Does anymore need to be done?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tommy2k8, Jul 27, 2009.

  1. tommy2k8

    tommy2k8 Private First Class

    I just had a look at a computer which took ages to do anything. It has 512MB RAM but was paging at 664MB!
    I followed the majorgeeks cleaning procedure. Attached are the logs; should I go back and do anything else to the machine, or do you think it is okay now?
     

    Attached Files:

  2. tommy2k8

    tommy2k8 Private First Class

    Further to my earlier thread, here is my Root Repeal Log (as you can only attach 4 at once)
     

    Attached Files:

  3. tommy2k8

    tommy2k8 Private First Class

    I disinfected them all by the way
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have done that before saving the log with MBAM.


    You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Make sure to Quarantine/Delete any malware before saving the log. Attach the new log.

    You need to put ComboFix.exe onto your Desktop. You ran it from drive F. Remaining steps I will need to give will not work unless you follow all instructions properly.

    Also MGtools did not run properly. Did you make sure you allowed it to finish running? Did you click the Accept button Twice for the TrendMicro HijackThis license agreement? Try running the below.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new SAS and MBAM logs
    • C:\MGlogs.zip
    Make sure you tell what malware problems you are still having if any remain!
     
  5. tommy2k8

    tommy2k8 Private First Class

    I don't know when I am going to get there again, do you want me to book a special trip so I can do what you say?

    The computer was running 'as new' when I left!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean by book a trip? If you want to or need to finish cleaning it then continue when you can, but do realize that it can take 2 to 3 days in between answers since we are just that busy.
     
  7. tommy2k8

    tommy2k8 Private First Class

    Got some problems with this system.
    Ran SuperAntiSpyware, MalwareBytes and when I ran ComboFix, it kept saying 'incompatible with 2000 and XP'. But, it ran perfectly fine on Monday.
    Yesterday, I went back - no internet connection. Actually, it was reported to be connected, but it wouldn't assign an IP! So I ran SS and MBAM again, then ComboFix, then the internet worked!! However, Monday's scans and yesterday's scans with SS and MBAM yielded the same results, even though I'd quranatined them. I then ran MGTools, and followed the instructions.
    Now the system is still slow, and all I get when I click Turn Off, is the icons disappearing, wallpaper is still there, but the machine won't turn off!
    The logs (from yesterday's scans) are attached
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below files do not belong in this folder. If you need them, move them somewhere else. Otherwise delete them.
    Code:
    2009-08-03 15:52 . 2008-12-18 08:49 102400 ----a-w- c:\program files\DSort.exe
    2009-08-03 15:52 . 2008-12-18 08:49 102400 ----a-w- c:\program files\DCheck.exe
    2009-08-03 15:52 . 2008-12-18 08:49 102400 ----a-w- c:\program files\DCreate.exe
    2009-08-03 15:52 . 2008-12-03 10:46 94208 ----a-w- c:\program files\DDelete.exe
    Run the C:\MGtools\RemMWS.bat file by double clicking on it. This should run pretty fast and may not even give you any messages unless there is an error.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. tommy2k8

    tommy2k8 Private First Class

    This job is a bit different from my other jobs, in the sense that I've got to go to Swanley by train and back every time, and it's used in an office for business.
    I think it'll be cheaper to get them a new disk and do a complete reinstall.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's up to you what you would like to do. I don't think it is worth the money and time required to purchase a new disk and reinstall from scratch. Especially for things like MyWay and Viewpoint that remain. They are just minor annoyances that scanners will pick up. MyWay is really just an adware issue. In the most technical sense, it is not a real malware issue. You could even ignore these last issues if you wish as long as the PC is running properly. Just remember that some scanners will keep detecting MyWay.
     
  11. tommy2k8

    tommy2k8 Private First Class

    About a week after I discovered and removed the 'nasties' (or lack of them!) I did some disk performance tests, and discovered that the disk performance was much lower than a normal Maxtor disk!
    I hope this doesn't put you off dealing with my malware posts in the future
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes this can also occur for non-malware reasons too. ;)
    Nope! We know that we can most malware problems, and accept the fact that some malware cannot be removed and that sometimes the after effects of malware may necessitate a reinstall to properly fix the OS.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds