Please Verify I'm clean

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Klepton, Feb 12, 2013.

  1. Klepton

    Klepton Private E-2

    Hello, I started cleaning up a friend's wife's laptop last week by running SUPERAntiSpyware, Malwarebytes' Anti-Malware, SpyBot Search & Destroy and AVG Antivirus Free 2013. They found and deleted a few things, but wanted to verify that there is nothing bad left on the computer. I'm not seeing any odd behavior now, but I'd like a professional opinion on its current state before proceeding with the final cleanup steps. I've run the suggested programs and have attached the logs.

    Note 1 - I wasn't able to find the MBAM log from the first run, when I was trying to clean the computer not using your guide. It was not in the logs tab.

    Note 2 - I must say that I ended up having to run HitmanPro twice. The first time I ran it, I had to leave it unattended for only a few minutes and when I got back it had already finished and there was no log left behind. When I left it was uploading some results to the Cloud and was taking a while, so I figured it would take more than a few minutes to upload all of them. I remember there being about 4 and all had to do with a Google Earth Plugin. I thought I'd be able to see the same results, since the default setting is set to Ignore for most of them. However, when I ran it the second time there were not results from the scan.
     

    Attached Files:

    Last edited: Feb 12, 2013
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'm looking over your logs Klepton and will reply.

    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You should not be using MSconfig to control startups - please run MSconfig and put your PC into normal startup mode as requested.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall this undesired program:
    Viewpoint Media Player

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Files
    C:\WINDOWS\Temp\*.*
    C:\Documents and Settings\User\Local Settings\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}][/b]
    
    :Commands
    [purity]
    [EMPTYTEMP]
    [start explorer]
    [Reboot]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    With all devices that were previously connected when you ran the READ ME FIRST guide, please run the following online scan -
    Using ESET's Online Scanner

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\_OTM\MovedFiles log
    • ESETScan.txt
     
  4. Klepton

    Klepton Private E-2

    Oops, I must've missed that. I've enabled Normal Startup in msconfig.

    I've removed Windows Messenger.

    I've removed Viewpoint Media Player.

    I ran the HJT (C:\MGtools\analyse.exe) fix.

    I ran OTM with the given code. ***Note - I had to run this twice. The first time it ran (after I pasted the code) up until AVG flagged it as a threat and closed it. I then restarted the computer and this time disabled AVG while running OTM. I suggest you add this step (disabling antivirus before running this program) to your instructions. ***

    I ran the ESET Online Scanner and it found 3 threats.

    I ran the C:\MGtools\GetLogs.bat file.
     

    Attached Files:

  5. Klepton

    Klepton Private E-2

    When I ran the ESET Online Scanner and it found 3 threats, why did this find threats that the previous scans didn't? In particular, a worm/virus. Is AVG an inferior anti-virus than ESET? Or is it because these were re-enabled when I configured msconfig to startup in Normal Mode so that's why they weren't caught before?
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Personally, I regard ESET higher.
    Re: ESET scan results
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WildTangent9.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined <-- found in Spybot's quarantined folder
    C:\MGtools\Process.exe Win32/PrcView application cleaned by deleting - quarantined <-- a False Detection which you were advised of in the "Using ESET's Online Scanner" link
    Re-read the first sentence in that link! ;)

    *Let's see if anything remains from CouponPrinter-

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach the JRT.txt to your next message.

    Be sure to tell me how the pc is running.
     
  7. Klepton

    Klepton Private E-2

    The pc seems to be running fine now. I ran JRT and have attached the log.
     

    Attached Files:

    • JRT.txt
      File size:
      3.2 KB
      Views:
      2
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    "Antivirus software can't 'clean' a worm or a trojan, because there is nothing to clean - the entire file IS the worm or trojan. Quarantine plays a nice middle ground, because it moves the file to safe storage under control of the antivirus program - so it can't harm your system." It is prevented from executing any commands or functions by Spybot... but is still detected being present on your hard-drive by ESET.

    To empty SpyBot's Quarantine
    Quarantine can be either launched via the Start Center or can also be found in SDTray’s program list.
    Just right click on the Spybot – Search & Destroy icon in your traybar beside the Windows clock and navigate to “Basic Tools“ → “Quarantine“. Once “Quarantine“ has been started just hit the purge selected button.

    Noted - "Thanks".

    _______________________________

    * If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. It provides no "real-time" protection unless you purchase it and does not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 4 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. If running Vista or Win 7, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and/or deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  9. Klepton

    Klepton Private E-2

    Unfortunately, this computer no longer has Spybot S&D installed. That threat must've been quarantined previously. Do I need to re-install it and if so, will it appear in its Quarantine folder? Or, is there another way to remove it?
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Using Windows Explorer, manually delete these folders if still present:
    C:\ProgramData\Spybot - Search & Destroy
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
     
  11. Klepton

    Klepton Private E-2

    Ok, I deleted the C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy folder. Since this computer is running Windows XP, it does not have a C:\ProgramData folder. So I'm assuming I can now move on to the "* If you are not having any other malware problems, it is time to do our final steps:" section?
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Yes
     
  13. Klepton

    Klepton Private E-2

    1. Ok, so I'm keeping MAM and the .exe for the ESET Online Scan.
    2. I re-enabled the Disk Emulation software and had to reboot.
    3. N/A (Windows XP)
    4. I could not find HijackThis anywhere to uninstall.
    5. I ran the MGclean.bat file and it gave me an error about not finding a specified file. However, it seemed to work as it cleaned everything from c:\
    6. N/A
    7. I deleted HitmanPro
    8. I Disabled System Restore, rebooted, then re-enabled it.
    9. Will do...

    One last question: I use CCleaner a lot! Is the included Registry cleaner safe to use or do you recommend a separate standalone registry cleaner?
     
    Last edited: Feb 15, 2013
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If I had the need to use one, it would be CCleaner's... bearing in mind all of the precautionary advice chaslang gives in this post:

    http://forums.majorgeeks.com/showpost.php?p=1692149&postcount=74
     
  15. Klepton

    Klepton Private E-2

    Ok, thank you very much! I appreciate all your help and guidance!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds