Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: MicroSoft Windows Malicious Software Removal tool  (Read 6701 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

    Topic Starter
  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
MicroSoft Windows Malicious Software Removal tool
« on: May 15, 2008, 06:28:03 PM »
I just dl'd this up-date and shortly afterward I got a message stating that it had found and removed Trojan Downloader:Win32/Zlob. I can't understand how this could have got in considering all the protections I have in place. I have Avast, Windows firewall, Windows Defender, Threatfire, Spybot S&D and Spywareblaster and Ad-Aware. Could this be a case of false positives?
Windows 8 and Windows 10 dual boot with two SSD's

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #1 on: May 15, 2008, 06:32:47 PM »
Possible. Don't clean anything....

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
Post SUPERAntiSpyware log.

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.

SuperDave

    Topic Starter
  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #2 on: May 16, 2008, 04:32:18 PM »
Too late. The aformentioned program already removed it but I'll run the other checks anyway. Be right back.
Windows 8 and Windows 10 dual boot with two SSD's

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #3 on: May 16, 2008, 06:58:23 PM »
Smart enough :)

SuperDave

    Topic Starter
  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #4 on: May 16, 2008, 07:41:15 PM »
After an almost 3 hrs. scan I came up with no logs. When I re-opened the program, there were no logs showing. There were 16 items fixed. 14 were adware and tracking cookies. I'll continue on with the other scans
Windows 8 and Windows 10 dual boot with two SSD's

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #5 on: May 16, 2008, 07:43:39 PM »
Fair enough :)

SuperDave

    Topic Starter
  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #6 on: May 16, 2008, 09:28:21 PM »
Malwarebytes' Anti-Malware 1.12
Database version: 755

Scan type: Full Scan (C:\|E:\|F:\|G:\|)
Objects scanned: 113766
Time elapsed: 31 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Ares Gold (Adware.WhenUSave) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP601\A0040726.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP602\A0041031.exe (Rogue.VirusHeat) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP602\A0041032.Dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP603\A0041172.Dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP603\A0041173.exe (Rogue.VirusHeat) -> Quarantined and deleted successfully.
C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
Windows 8 and Windows 10 dual boot with two SSD's

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #7 on: May 16, 2008, 09:44:47 PM »
Keep going :)

SuperDave

    Topic Starter
  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #8 on: May 17, 2008, 01:36:56 PM »
Here's the hijack log. It looks good to my inexperienced but learning eyes. I think the only ones I need to fix are # 20 and #23 Service: Ad-aware- no file

[recovering space - attachment deleted by admin]
Windows 8 and Windows 10 dual boot with two SSD's

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #9 on: May 17, 2008, 01:44:51 PM »
Checkmark:
- O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
- O23 - Service: Ad-Aware 2007 Service (aawservice) - Unknown owner - (no file)
Click "Fix checked" button.

Other, then that the log is clean.

Don't forget to reset System Restore.

SuperDave

    Topic Starter
  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #10 on: May 17, 2008, 01:49:14 PM »
Thanks, Broni. I suppose those bugs could have gotten in before I installed all the protection I now have. I guess it begs the question; is there such a thing as a clean computer?
Windows 8 and Windows 10 dual boot with two SSD's

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: MicroSoft Windows Malicious Software Removal tool
« Reply #11 on: May 17, 2008, 01:51:43 PM »
Some people come close, but there is no 100% protection.