Logs from Malware Removal Guide - Just want to be sure I'm clean

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by DJNova, Jul 27, 2011.

  1. DJNova

    DJNova Private E-2

    On 18/07/11 I went to a page from a Google search. After a couple of seconds on the page it closed and a fake anti-virus, simply called Defender, popped up and started "scanning for viruses".

    Despite my better judgement, I panicked and clicked "stop scan". I immediately realised my mistake and started trying to kill it. I first tried to open Task Manager, but that instantly closed and Defender told me that Task Manager was infected with a virus. Next I tried to open command prompt, but the same thing happened. My next attempt was to try to open McAfee Security Centre, but as I moused towards the icon, it disappeared. I was starting to get desperate and was even trying stuff that obviously wouldn't work (ESC, Alt+F4, what have you).

    After I eventually managed to kill it (which, unfortunately, I don't actually remember how I did), I followed the path of the shortcut it left on my desktop and put it through McAfee's Shredder, then did the same to the shortcut itself. After this I ran full scans with SUPERAntiSpyware, Spybot - Search & Destroy, Malwarebytes' Anti-Malware and McAfee; which found various Trojans, Adware and Keyloggers in both my files and registry. I continued running precautionary scans over the next few days, which picked up a few stragglers.

    However, scans kept coming up empty after this, but my machine has still been running slower than usual and Zemana AntiLogger is reporting all kinds of activity. IE has also been randomly having issues; mostly randomly crashing, hanging and performing overall sluggishly.

    In my search for a more thorough method of flushing out Malware I stumbled upon this site. I went through your Malware Removal Guide and did it all with no problems, except for not running RootRepeal due to having a 64 bit OS.

    I have attached the required logs and would really appreciate some help on this matter, as my knowledge of Malware is limited at best. I am particularly concerned about there being some form of keylogging/screen capture/etc going on, as I frequently use online banking and various forms of e-commerce, and being unable to do any of these things until I am sure my machine is clean in very inconvenient.

    Thanking you in advance

    DJNova
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Do you use a proxy server? If not, then fix this:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = hipxy:80

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?
     
  3. DJNova

    DJNova Private E-2

    Thanks for the quick reply.

    I use that proxy at TAFE, so that's fine.

    As for my computer running slowly, booting has been taking longer than usual, especially after logging in; it can take almost a couple of minutes before I can do anything, and prior to being attacked by Defender it took maybe 15 seconds.

    It also has been getting slow and laggy when multi-tasking, especially tasks with high memory usage like 3D modelling. Since running through the Malware Removal Guide though, these both seems to have cleared up.

    Now the only thing running especially slow is IE. It takes a long time to start up and almost as long to open a new tab. I haven't had it crash or hang yet since doing the Malware Removal Guide.

    Everything seems fine in Task Manager.

    I have another question too, if it's not to much trouble. After my first manual reboot after running through the Malware Removal Guide I noticed a couple of hidden files on my desktop that weren't there before. One is a temp file from a word document I had on the desktop months ago, and the other 2 are both .ini files named desktop. I have attached a screenshot of the desktop.inis. Is it okay to delete these?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't need to delete those files, as MGTools has set your system to show hidden files. Once we do the final cleanup, those will become hidden again.

    I suggest you post in the software forum for your issues with IE being slow.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  5. DJNova

    DJNova Private E-2

    Thank you very much for your help. Everything's gone off without a hitch and now I can finally stop being paranoid about keyloggers.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds