Done "Read & Run Me First" to remove Malware... all seems better except

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mikeRa20, May 11, 2008.

  1. mikeRa20

    mikeRa20 Private E-2

    my wall paper is white and right clicking on it and selecting properties comes up with "Internet Explorer Properties"

    my intial problems started with clicking an active-x add on.

    issues included:

    - malwarrior 2008 pop ups

    - blue wallpaper with msg: "Warning Spyware detected on your computer: Install an antivirus or Spyware remover to clean computer"

    - "adware.W32.Spyshredder was detected" msg

    - task manager disabled

    - roches eating screensaver

    - "Not found: c:/windows?privacy_danger/index.htm Make sure path or internet address is correct" msg

    - Windows script host msg: Could not find c:\Documents & Settings\local settings\temp\ttF.tmp.Vbs



    my logs are attached.

    any help will be much appreciated.
     

    Attached Files:

  2. mikeRa20

    mikeRa20 Private E-2

    here's the combo fix log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    What are these:
    C:\Documents and Settings\2\Desktop\default.xex
    C:\Documents and Settings\2\Desktop\Woodmn

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now empty:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\2\Local Settings\temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  4. mikeRa20

    mikeRa20 Private E-2

    hey TimW thanks for the help much appreciated.

    i did the MGtools anayalyse and fixed the line you told me to.

    however when trying to merge fixME.reg with the registry the following msg came up:

    "Cannot import C:\Docucments & Settining\2\Application Data\Microsoft\Internet Explorer\fixME.reg: specified file is not register script. You can only import binary reg files"

    i did the save as type "all files" and with option ANSI. the other options were Unicode, Unicode Big Endian and UTF8. Which one should i select?

    also i dont think i have avenger. should i download load it? and how do i get logs from it?

    C:\Documents and Settings\2\Desktop\default.xex: I have no idea what this is. it was created a year ago, last acssed recently.

    C:\Documents and Settings\2\Desktop\Woodmn is just a folder with a few word documents of a mates resume.

    thanks again.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry..we didn't use avenger..so not to worry with that.

    Did you save what I wrote in the quote box to notepad and then title it fixMw.reg when you save it and select "all files" as the type?
     
  6. mikeRa20

    mikeRa20 Private E-2

    yeah i did save it as type "all files" and encoding "ANSI" should i just try it with the other 3 encoding types?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This indicates to me that you did not highlight the text in the quote box and then open notepad and paste it in.....then save the notepad as directed.
     
  8. mikeRa20

    mikeRa20 Private E-2

    got it working... i had cut and pasted from my email and it had an * included at the start and end of the quoted text.... sorry

    here's the GMtools log

    thanks
     

    Attached Files:

  9. mikeRa20

    mikeRa20 Private E-2

    hey i forgot to empty
    C:\WINDOWS\Temp\
    C:\Documents and Settings\2\Local Settings\temp\

    before running C:\MGtools\GetLogs.bat.

    have done so now and re run C:\MGtools\GetLogs.bat here's the new log.

    i still have to same problem with my wall paper.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good......now as far as your desktop...you need to right click it / properties / desktop / customize / web / and make sure there is nothing there...

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  11. mikeRa20

    mikeRa20 Private E-2

    everything seems fine now.

    thanks heaps for your help
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're very welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds