Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Infected with Trojans and Malware
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Infected with Trojans and Malware
Hello:
A coworker went to some bad sites and got there PC all messed up. We run Symantec Corporate, so that is the antivirus program that was used to do the AV scans. I followed the instructions in the malware removal thread. Attached are the 3 log files. PandaAntiRootkit came up clean. We do run SAAZ monitoring software on all of our PCs for remote network support. Thanks!! |
|
#2
|
||||
|
||||
|
looks like the steps did what they are supposed to do.
It also looks like somebody likes playing games - Remove HijackThis entries
------------------------------------------------------------------------------- Update your Java Runtime Environment
If for some reason you couldn't update through the above instructions. Update your Java Runtime Environment
------------------------------------------------------------------------------ Let's run an online scan to see if I missed anything - Run Kaspersky Online AV Scanner Order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
If the kaspersky log checks out then we can clean up, remove backups, and secure the work you did already |
|
|
|
#3
|
|||
|
|||
|
Thanks for your help!
Looks like Kaspersky found a couple of things. 2 In old Symantec Quarantine and several of the clean up tools. Also found 2 others that were missed by Symantec. Here is the log. |
|
#4
|
||||
|
||||
|
Obviously you want to clean out Symantec Quarantine
but... Asterisk Logger: Reveal/recover password behind asterisks (***) Do you use that program? Or would you like to remove it? I would like to hope that you or your coworker installed it rather than an infection. |
|
#5
|
|||
|
|||
|
Thanks alot for your help!
The logger was installed by a network contracter, not by malware. He should have removed it. |
|
#6
|
||||
|
||||
|
How is the computer running? any symptoms left?
Looks like they removed the program but not the zip of the installer Just delete these then empty the recycle bin: C:\BackUp of Files\Other\astlog.zip C:\Documents and Settings\mstraub\Desktop\Other\astlog.zip ------------------------------------------------------------------ Uninstall Combofix * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter. * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ----------------------------------------------------------------------- OTCleanit! by Oldtimer
--------------------------------------------------------------------------- Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
here are some additional utilities that will enhance your safety
|
|
#7
|
|||
|
|||
|
Deleted this post because I found the answer on google.
Thanks.... Last edited by echu1989; 07-16-2008 at 10:14 AM.. Reason: Found answer searching on google.... |
|
#8
|
||||
|
||||
|
Ok, so everything is normal now?
|
|
#9
|
||||
|
||||
|
Looks good, well-done Blind Dragon.
I can do these logs now, i have found out how to analyse them... |
|
|
|
#10
|
|||
|
|||
|
Everything seems fine accept for a small issue in Outlook 2000. It bombs whenever the user tries to access to the Tools->Customize option. I am likely going to just uninstall and reinstall that application.
Thanks again for all of your help. I followed all the steps in your follow up guide and I also installed Firefox and told my user to use that browser. |
|
#11
|
||||
|
||||
|
Within firefox you can select tools -> add-ons -> get addons -> browse all addons -> you can get and IE Tab for sites that demand IE and you can run IE within firefox browser
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Password stealing trojans, URL redirects - am I still infected? | Virus & Malware removal | 4 | 02-06-2008 02:10 AM | |
| Need Help with my infected PC! (trojans & loggers) | Virus & Malware removal | 0 | 02-02-2008 02:39 PM | |
| Infected system (trojans etc) please help | Virus & Malware removal | 4 | 01-02-2008 05:09 PM | |
| Infected with possible trojans (more then one i think) | Virus & Malware removal | 3 | 04-24-2007 09:48 AM | |
| Infected by trojans including spyaxe | Virus & Malware removal | 1 | 11-24-2005 03:48 AM | |
All times are GMT -4. The time now is 04:35 PM.


