Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Infection mdelk.exe and bagle [RESOLVED]


  • This topic is locked This topic is locked

#61
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,965 posts
Hi, Karol33 :)

I am glad the computer is running better.

Yes. Running the Kaspersky online scanner is a good idea. Post the report it may produce.

Before reinstalling AVG7, once you have downloaded the AVG7 Installer to your desktop, remove AVAST. You can't have two antivirus programs running. Then install AVG7.

Please also download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Edited by JSntgRvr, 06 March 2008 - 11:28 AM.

  • 0

Advertisements


#62
Karol33

Karol33

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Will do. Ill post the logs later.
  • 0

#63
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,965 posts
:) :)
  • 0

#64
Karol33

Karol33

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
I have uploaded the kaspersky report and the malwarebytes app is clean.

Kaspersky has found a lot of infections.

Attached Files


  • 0

#65
Karol33

Karol33

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Ran full scan of that malware app and this is what it did:

Malwarebytes' Anti-Malware 1.07
Database version: 461

Scan type: Full Scan (A:\|C:\|)
Objects scanned: 156476
Time elapsed: 40 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 61

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0564274.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0564275.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0565415.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0565416.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0566734.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0566735.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0566926.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP690\A0566927.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP692\A0568006.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP692\A0568007.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP692\A0568154.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP692\A0568155.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP692\A0568156.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP693\A0568279.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP693\A0568280.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579026.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579034.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579036.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579052.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579054.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579082.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579096.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579122.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579401.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579413.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579418.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579422.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579432.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579434.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579438.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579442.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579455.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579456.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579481.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579484.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579500.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579513.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579526.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579528.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579664.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579692.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579745.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0579960.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580120.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580195.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580200.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580248.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580299.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580348.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580358.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580387.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580388.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580435.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580528.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580590.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580665.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580734.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580739.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580788.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580795.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{13A08FD4-A8F0-45D6-811E-16EFE3C81A57}\RP694\A0580819.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
  • 0

#66
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,965 posts
Hi, Karol33 :)

Congratulations.Posted Image

What is left will be easy to correct.

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programmes changing them. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK..

Since the tools we used to scan the computer, as well as tools to delete files and folders, are no longer needed, they should be removed, as well as the folders created by these tools.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.


    • Posted Image

  • If the disclaimer notice is displayed, select "2" and press Enter

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
Create a Restore point (If the above process fails):
  • Click Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore.
  • In the System Restore dialog box, click Create a restore point, and then click Next.
  • Type a description for your restore point, such as "After Cleanup", then click Create.

The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • ZonedOut + IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  • Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

I believe that should do it.

Best wishes! Posted Image
  • 0

#67
Karol33

Karol33

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Thanks a lot for your help man and for dealing with my problem. :)
  • 0

#68
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,965 posts
You are Welcome. :)
  • 0

#69
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,965 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP