also @ TechSpot: Mozilla developing Metro-specific Firefox for Windows 8
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Download Now:

Logfiles after virus removal

Thread Tools Search this Thread
  #1  
Old 08-17-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
Logfiles after virus removal

My sons computer got infected with viruses, where the clock should be it said VIRUS ALERT! and he lost a lot of icons on the desktop and the start menu, including My Computer. AVG also found infected files.

I ran through your excellent 15 step virus removal instructions and I think the system is clean now. Everything seems to work normally.

The only mistake I made was forgetting to disable the Teatime Protection with SS&D, I hope that hasn't ruined the cleaning process.

I am posting my hijackthis, ComboFix and SAS logs for inspection to make sure.

Panda Antirootkit returned no rootkits found.

I am grateful for all feedback.

Torbjörn, Sweden
Attached Files
File Type: txt Combofixlog.txt (13.5 KB, 1 views)
File Type: log hijackthis.log (11.0 KB, 4 views)
File Type: log SUPERAntiSpyware Scan Log - 08-16-2008 - 18-25-58.log (33.7 KB, 3 views)
  #2  
Old 08-18-2008
SpiritWind's Avatar
TechSpot Enthusiast
 
Location: Southern Calif
Member since: Jul 2008, 164 posts
Hi :

Usually when you see a "Virus Alert", it means you have a "Rogue" program and
the best program to deal with those is the FREE Version of "Malwarebytes'
Anti-Malware", which we usually recommend be run & available at
www.malwarebytes.org/mbam.php ; even though you ran SUPERAntiSpyware & it
found quite a bit, would be wise to be through & run the Malwarebytes program .
I noticed your Sun Java is slightly outdated, a security risk; best to have ONLY the
latest version by uninstalling ALL "old" versions, then going to www.java.com for
the Latest . Also the Adobe Reader is outdated, another security risk ; since this
program is under contant attack by malware, would be wise to uninstall it and
seriously consider the alternative "Foxit Reader", with Info at
http://foxitsoftware.com/pdf/rd_intro.php .

NOTE : Both Ad-Aware AND Spybot are no longer top antiSPYWARE programs.
  #3  
Old 08-18-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
Ok, thanks, I have downloaded the latest Adobe and Java updates and have removed the old ones.

I just discovered however when I changed to my sons identity on the computer that the original problems with VIRUS ALERT where the clock should be, missing icons on the desktop and lots of things gone on the start menu as My computer, Control Panel, Search and so on was still there on his identity.

My identity is ok, everything works from there, looks ok from there, and it was from my identity I did all the cleaning operations.

Got a bit nervous when I saw that... but luckily my identity still looks ok. But this must mean something bad still is in there somewhere.

What to do???
  #4  
Old 08-18-2008
Newcomer, in training
 
Member since: Aug 2008, 3 posts
System Restore infected?

I fixed the problem with my sons identity, his desktop with SmitFraudFix

I also found out that AVG found four Trojan Downloaders in System Restore (C:\System Volume Information\_restore..........dll, one of them .exe) when it scanned overnight.

In another thread I found out that I should disable System Restore to get rid of this and then reset System Restore, this as soon as I was sure the computer was clean.

So - I would greatly appreciate if somebody with knowledge could inspect the files I attached to my first post!
Closed Thread

Similar Topics
Topic Replies Forum
Virus disguised as virus removal 1 Virus and Malware Removal
Logfiles to be analyzed 1 Virus and Malware Removal
More logfiles to be analyzed please 3 Virus and Malware Removal
LogFiles after 8 step process 9 Virus and Malware Removal
Logfiles of 8-step virus/malware removal process 1 Virus and Malware Removal

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 12:09 PM.