8 step results

Status
Not open for further replies.

bignutz

Posts: 12   +0
Hello to all,

I have completed the 8 step removal and attached logs. any help would be greatly appreciated.
 
Hello bignutz.

You´ve certainly got some crap there, and not even a Antivirus program, this is somewhat suicidal in today's digital world.
Avast makes an excellent free antivirus client
http://www.avast.com/eng/avast_4_home.html
As does Avira: http://www.avira.com/en/download/

Install, update the antivirus program you have chosen, run a complete systemscan.

Please upload and have these files scanned:
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
Here:

http://virusscan.jotti.org/ Or here: http://www.virustotal.com/en/indexf.html

Attach back the results.
 
Hello Touch,

I installed one of the anti virus as instructed, updated and did a complete scan, I installed the avast antivirus all infections were moved to the chest. I was also instructed to upload specific files to have them checked. I need instructions on how to upload those specific files and should i take action as far as removing them from the chest file. I have quite a few infections in each of the profile on the computer. Thank for all your help.
 
We´ll leave the upload part for now.

I´ll prefer you post a combolog -

Please download combofix here -> https://www.techspot.com/downloads/5587-combofix.html

Before Saving it to Desktop, please rename it to 123.com to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall.
It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after
scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post
 
Open notepad and copy/paste the text in the quotebox below into it:
Name the file as CFScript
and Save it on the desktop

Killall::
Snapshot::
File::
c:\windows\system32\yelesato.exe
c:\windows\SYSTEM32\076122E4BB.sys
c:\windows\system32\drivers\a362870d.sys
Folder::
c:\documents and settings\All Users\Application Data\zelokore
c:\documents and settings\All Users\Application Data\vajetezo
c:\documents and settings\All Users\Application Data\tumetoho
c:\documents and settings\All Users\Application Data\neniweja
c:\documents and settings\All Users\Application Data\hihogufe
c:\documents and settings\All Users\Application Data\gusuwopu
c:\documents and settings\All Users\Application Data\tinonere
c:\documents and settings\All Users\Application Data\kemaniwu
c:\documents and settings\All Users\Application Data\tojitala
c:\documents and settings\All Users\Application Data\nebozege
c:\documents and settings\All Users\Application Data\henemate
c:\documents and settings\All Users\Application Data\hidekeli
c:\documents and settings\All Users\Application Data\lewabenu
c:\documents and settings\All Users\Application Data\towopudi
c:\documents and settings\All Users\Application Data\wamofuma
c:\documents and settings\All Users\Application Data\vugehoye
c:\documents and settings\All Users\Application Data\yebalino
c:\documents and settings\All Users\Application Data\tigefeki
c:\documents and settings\All Users\Application Data\hemodizi
c:\documents and settings\All Users\Application Data\yerehute
c:\documents and settings\All Users\Application Data\jakejoki
c:\documents and settings\All Users\Application Data\jadikure
Driver::
a362870d

http://www.fromsej.saknet.dk/billeder/cfscript.gif

Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post
 
results from combofixlog2

Hello Touch,

Combofix logs for the 2nd scan results, Thank you in advance.
 
It looks clean.

Update malwarebyte, run a complete scan and have it to fix what it find.

Attach malwarebyte log, along with new hijackthis log
 
That´s good news :approve:

You should Create a New Restore Point to prevent possible reinfection from an old one.
The easiest and safest way to do this is:
Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a restore point, and Ok it.
Next, go to Start > Run and type in cleanmgr
Select the More options tab
Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.


Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
When shown the disclaimer, Select "2"
The above procedure will:
Delete the following:
ComboFix and its associated files and folders.
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.

To learn more about how to protect yourself while on the internet, please read Tony Klein´s guide:
How did I get infected in the first place?
 
Hello Touch,

New restore point in in place, and combofix has been deleted from the computer. Thank you and keep up the good work...
 
Status
Not open for further replies.
Back