looking for a check up

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Scott0, Jun 27, 2009.

  1. Scott0

    Scott0 Private E-2

    Geeksters,

    Please review attached logs. All should be ok but you never know. Fifth log to follow. ;)

    S.
     

    Attached Files:

  2. Scott0

    Scott0 Private E-2

    5th log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember to always post all logs in one thread. You just needed two messages. Not two threads. I merged your other thread back here.

    Note you did not use the current version of MGtools. Please remember to always download and use the current version as instructed. You should not be saving old versions.

    Your logs are clean but you may want to restore the below which MBAM mistaken removed because you saved it in a bad location (your Desktop)

    toshibam1202driversforwindowsserver2003drivers_3393.exe

    And the above leads me right into the below.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing. And in addition, some file save here will be detected as malware and will be deleted automatically by many scanners.

    Why are you running this PC with no protection? You need to do all of the below ASAP.
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Jun 29, 2009
  4. Scott0

    Scott0 Private E-2

    Thanks for taking a look at this for me. I have just a few questions.

    Went over instructions for MBAM and found nothing stating that it “should not” be downloaded to the desktop and/or run from there. Maybe I missed it again with the second reading. It was put there with the intent of removing it after following the instructions. Then use something else in it’s place. But hence forth I will never run any program from the desktop unless specifically instructed to do so.

    Followed your instructions but I could not find the MGclean.bat file to run it. Opened the c:\MGtools folder but found no MGclean.bat file. Arranged the view to show bat files grouped together to make sure I was not over looking it. did not findit. Is there a way to get this file to run it? Thought I had the latest MG tools. Is there a problem with downloading the new version and overwriting the old version? Should I do another download and run the program again?

    Followed the remaining procedures with no problems. I will move all the folders from the desktop and add the protections you mentioned.
    Is there a way to add a 5th attachment to a thread other than replying to one's own previous message? My thought being that it looks like someone has looked at the thread because of the reply icon that appears. I would think (maybe wrongly so) that someone would think that a problem was being worked on.

    Always looking to get better at this.

    Scott0 :-o
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was not referring to MBAM. I was referring to the fact that you put toshibam1202driversforwindowsserver2003drivers_3393.exe on your Desktop and that was probably why MBAM detected it as malware. However it is a bad practice to save things to your Desktop. In forums like this, we do this but only as a temporary measure to make them easy to find and run but when we finish, we remove them.

    That was because you did not have the current version as I had mentioned in my previous message. You can just use the below older version of instructions.

    You just simply add a second message to attach it. This does not cause any problems. You would still be the last person who posted which means that you are now waiting for one of us to respond.



    Old form of final instructions:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix and C:\QooBox folders from combofix (if it exists and note that you may need to substitute a different drive letter than C: if you have Windows installed on a different drive.)
      • Also delete the below two files that are left behind by ComboFix, some scanners falsely detect these as problems which they are not:
        • C:\WINDOWS\NirCmd.exe
        • C:\WINDOWS\PEV.exe
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. Scott0

    Scott0 Private E-2

    Chaslang,

    Thanks for the info. Was able to perform all the functions but could not find C:\WINDOWS\NirCmd.exe or C:\WINDOWS\PEV.exe. Other than that all seems to be well. Again thanks for the help.

    Be back soon, :wave

    Scott0
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds