Not sure if clean now - attached logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jjysp, Apr 3, 2010.

  1. jjysp

    jjysp Private E-2

    Laptop running Vista basic had mutliple malware. I found this great site and thank you. I followed all the direstions in the READ & RUN ME FIRST and have all the logs. I know it zapped a bunch of things and I fixed them as per the instructions, but I want to make sure that it is all clean. So please look at the attached logs and tell me if I need to do anything else. Much appreciated. Thanks!
     

    Attached Files:

  2. jjysp

    jjysp Private E-2

    Last log attached. Thanks!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are clean. You should just uninstall the outdated Java(TM) SE Runtime Environment 6


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. jjysp

    jjysp Private E-2

    Thanks! You guys are fast and great! I have one small (hopefully) problem now. I can only open IE as an administrator. Did I do something wrong?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! And according to your logs it does not seem to be related to any malware found via those scans. If you had run additional scans that removed malware before coming here or post secondary logs rather than initial logs, perhaps there were other problems we did not see due to this. I suggest you do the below.

    • Please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r

    Also see if there is any change to your ability to run IE. If still having a problem, see if there are problems running anything else. Make sure you have not created any policies to block running of any programs. If IE does not run without using Run As Administrator then what is the exact word for word error message you see?
     
  6. jjysp

    jjysp Private E-2

    Sorry for the delay. Log attached. The program Win32kdiag crashed the first time, but the second time it appears to have worked and the log is attached. No change with Internet Explorer. When I try to run it, nothing happens. No error message or anything, just nothing.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still does not appear to be a malware problem or an obvious permissions problem. You would be better off posting in the Software Forum for additional help. However, if you are trying to run IE from a shortcut on your Desktop, what happens if you Click Start, Run and enter iexplore.exe and click OK.

    Also a question! Do you know what the below folder is for? What is in the folder?
    Code:
    c:\users\Jodie\AppData\Local\larogb
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds