
« Reply #31 on: October 06, 2013, 09:05:02 PM »
I shall give my reply to you tomorow. Stay tuned.
If need, bump your topic.

wilky

  • Guest
Re: Help cleaning infected computer
« Reply #32 on: October 07, 2013, 07:50:29 PM »
bump, don't forget about me!!

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help cleaning infected computer
« Reply #33 on: October 08, 2013, 12:26:52 PM »
Hi,

Thanks for bumping.

I wanna re-check Gmer results with these two kernel tool.



Download TDSSKiller  and save it to your desktop

  Execute TDSSKiller.exe by doubleclicking on it.
Confirm "End user Licence Agreement" and "KSN Statement" dialog box by clicking on Accept button.
  •   Press Start Scan
  •   If Suspicious object is detected, the default action will be Skip, click on Continue.
  •   If Malicious objects are found, select Cure.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.


----- next -----




Please download Malwarebytes AntiRootkit and save it to your desktop.
http://www.malwarebytes.org/products/mbar/

Full instructions how to use MBAR
http://www.bleepingcomputer.com/virus-removal/how-to-use-malwarebytes-anti-rootkit

    Please note: This is a beta version so please be sure to read the disclaimer and note of it.

  • Unzip/unrar MBAR in a folder to your Desktop
  • Open the folder where the contents were unzipped to run mbar.exe

  • Click on Next > then on Update button to download fresh definitions.
  • When database updates click Next
  • In the following window ensure "Targets" scan for Drivers; Sectors; System are ticked. Then select "Scan button"

  • If an infection/s are found ensure "Create Restore Point" is checked, then select the "Cleanup Button" to remove threats.
    Or if you are sure any entries should not be kept, just untick them. A list of infected files will be listed.

  • The Clean up procedure will be Scheduled for process.
  • When complete pop-up will show you. Select the Yes button and the system should re-boot to complete the cleaning process.
>> Please attach the two following logs from the mbar folder:

system-log.txt
and
mbar-log-year-month-day (hour-minute-second).txt.

wilky

  • Guest
Re: Help cleaning infected computer
« Reply #34 on: October 08, 2013, 07:20:14 PM »
TDSSKiller found something and had to restart to cure. When it restarted, it asked to scan again, so I did. That's why there are two logs for TDSSKiller.
thanks for your help

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help cleaning infected computer
« Reply #35 on: October 08, 2013, 07:31:08 PM »
Nice work. We shall deploy an deeper TDSSKiller check:




  • Re-run TDSSKiller.exe and click on Change parametres.
  • Under Additional options check the boxes next to:
    - Verify Driver Digital Signature;
    - Detect TDLFS file system
    - Use KSN to scan objects
  • Click OK, and then click Start Scan button.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • Click the Report button and attach the contents of it into your next reply
Note:It will also create a log in the C:\ directory.

wilky

  • Guest
Re: Help cleaning infected computer
« Reply #36 on: October 08, 2013, 07:53:20 PM »
log attached, didn't find anymore.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help cleaning infected computer
« Reply #37 on: October 08, 2013, 07:58:23 PM »
Will you re-run Gmer and create fresh Gmer1.txt log?


wilky

  • Guest
Re: Help cleaning infected computer
« Reply #38 on: October 08, 2013, 08:39:04 PM »
log is attached.
thanks

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help cleaning infected computer
« Reply #39 on: October 08, 2013, 08:48:18 PM »
Is there any improvements?

wilky

  • Guest
Re: Help cleaning infected computer
« Reply #40 on: October 08, 2013, 09:06:40 PM »
Yes indeed. I think our work here is finished. The TDSSKiller found the lurking suspect.
I thank you for your help, it is much appreciated.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Help cleaning infected computer
« Reply #41 on: October 09, 2013, 12:29:47 AM »
Although everything looks good, I would like to re-check & examine MBR myself if I may.



Please download aswMBR and save it to your desktop.

Double click aswMBR.exe to start the tool.
  • Select No if prompted to download the Avast database.
    Under AV Scan: from "QuickScan" switch to "(none)" option.

     
  • Click Scan
     
  • Upon completion of the scan ( Scan finished successfully ) click Save log and save it to your desktop, and post that log in your next reply for review.
    Note: do NOT attempt any Fix yet.

     
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well. Or you may upload MBR to http://www.wikisend.com.