Did Read and Run Malware process - results

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mladyraven, Oct 21, 2009.

  1. mladyraven

    mladyraven Corporal

    First week Sept pages started freezing, FF crashing, I ran Malwarebytes and it found and quarantined several items-this was Sept 9th. I then ran Macafee Suite ( which I get from Cox) and it found several more Trojans- it said it had quarantined them, however, when I looked in the vault there was NOTHING there. ( This all got through Macafee!) I ran Housecall - clean- SuperAntiSpy- cookies and adware, cleaned and the computer was working fine for a day or so. Then FF crashing etc... kept trying different things. Last night my Macafree Suite from Cox expired, it does that every few months. I tried to renew, download again and it would not let me. I called Cox Tech Support we tried many things and they said I must have a virus - duh!
    When I tried to download it via IE message was "Windows cannot connect to Internet using HTTP, HTTPS, or FTP, check Firewall, HTTP port 80, HTTP port 443 and FTP port 21, check with Internet provider" I checked with Cox again, there was nothing wrong with my ISP or bandwith.
    I could not get Combofix to run, I tried twice. The first time it ran for 30 minutes and the second time it ran for 55 min, and I had the blue screen the entire time. I got a bit of information when I did a search files and I have included that.
    I did everything else you said to do. Before I started, I uninstalled all the programs and then reinstalled them. I installed Avast Free until I can figure out what to do, I ran it and it came back clean.
    Those first Trojans were a root problem.
    Also , I ran a msconfig last week and one of the Services - was a blank line and just running on the the right. The Dell tech told me to delete it , it was most likely a Trojan or Virus.
    Last issue, Windows Installer keeps trying to update my Dell Support Center. That expired in July. At start up and when I am downloading something else, the Windows Downloader pops up and tries to run, until it gets to a window that says, please put in CD Dell Support.
    :(
    I believe I have done everything you have asked, I will now attach the report.
    Oh, what I was doing when the problem started in Sept. Ah, looking at an adult site....rolleyes- Macfee site advisor said safe. First time and this is the mess I make!!!!

    Again, there are 2 mblogs because I included the one from Sept 9th and after I uninstalled mblogs and ran again, I saved today's log. So, I did follow all the directions.
     

    Attached Files:

  2. mladyraven

    mladyraven Corporal

    Part two, the information I was able to find by searching files concerning Combofix. See above.

    I am trying not to do anything much with the computer. However, I do some work from home on a online crisis line, so, I am hoping this is safe to do.

    Thank you very much.
    Raven
     

    Attached Files:

  3. mladyraven

    mladyraven Corporal

    I think this is the MGlogs that were supposed to be attached, thank you.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't appear to be having malware problems. I will give you a few things to do but if you still have connection issues, you will have to post in the Networking ( or Software ) Forum since this is not malware.

    First run the below to hopefully cleanup the mess from McAfee:

    McAfee Consumer Product Removal Tool


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [McAfee Update] C:\DOCUME~1\Nicole\LOCALS~1\Temp\mcupdate_1258794975.exe /syncfin C:\DOCUME~1\Nicole\LOCALS~1\Temp\mcupdate_1258794975.ini
    O18 - Filter: x-sdch - (no CLSID) - (no file)

    After clicking Fix, exit HJT.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Delete the below folder if it still exists:
    C:\Program Files\McAfee

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Nicole\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. mladyraven

    mladyraven Corporal

    At this time I cannot do anything on the machine, I cannot connect to the NET. Malware bytes - when I would go to open it , it said it was already running, however, in task manager it did not say that. Instead of waiting I tried a few things, I ran Spyware Terminator in safe mode , it found a few things ( I saved them , however, I cannot get to them. ) I deleted and rebooted, when I rebooted, ckdsk came up and started running and started deleting tons of files. It went by so fast I could not stop it or read all that it deleted.
    It was a matter of seconds. After rebooted, my windows firewall was shut down and I could not get it to turn back on. I could not get to the NET using FF or IE. Cox Tech, refreshed, set up a new ISP number, we could not find the Network adapter that was gone. Finally the machine would accept the drivers from the CD that came with the computer. I added them and we Tested and it said Network adapter was working, however, it was not communicating with modem, Tech could see modem was online. Also a Winsock was missing so he helped me replace that.
    Got a message Windows cannot connect to the Internet using HTTP, HTTPS, or FTP. Check Firewall, HTTP port 80 HTTP port 443 and FTP Port 21
    After I reloaded drivers and Nivida adapter it just says - no connection to the Internet. My Window Firewall is shut down, and it says Cannot start Firewall,/Internet Connection sharing ICS services.
    I had an old HP Pavilion in the closet was going to fix and give to grandson. I partitioned it last night , reformatted, added Windows and am running it now.
    I downloaded McAFee from Cox and IE went out on me with the same error message. I uninstalled it, rebooted and ckdsk came up and starting running again.. however, it did not delete files , however it repaired, several bad boot sections- during part 4 files. Out of 5 errors three were in McAfee, the other two were in Windows 13181 Prefetch . UPBCFO21.PF
    MSCMCNDSV.dll
    viruss~1/naiann.dll
    I am wondering if something came in with Cox McAfree suite.
    I think Windows is now corrupted on my other machine, I am not sure how to repair it. It only gives me the Option to reinstall and I will lose everything on the machine, I do not have an external HD
    I am still a newbie, an older grandma, and learning as I go along.
    A friend in Texas who works for ACER is going to talk to me on the phone later today and see if he can figure out what to do.
    I will write back once I figure out more about what is going on.
    Thank you for your time.
    I guess I was having a McAfee software error and I made it a total disaster now... rolleyes
    Once the machine is running I will do what you suggested.
    Do you have any suggestions for me re a free AV to use?
    Thank you.
    So, if I cannot get it running I need to post to Networking problems. Then once I get it running I can do the steps you suggested. Thanks
     
  6. mladyraven

    mladyraven Corporal

    Well, my friend from ACER said I have to reformat , so I have posted in Networking, because I am not sure how to save important information from my old computer. I do not have an external HD and cannot get on the net to save online. Thanks for all of your help!
     
  7. mladyraven

    mladyraven Corporal

    The system was trashed, I ended up trying to reinstall which it would not let me. It went in a loop at 34% , would not download devices. Finally, I got through to Microsoft and someone helped me delete and partition, then fresh install. I have removed the Windows Messanger as you suggested. Being this is a fresh install do I still need to do the other steps you suggested?
    Thank you for your assistance.
    Grateful Newbie
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No! What you should do is the below. ;)
     
  9. mladyraven

    mladyraven Corporal


    OK, I will do exactly as suggested! ;)
    The day after the install IE kept crashing.
    I downloaded all updates and re- loaded Cox Cable McAfee.
    I ran Super Spy Ware and in one day I had 27 issues, then I ran mbam and I do not understand what it found and what it means.

    Again, thanks for all your assistance, except for FF crashing a bit, which is a FF problem I believe from what I am reading things are going well.
    I guess I need to go to software, I would like to know the best AV to buy, I do not think the free McAfee is doing a good job.
    :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cannot comment without a log. For all I know, you are talking about cookies which are not problems.

    Not problems. It is just due to changes from Windows defaults since you have installed McAfee. These are things that MBAM should not be complaining about but they have decided they would report them even though they are not issues. That way people will know if they keys have been modified. Basically they are notifications.

    Who is best is subjective and changes every couple of weeks with updates and can change with each program version update. McAfee and Symantec are never best.
     
  11. mladyraven

    mladyraven Corporal

    Thank you. I am reading all you suggested and making choices about what AV and Spyware to use. My daughter, son in law and myself by them ( 3 users license ) so, I will have him read the information and we will decide together. He is not happy with McAfee and even though it is free from Cox, I do not trust it.
    Thanks for caring about us and giving so generously of your time.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds