Malware? - Logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vegas78, Dec 31, 2008.

  1. vegas78

    vegas78 Private E-2

    Hi,

    I followed all the steps in your READ & RUN guide but don't think this fixed the problem. Could you help please?

    Internet Explorer is extremely slow in loading pages and frequently says it can't open them. Apart from this the computer seems to be running fine. I also run Firefox and this is much faster so I don't think it is my connection.

    The tools all ran fine apart from combofix said I was still running Avast and Mcafee Personal Firewal and Virus Scan. I had disabled Avast from its control panel but the programs were still running and when I tried to terminate them from task manager it said "access denied".

    The Mcafee products are weird relics. They came with the computer but I uninstalled them when I got it and thought they were gone. I have searched for any file or folder named Mcafee or MPF and can't find any trace of these. I have also searched the registry and used Ccleaner to check what is loading at startup. I have no idea where they are running from and no idea how to disable them.

    I had one other error message when running combofix which was "Find String (QGREP) Utility has stopped working". This popped up as combofix was preparing the log.

    thankyou!

    Ben
     

    Attached Files:

  2. vegas78

    vegas78 Private E-2

    here is the MGtools log...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The new version of ComboFix is a little flaky. You do not have anything from McAfee running and your Avast protection may have been properly shutdown when you started your scan, but after a reboot, it probably was back on.

    Your problems may not be malware. However we need to correct a few procedural issues first that were not run properly while running the READ & RUN ME.

    First you must run MSconfig and put your PC into normal startup mode as requested in step 1 of the READ & RUN ME. At least according to your logs it appears that many many items are trapped in the MSconfig registry keys. If you are not using MSconfig itself, are you using anything else to control startups. Like maybe Windows Defender or Spybot, or CCleaner? If so, disable whatever you have configured.



    Now we need to get both SUPERAntiSpyware properly updated. You are way out of date with both.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now for Malwarebytes, run it and update to the current database and run a new scan with it too. Attach the new log.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to get a log from the proper version of MGtools since you are about 2 months out of date with it.


    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.




    Run MGtools.exe then attach the below logs:
    • the new logs from SAS and MBAM
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. vegas78

    vegas78 Private E-2

    Hi,

    Thanks so much for looking at this. I have followed the steps and attach the new logs.

    With the McAfee thing, Windows Firewall in the control panel also sees McAfee firewall as running?

    Ccleaner had been set up to control startup items but I've disabled this now.

    I should also admit that I had Hijack this fix some other lines before I received your reply (including the WormRadar.com line).

    One final thing - when running MGTools I had the error message "SteelWerX Who Am I has stopped working".

    IE does seem to be running faster and I haven't received an error message for a couple of days so fingers crossed!

    Thanks again for your help,
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds