2012-11-15, 19:45
I had the FBI virus attack recently. I was able to identify and clean it with Malwarebytes, but some sort of Trojan keeps showing up whenever I do a subsequent scan and removal. I know that I wasn't supposed to, but I tried ComboFix to see if that would work. No luck - it keeps showing up in MalwareByte scans. I have also run SpyBot and Eset.

I'd like some help in making sure that my machine is absolutely clean.


SpyBot did not have any results to post.

shelf life
2012-11-23, 16:24
Can you post the last Malwarebytes log. If you open up MBAM theres is a tab for opening up previous scan logs.

2012-11-23, 19:22
Here you go. Thank you for your help.


shelf life
2012-11-24, 00:42
Download rougekiller.exe (http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe) to your desktop.

Right click the icon to run as admin. A quick scan will take place. Afterwards, click on the scan button.
Once it done, under the registry tab you should see the path to the file in question. Uncheck anything else and leave that one checked. Click the delete button and last on the Report button. A .txt file will saved to your desktop.

2012-11-24, 03:14
Thank you for your help!


RogueKiller V8.3.1 [Nov 23 2012] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Bob [Admin rights]
Mode : Remove -- Date : 11/23/2012 19:13:07

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 9 ¤¤¤
[RUN][ROGUE ST] HKLM\[...]\Policies\Explorer\\Run : 10075 (C:\PROGRA~3\LOCALS~1\Temp\msewxxji.scr) -> DELETED
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> NOT SELECTED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NOT SELECTED
[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> NOT SELECTED
[HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> NOT SELECTED
[HJ] HKLM\[...]\System : EnableLUA (0) -> NOT SELECTED
[HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> NOT SELECTED
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NOT SELECTED
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NOT SELECTED

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST31000524AS +++++
--- User ---
[MBR] 94fd51b68ea5f8b85e501f14e34012fd
[BSP] a6da8d8eff06629f807697e18755dcfd : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 20736 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 42549248 | Size: 933092 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2]_D_11232012_02d1913.txt >>
RKreport[1]_S_11232012_02d1911.txt ; RKreport[2]_D_11232012_02d1913.txt

shelf life
2012-11-24, 15:22
Ok, looks like it been deleted. You can also delete the RougeKiller icon and log from your desktop.

some tips:
No software can think for you. Help yourself. In no special order:

1) It is essential to keep your operating system (Windows) browser (IE, FireFox, Chrome, Opera) and other software up to date to "patch" vulnerabilities that could be exploited. Visit Windows Update (http://www.update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us) frequently or use the Windows auto-update feature. Staying updated is also essential for other web based applications like Java, Adobe Flash/Reader, iTunes etc. More and more third party applications are being targeted. Use the auto-update features available in most software. Not sure if you are using the latest version of software? Check their version status and get the updates here. ( http://secunia.com/vulnerability_scanning/online/)

2) Know what you are installing to your computer. Alot of software can come bundled with unwanted add-ons, like adware, toolbars and malware. More and more legitimate software is installing useless toolbars if not unchecked first. Do not install any files from ads, popups or random links. Do not fall for fake warnings about virus and trojans being found on your computer and you are then prompted to install software to remedy this.

3) Install and keep updated: one antivirus and two or three anti-malware applications. If not updated they will soon be worthless. If either of these frequently find malware then its time to *review your computer habits*.

4) Refrain from clicking on links or attachments via E-Mail, IM, IRC, Chat Rooms, Blogs or Social Networking Sites, no matter how tempting or legitimate the message may seem. See also E-mail phishing tricks. (http://www.fraud.org/tips/internet/phishing.htm)

5) Do not click on ads/pop ups or offers from websites requesting that you need to install software to your computer--*for any reason*. Use the Alt+F4 keys to close the window.

6) Don't click on offers to "scan" your computer. Install ActiveX Objects with care. Do you trust the website to install components?

7) Consider the use of limited (non-privileged) accounts for everyday use, rather than administrator accounts. Limited accounts (http://www.microsoft.com/protect/computer/advanced/useraccount.mspx) can help prevent *malware from installing and lessen its potential impact.* This is exactly what user account control (UAC) in Windows Vista, Windows 7 and Windows 8 attempts to address.

8) Install and understand the *limitations* of a software firewall.

9) Your browser risks: The why and how (http://www.cert.org/tech_tips/securing_browser/) to secure your browser for safer surfing. For added protection disable Java (http://blog.eset.com/2012/08/29/disabling-java-a-safer-way-to-browse) in your browser.

10) Warez, cracks, keygens etc are very popular for carrying malware payloads. If you look for these you will encounter malware. If you download/install files via p2p networks you will encounter malware. Do you really trust the source of the file?
More info/tips with pictures, links below

Happy Safe Surfing.

2012-11-24, 18:06
Thank you very much for your help. it is sincerely appeciated!

shelf life
2012-11-25, 15:59
ok your welcome. you can remove combofix like this:

click start then in the search field type in;
combofix /uninstall
click ok or enter, note the space after the x and before the /

Happy Safe surfing out there.