If I only had a brain....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MarinaJ, Jan 28, 2010.

  1. MarinaJ

    MarinaJ Private E-2

    Hi,

    Could someone please look at my logs. I do not have a Super Anti Spyware log because it causes conflicts with my Zone Alarm Anti Virus/anti spyware. I did have it once and Windows kept telling me I had multiple AV protection and it took while to get rid of all of it.

    I do have issues of screens like Outlook Express popping up and I never use that. I cannot change winlogon.exe and csrss.exe from high priority. My computer freezes alot with screens popping up for no reason which is very unnerving!!! After I closed Combo Fix, I also had a IE8 icon my backtop appear and Firefox is my default browser. I seldom use IE. My spyware blaster is daily missing its firefox protection and I have to go in and recheck it, just to have it unchecked the next day. Also, I have a question, lately my Zone Alarm is saying that Malwarebytes wants to open a raw disk device to scan and I never saw that message before, is that legit and okay to do? I also see WMI for windows wants to a lot. I run weekly scans and sometimes more but nothing shows up.Sometimes my computer starts up differently too. The black screen like the safe mode screen flashes for a moment and sometimes it doesnt. (Sorry I dont know the proper terms for these screens.

    Thanks for all your help, I really appreciate it!
     

    Attached Files:

    Last edited: Jan 28, 2010
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, MarinaJ


    Please attach this requested log also:

    C:\combofix.txt Jan 27 2010

    Once you do - you will be in our work queue, where the oldest threads are worked FIRST.

    dr.m
     
  3. MarinaJ

    MarinaJ Private E-2

    Sorry, here it is. If you need anything else, just let me know. Thanks!!:)
     

    Attached Files:

  4. MarinaJ

    MarinaJ Private E-2

    Oh, I forgot to tell you. I did exactly as you stated and turned off my firewall and my AV protection with running MG tools and it worked fine, I think. I also did not get any pop up windows but I all ready had HiJack This installed. Naturally, I then turned on my firewall and my AV again after I had the log file sitting on my desktop, then Zone Alarm called it a virus trojan-dropper.win32.agent.blds and now it is sitting in quarantine. I'm just leaving it there for the moment until you advise me. Thanks again
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, MarinaJ

    SUPERAntiSpyware is NOT an anti-virus program and as far as we know it does not have problems with ZoneAlarm......especially the free SUPERAntispyware which has no active protection, it is a "On Demand" scanner only. We have had many, many people run it who have ZA Security Suite installed.

    I have not detected any malware in your logs - your main issues are these:
    1) You have not updated your OS with XP SP3
    2) You cannot run ZA Security Suite and most other applications with this small amount of RAM installed:
    Before I give you the cleanup steps, please answer this question:
    * Exactly what did Zone Alarm detect and quarantine?
     
    Last edited by a moderator: Feb 1, 2010
  6. MarinaJ

    MarinaJ Private E-2

    Hi Dr. Moriarty,

    Thank you for your quick reply. I did try to download SP3 quite awhile ago and couldn't do it. Then I read it many people had trouble with it and then I didnt try again. So, if you want me to after all this or before, just let me know if I should try before the cleanup? Also, with the RAM, I know physical is different than the virtual and when I had Advance System Care I think it would do something to help compress files or do something with my RAM but I don't know if that is the same thing? I want to get Advance System Care too again when I can download again. If not, are you suggesting I purchase more RAM?

    Zone Alarm stated Infection: Trojan-Dropper Win32.Agent.blds then Path C:\MG Tools.exe. But that is all it says on the screen. After I did everything and put ZA back on it immediately put it in there.

    One more thing, about IE8, it says Default Search Assistant Sub_RFC 1766 and I did a search and it stated when MS does it monthly tests for virus with their downloads after it finds something bad and repairs it, sometimes that is what happens to the search and I dont know how to change it and if leaving like that poses a threat to my system. I dont use IE8 but use Firefox. If you have any advice with that issue, I would greatly appreciate it.

    Thanks again,
    MarinaJ
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome!

    Yes, I strongly recommend that you increase your installed RAM to at least 1gb.

    *Zone Alarm's detection of MGTools.exe is a False Positive, but we've finished using it. Remember to empty out ZA's quarantine folder AFTER running our cleanup procedure.

    Your other questions about updating to XP SP3, and "Default Search Assistant Sub_RFC 1766" are topics that should be worked in our Software Forum
    .

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:

    Safe surfing! [​IMG]
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    However it is normal and the default. ;)
    .
     
  9. MarinaJ

    MarinaJ Private E-2

    Thanks a bunch, Dr. Moriarty, I will do that. Take care,
    MarinaJ:)
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Thanks, chas.

    and - "You're Welcome, MarinaJ - hope to see you around the other forums."

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds