Malware removal process and logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by muchwork, Dec 1, 2008.

  1. muchwork

    muchwork Private E-2

    I discovered A9Installer (the icon was for set up so it was not yet installed) on my computer and did a google on it and came to your website with the forum that takes you through the long arduous process of malware removal. I performed the whole thing from beginning to end and have attached the logs in hopes that you will review them and let me know if all is well.

    There are a couple of things I encountered in the process you should be aware of:
    During the Combofix process the following things occurred:

    1. I received a message that a firewall had blocked a potential virus during the process (didn't write down what it said but i assume it is the one you mentioned called Huar.Invader...at least I think that's what you called it). I thought I had disabled the firewall (McAfee) but I am thinking maybe it was the windows firewall that I possibly failed to disable.

    2. I did not get the window that said: "
    Almost done...this window will close in a short while. Please wait a few seconds for the report log to pop up. ComboFix's log shall be located at C:\ComboFix.txt"

    Instead it went straight to a display of the log. I did a 'save as' to the desktop and closed the log and got a brown screen. No icons, no nothing. I then pressed Ctrl. Alt. Delete to reboot. I got the usual window and clicked 'end program'. Then I went to the 'shut down' tab and the drop down menu showed up and I clicked on 'restart'. The computer restarted just fine. However, my desktop was no longer of 'Mater' from the movie Cars it is now just plain ole brown.
     
  2. AbbySue

    AbbySue MajorGeeks Administrator

  3. muchwork

    muchwork Private E-2

    I think I forgot to hit the "upload" button the first time around.
    Also, I tried to send a second message so I could attach the 4th log in a separate message but, being new to this forum thing, I was unable to figure it out. I will try to figure it out again. Otherwise, I will wait until you reply again and send it then. Sorry for being such a dunce in regarding this. :confused
     

    Attached Files:

  4. muchwork

    muchwork Private E-2

    Last log attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm reviewing your logs now. Are you still having any malware problems right now?
     
  6. muchwork

    muchwork Private E-2

    No, I am not having any problems.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good because your logs say you are in pretty good shape. We just have a few minor things to do.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    As long as you get a success message from the below registry patch then you can continue on to the below final instructions.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. muchwork

    muchwork Private E-2

    I followed your instructions to the letter and I DID receive the success message about adding it the the registry.

    I proceeded from there with steps 1 - 9 you sent and I encountered a few things I have questions about. Below is a summary of each step:

    1. I kept SAS and Malwarebytes like you recommended.
    2. Combo fix uninstalled perfectly
    3. I deleted CCleaner with no problem. I tried to uninstall SpyBot Search and Destroy and received a two paragraph warning. The second paragraph gave the following message: " Are you really sure you want to completely remove Spybot-Search and Destroy and all of its components instead of trying the Undo functions first?" Is it OK to go ahead and uninstall it?
    Should I delete the logs I sent to you? Can I delete messengerdisable.zip and WindowsXP-KB310994-SP2Home-BootDisk-ENU.exe from the desktop?
    4. I deleted fixme.reg from the desktop
    5. Not Applicable - I am running XP
    6. I uninstalled Hijack this. I Received a message that it may have already been uninstalled and asked if I wanted to remove the name from add/remove programs. I clicked yes. Hope that was OK.
    7. Deleted C:\MGlogs.zip and C:\MGtools.exe file without a problem. When I tried to delete the C:\Mgtools folder I received the following message:
    "Renaming, moving or deleting MGtools could make some programs not work. Are you sure you want to do this?" I clicked no until I could get an answer from you that it would be ok. Can I click yes when I get this message?

    8. Haven't done this yet. Waiting to hear back from you on the above items before I proceed.
    9. Haven't done this yet either.

    I believe that covers all my questions. Thanks for all the help you are giving me. Your time and effort is MUCH appreciated! :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to uninstall Spybot. In fact it is part of what you will see in the link in step 9 (when you get to it) that you should install and keep.

    Did you read step 3? ;)

    Just delete the folder and ignore this warning as it is incorrect if you had already uninstalled HijackThis.
     
    Last edited: Dec 6, 2008
  10. muchwork

    muchwork Private E-2

    I completed number 8 and 9. Rather than using the AV and Firewalls you suggested I currently have McAfee so I thought I'd just leave well enough alone and maybe I'll change when it expires.

    Question - Mcafee occasionally gives me a warning of a PUP called Tool-NirCmd and tells me it blocked it. Should I allow this program or not? What is it?

    Also, during this whole Malware removal process I did encounter another warning from McAfee regarding PrcViewer. Should I allow this or not? I think I allowed it when it came up. Not sure though.

    If i purchese SAS and malwarebytes so they become real time do they perform like AV or are they in addition to that? Asking just so I know when the time comes that my McAfee expires.

    Regarding your instructions from #9 on SunJava. I seem to remember being instructed to do that during the Malware removal process and then to install the latest version from the SunJava website. I remember doing that. I now have a desktop icon that says: Java(TM)6 Update 10. Is that the right one?

    I use Firefox (have for a long time) but IE is still on my computer. Can I uninstall it or not? Because I don't use IE I didn't do anything regarding the Active X instructions. Should I do it even if I don't use IE?

    Lots of questions, I know, but I feel like since I've come this far I might as well be thorough about this. I saw that you recommended cleaning your computer twice a month. Does that mean using SAS and Malwarebytes or does that mean going through the entire process of Malware removal as instructed on this website?

    Thanks again for the help! :cool
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PUP = Potentially Unwanted Program which is most cases is nothing to worry about. NirCmd is a valid program (i.e., not a problem) put on your PC and used by ComboFix. Did you uninstall ComboFix? Did you toggle System Restore? You can delete the nircmd.exe file (if it still exists) if you want to avoid this message.

    This is also a valid program but you need to be more specific when you tell us a problem is being found. We need to know the exact full path to the file and the file name to make sure it is the valid program.

    They are not antivirus programs. They are antispyware programs. You still need an AV. Just like if McAfee does not include an antispyware program, you need one. Also if it does not have a firewall, you need one.

    They are up to update 11 now.

    NO!! You need it. It is an integral part of your Windows OS. You will not be able to access many websites without it and you will not be able to download all updates from Microsoft without it.

    Yes!

    Just running scans with the below are sufficient unless you have malware problems:
    1. your antivirus - make sure it is kept up to date
    2. SAS & MBAM - always update before running scans
    3. CCleaner to remove junk build up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds