the 4 logs after malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by peteschulte, May 18, 2009.

  1. peteschulte

    peteschulte Private E-2

    :)Thanks much; my machine is better than it's been in months.
    Where I posted my logs, I was instructed to post here. See the bottom of this note for more.

    Still unable to use FrontPage to access my webhost. Created a support ticket. They were unable to recreate the problem.
    Had attacks handled by Zone Alarm today from _restore.

    So after you guys / gals check these, I'll be glad to toggle restore. Waiting to see if further action is indicated. Salamata, danke, arigato gozaimasu, THANKS!
    peteschulte

    SUPERAntiSpywareScanLog-05-17-2009-13-10-49.log:
    You have already attached this file in thread : First Hello & activation resend request
    mbam-log-2009-05-17 (14-06-17).txt:
    You have already attached this file in thread : First Hello & activation resend request
    ComboFix.txt:
    You have already attached this file in thread : First Hello & activation resend request
    MGlogs.zip:
    You have already attached this file in thread : First Hello & activation resend request

    Looking forward to your reply in my email Inbox. Thank you so much for your work!


    :) Wow I am really grateful to you all for this process.

    Afterward, today I was able to get a Zone Alarm update for the first time since December. My computer now shuts down and starts normally, with the boot up time cut in half. I consider it fixed. Before, there were a number of errors in boot up -- such as the system couldn't find my profile (desktop icons) -- which have been corrected.
    I'm still failing one benchmark. FrontPage connection (log on) to my web host does not work. The same user name and password allow me to log on to my web host from Firefox, but not FrontPage. I created a support ticket at the web host. I'll check back for any word from you guys / gals.

    Again, thanks so much! Where can I make a contribution? :clap
    peteschulte
     

    Attached Files:

    Last edited by a moderator: May 19, 2009
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are in pretty good shape now after running the cleaning procedure. We just have a few additional things to do.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software which are very ineffective and you are much better off with SUPERAntiSpyware and Malwarevytes that we had you install:
    Ad-Aware 2007
    Ad-Aware SE Personal


    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. peteschulte

    peteschulte Private E-2

    Re: instructions after the 4 logs

    Thank you Chaslang :)

    for these instructions. I'm looking forward to the process tomorrow and will send the logs. It's an awesome service you offer at the MG Forum!

    peteschulte
     
  4. peteschulte

    peteschulte Private E-2

    :) Hello chaslang and malware experts,

    I followed the instructions with the only hitch being that when ComboFix restarted the machine, Zone Alarm started. There's more detail in the attached text file. It also describes why the CCleaner results are attached.

    Here's a post-cleanup question. Should I keep Zone Alarm? I have the paid version. In other words, what protection tools do you recommend that I keep running?

    I never get tired of saying THANKS to you guys. I had given up on getting results short of taking the computer to the shop, after trying to communicate with tech staff at Kaspersky and Zone Labs. Miracle, miraglo! Arise and walk!
    thanks! :cool
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Please keep all correspondence directly inline in the thread which makes it easier to respond to. There is nothing that CCleaner removed that you needed. Also we did not want you to change and of the check boxes. Everything on the initial Windows tab are temp files. We just want you to only click the Run Cleaner button and not run anything else (like Issues which edits the registry).


    Your log shows ZoneAlarm AntiVirus. I believe they use Kaspersky's AV. Does this include their firewall? I assume it does based on the temp files from it that I see in your logs. It does not appear to be running based on your logs. I see no processes for it listed. Did you kill it before you ran MGtools? You only needed to shutdown protection while running ComboFix.

    Our final instructions (below) will cover this.

    Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. peteschulte

    peteschulte Private E-2

    Re: Finished! plus a question and alert to your broken link

    Hi chaslang,
    Yes, I had turned off Zone Alarm while running combofix and the other programs. I have the paid version which appears to be working fine now. It's on your list as an approved firewall, so I'll keep it.
    I worked through all of the steps, purchased both scan programs, flushed and created system restore, turned off autoruns, ran Spybot S&D and finished with my TuneUp tools.
    Wow, that was great for the results and for learning. Whew it was a lot of work! The laptop is next.

    Here's the question. Why do I have two connection icons running? See attached. My Internet service is through Qwest with a USB cable. In addition we have a wifi network for the laptop upstairs. Does that explain it? But this shows activity while the laptop is turned off. Is it in-going and out-going? But I'm not aware of sending anything out while it is showing activity. BTW, I emailed this question to Qwest support and they replied that they were unable to form a support ticket from it.

    I found a broken link in "How to Protect Yourself from Malware" item 11, http://www.spywareinfo.com/articles/p2p/ -- This looked valuable to me and I would like to know if it is restored.

    Thank you again for the instructions and resources! :major
    peteschulte
     

    Attached Files:

  7. peteschulte

    peteschulte Private E-2

    Re: 24 hours after--an issue persists

    Hi chaslang,
    "Make sure to tell me how things are working after." Well, their 1000% better, but I still have this delay where I get the hour glass about every 10th click or every five minutes.
    Then I have to wait about 30 seconds while the machine does something. Any guess what this is and how to prevent it? :confused
    Could it be something with the NVIDIA card which I inherited with the machine and the 22-inch HP monitor, which I've only had a few months. The latter is running in analog.
    Could Task Manager help me to observe it starting and stopping and identify it?
    Thank you,
    Peter
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Finished! plus a question and alert to your broken link

    You're welcome.

    Not sure but it looks like you are using something as a gateway to the internet. Meaning you pass thru some other device. Yes it could be something related to your USB cable interface. You can post about this in the Hardware (or possibly better still the Networking) Forum since it is not a topic for the Malware Removal Forum.

    Thanks for reminding me that I needed to update this link to the new URL. ;) which is http://www.spywareinfoforum.info/articles/p2p/
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: 24 hours after--an issue persists

    Unknown. You will have to do some experimenting to see if you can isolate the cause. Things like
    • Test to see if it happens in safe boot mode.
    • Test to see if it only happens when a browser is open
    • Test to see if you disable various startup processes and services whether it still happens (i.e., check to see which application could be the cause).
    What is Voxeo doing?

    Use the below instead of Windows Task Manager to check what is running and what load is being placed on the system. Task Manager is not very good and does not always show all processes.

    Process Explorer
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds