Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virus help  (Read 5890 times)

0 Members and 1 Guest are viewing this topic.

RainPilot

    Topic Starter


    Starter

    Virus help
    « on: July 16, 2010, 07:04:11 PM »
    Hey, I think I had a virus but got rid of it but to be sure here are my logs - if someone could take a look at them it would be appreciated. Any tips to be sure if its gone would be helpful and any knowledge on what exactly I have/had would be awesome.

    Symptoms were minimal.
    Error 1397 - could not create directory. ( could not download anything )
    Error 1337 - program is corrupt and unreadable
    - could not do a system restore due to unspecified error.

    LOGS:
    Malware bytes  - http://pastebin.com/JiGUVi64
    Super-Anti-spyware - http://pastebin.com/m5835Cz5
    hijackthis/sniper.exe - http://pastebin.com/JGqtAfMh



    Sneakyone

    • Malware Removal Specialist


    • Beginner

      Thanked: 5
      Re: Virus help
      « Reply #1 on: July 17, 2010, 10:44:49 PM »
      Hi, Welcome to Computerhope! :)

      Please download OTL  to your Desktop. (If you already have it downloaded, then just follow the instructions below).
      • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
      • Under the Custom Scan box paste this in
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\*.sys
      %systemroot%\system32\drivers\*.dll
      %systemroot%\system32\drivers\*.ini
      %systemroot%\system32\drivers\*.exe
      %SYSTEMDRIVE%\*.*
      %PROGRAMFILES%\*.
      %appdata%\*.*
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      disk.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      usbstor.sys
      /md5stop
      CREATERESTOREPOINT
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


      • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
        • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
        • Please copy (Edit->Select All, Edit->Copy) and paste (Edit->Paste) the contents of these files, one at a time
      Note: in the event that OTL fails to run, please use alternate download links to try again:

      http://oldtimer.geekstogo.com/OTL.com
      http://oldtimer.geekstogo.com/OTL.scr

      RainPilot

        Topic Starter


        Starter

        Re: Virus help
        « Reply #2 on: July 18, 2010, 06:15:33 PM »
        Hey, Ran the scans. Logs below. Thanks for helping :D

        OTL.Txt - http://pastebin.com/t4BgRUdP
        Extras.Txt - http://pastebin.com/qz4wSVUE

        Sneakyone

        • Malware Removal Specialist


        • Beginner

          Thanked: 5
          Re: Virus help
          « Reply #3 on: July 18, 2010, 06:28:04 PM »
          Hi, :)

          Please download ComboFix from BleepingComputer.com

          Alternate link: GeeksToGo.com

          Alternate link: Forospyware.com


          Rename ComboFix.exe to commy.exe before you save it to your Desktop
          • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
          • Click Start then copy paste the following command into the search box & hit enter: "%userprofile%\desktop\commy.exe" /stepdel
          • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. This will not install in Vista. Just continue scanning, and skip the console install.
          • When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

          RainPilot

            Topic Starter


            Starter

            Re: Virus help
            « Reply #4 on: July 18, 2010, 08:43:12 PM »
            Hey, Thanks for the help so far. Heres the log requested

            commy.exe - http://pastebin.com/s8MTAQdM

            Question. Is it safe to leave these links up for extended amount of time, is there any valuable information that could be used against me?

            Sneakyone

            • Malware Removal Specialist


            • Beginner

              Thanked: 5
              Re: Virus help
              « Reply #5 on: July 19, 2010, 12:35:58 AM »
              Hi, :)

              No, there shouldn't be.

              Please download Malwarebytes Anti-Malware from here.

              Double Click mbam-setup.exe to install the application.
              • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
              • If an update is found, it will download and install the latest version.
              • Once the program has loaded, select "Perform Full Scan", then click Scan.
              • The scan may take some time to finish,so please be patient.
              • When the scan is complete, click OK, then Show Results to view the results.
              • Make sure that everything is checked, and click Remove Selected.
              • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
              • Please save the log to a location you will remember.
              • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
              • Copy and paste the entire report in your next reply.
              Extra Note:

              If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

              RainPilot

                Topic Starter


                Starter

                Re: Virus help
                « Reply #6 on: July 19, 2010, 10:08:00 AM »
                Log as requested. Am I safe?
                http://pastebin.com/CttEUfYP

                Sneakyone

                • Malware Removal Specialist


                • Beginner

                  Thanked: 5
                  Re: Virus help
                  « Reply #7 on: July 20, 2010, 03:53:17 PM »
                  Hi, :)

                  One final check before I can confirm that. 

                  Please run a free online scan with the ESET Online Scanner
                  Note: You will need to use Internet Explorer for this scan[/i]
                  • Tick the box next to YES, I accept the Terms of Use
                  • Click Start
                  • When asked, allow the ActiveX control to install
                  • Click Start
                  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
                  • Click Scan (This scan can take several hours, so please be patient)
                  • Once the scan is completed, you may close the window
                  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
                  • Copy and paste that log as a reply to this topic