do i know when my computer is fixed?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by copyman_5, Sep 2, 2008.

  1. copyman_5

    copyman_5 Private E-2

    How do i know when my computer is fixed?

    Hello-
    I greatfully ran across the MG site after waiting FOREVER at another one for over a week with absolutely no help. I had multiple Trojans, virus, system files bad, Virtumonde and a whole bunch more given to me by SpyHunter---yes, my fault.
    Here I performed the complete READ AND RUN FIRST portion and I think I've taken care of most if not all of my problems, but I'd like someone here to confirm it if they would. I've got reports here.
    I thank you in advance and really appreciate what's been done so far!! :cool
    Let me know how to proceed next please.
    Peace--copyman_5
     

    Attached Files:

    Last edited: Sep 2, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the logs from SUPERAntiSpyware and MGtools that were requested before we can continue.

    You also must disable Spybot's Teatimer as was requested in the READ & RUN ME.
     
  3. copyman_5

    copyman_5 Private E-2

    Thanks for responding so quickly!
    Disabled TeaTimer again.
    Attached logs for you-
    All yours!

    Steven
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. copyman_5

    copyman_5 Private E-2

    Ok-
    I got to the part where fixme.reg is supposed to merge with registry. No go. What I get is: Cannot import C:\Documents and Settings\Steven Vimr\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor.
    Did I do something wrong?
    copyman_5
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. You did not do exactly what was requested. I'm guessing that you do not have the REGEDITT4 line as the first line. The first line in the file must be the REGEDIT4 line. No lines can be above it.
     
  7. copyman_5

    copyman_5 Private E-2

    Ah my mistake, ok what I did was copy/paste from the email, which I now see has * at the beginning and end of everything. Did copy/paste right from thread and all is good so far. Attached files. Awaiting your glad tidings. :-D
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A word of advice for the future. Only use the emails to inform you that you need to look at the thread. Always work from what is posted in the thread in any forum you work on. Emails do not always show things properly and often the email may be incorrect because the message may have to be edited after it is posted.

    Your logs are clean. Final instructions to follow in a moment.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. copyman_5

    copyman_5 Private E-2

    You are my new best friend---
    I appreciate all your fast, courteous, and informative help. I'll be sure to pass along this site and my good feelings about it. Is there any way to send you guys some money? I know I would've spent quite a bit of money to get this thing fixed had I brought it somewhere. :major

    I'll take your advice and purchase at least one of those for protection.

    Thanks again and have a great night!

    Peace--Steven V./copyman_5
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Thanks for spreading the good word.:)

    Not necessary but I do have a paypal account. ;)
     
  12. copyman_5

    copyman_5 Private E-2

    Hello again--
    Something strange still....My computer rebooted after downloading updates and the message to load .NET FRAMEWORK V 2.0.50727 came up. I've tried to load it a few different times with no luck from MSN. Also this morning all of my favorites are not in the order I've put them in. Any clues?
    Thanks--copyman_5
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean from MSN. Did you mean from Microsoft Update? For problems getting updates from Microsoft you should post in the Software Forum. You can always just download the file and install them manually too. Like from the below links:

    http://www.microsoft.com/downloads/details.aspx?FamilyID=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5&displaylang=en

    http://www.microsoft.com/downloads/details.aspx?familyid=79BC3B77-E02C-4AD3-AACF-A7633F706BA5&displaylang=en


    Note there are versions 3.0 and 3.5 out too.


    Not really but probably just a sorting issue. If you do not use the simple form of right click and Sort by Name, you will have to rearrange them to how you want them.
     
  14. copyman_5

    copyman_5 Private E-2

    Hi,
    Yes, Microsoft Update. I'm able to download them but not install. I was wondering if these problems were somehow leftovers from our previous issues we fixed. I'll move the thread if I need to. I've loaded 3 & 3.5 with no luck either. I can let you know what the message said or do it on another thread.

    Thanks much-Steven
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you start a new thread in the Software Forum and post a full explanation of your current problem there.
     
  16. copyman_5

    copyman_5 Private E-2

    Hello-
    Done and fixed! As before, I appreciate all of you and your site. How can I access your Paypal acct for a charitable contribution? I can't PM anyone cuz I don't have that many posts.
    Peace--Steven
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You can send me an email at majorgeeks.com with your email info and I will respond to it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds