Results 1 to 10 of 76

Thread: Need help with conficker worm!!!!

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Emeritus- Security Expert peku006's Avatar
    Join Date
    Feb 2007
    Location
    Norway
    Posts
    3,103

    Default

    Hi John
    we can continue with mbam

    Malwarebytes' Anti-Malware

    • Open Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Check for Updates
    • After the update have been completed, Select the Scanner tab.
    • Make sure the "Perform full scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:
    1. Click on the Show Results button to see a list of any malware that was found.
    2. Check all items except items in the C:\System Volume Information folder... then click on Remove Selected.
      We will take care of the System Volume Information items later.
    3. When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
    4. The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
    5. Copy and paste the contents of that report in your next reply and exit MBAM.


    Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
    Click OK to either and let MBAM proceed with the disinfection process.
    If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


    Please reply with

    the Malwarebytes' Anti-Malware Log

    Thanks peku006
    I don't help with logs thru PM. If you have problems create a thread in the forum, please.

  2. #2
    Member
    Join Date
    Jul 2010
    Posts
    73

    Default MB log

    peku,

    MB found 2 infections of conficker. Neither were in C:\System Volume Information. I had them removed, re-started the computer. Is it possible that I could keep getting re-infected with this when I hook up to the network at work? Our internet (emails) is wireless but I sometimes access Microsoft Dynamics and one other drive on the network when I am here.

    thanks.

    John





    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 5100

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    11/12/2010 9:58:40 AM
    mbam-log-2010-11-12 (09-58-40).txt

    Scan type: Full scan (C:\|D:\|E:\|)
    Objects scanned: 255385
    Time elapsed: 46 minute(s), 32 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\john\Local Settings\temp\NOD58B.tmp (Worm.Conficker) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mxpcivny.dll (Worm.Conficker) -> Quarantined and deleted successfully.

  3. #3
    Emeritus- Security Expert peku006's Avatar
    Join Date
    Feb 2007
    Location
    Norway
    Posts
    3,103

    Default

    Hi dallak
    Is it possible that I could keep getting re-infected with this when I hook up to the network at work? Our internet (emails) is wireless but I sometimes access Microsoft Dynamics and one other drive on the network when
    I do not think that it is possible

    1. Download TDSSKiller and extract its contents into a folder in desired location (i.e. c:\tdsskiller).
    2. Execute the file TDSSKiller.exe.
    3. Click Start Scan. If threats are found, select cure and click Continue (tool may prompt for a reboot).
    4. Post back contents of log file in c: drive root (name should be in UtilityName.Version_Date_Time_log.txt format)

    Thanks peku006
    I don't help with logs thru PM. If you have problems create a thread in the forum, please.

  4. #4
    Member
    Join Date
    Jul 2010
    Posts
    73

    Default tdsskiller

    kaspersky website must be down. I will try again later. anywhere else I can get it?

  5. #5
    Member
    Join Date
    Jul 2010
    Posts
    73

    Default kaspersky


  6. #6
    Member
    Join Date
    Jul 2010
    Posts
    73

    Default tdsskiller

    I found 2.4.1.0 on Softpedia.com. I will use that.

  7. #7
    Member
    Join Date
    Jul 2010
    Posts
    73

    Default tdsskiller

    ran it; no threats found.


    John

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •