Where to ask for help with cleaning malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by paultomasi, Jul 10, 2010.

  1. paultomasi

    paultomasi Private E-2

    Where and how do I post, to receive help with cleaning my system.

    I have completed the "Windows XP Cleaning Procedure".
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have followed the Read and Run First instructions, you need to attach the following logs:
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGLogs.zip
     
  3. paultomasi

    paultomasi Private E-2

    TimW

    Thank you very much for your reply. I was about to give up and seek help at bleepingcomputers...

    I will post the logs in a moment.

    I note at least one of the logs lists names of recent documents and web sites I have visited. Will any of this be visible to other browsers (members or non-members?)?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Members only. And if there is an issue with that, we can remove the items after reviewing them for malware. :)
     
  5. paultomasi

    paultomasi Private E-2

    TimW

    Once again, thank you very much for your reply.

    I will reply with attached files however, I may disguise the names of documents recently created (without effecting the rest of the log file).
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's entirely up to you. I am about to log off and will not be back on to check malware threads until tomorrow afternoon. Just be aware that my only interest is to find and remove malware on your system, not to make judgments. :major
     
  7. paultomasi

    paultomasi Private E-2

    TimW

    Thank you for your reply.

    I have reviewed the files and there is nothing or major concern however, I do need to include a short write-up of how the various scans performed and the nature of recent problems. This may not be ready until much later so I will looki forward to your reply tomorrow.

    Thank you for your time and patience.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the files when you are ready.
     
  9. paultomasi

    paultomasi Private E-2

    Dear TinW

    Thank you for being patient.

    My computer crashed horribly this morning (with a blue screen. See below) and for the small amount of time available to me, it took all day to get it up and running again (required a lengthy CHKDSK /F /R).




    ==============================================
    ATTACHED FILES
    ==============================================

    SAS.log
    mbam-log.txt
    rootrepeal.txt
    MGlogs.zip
    ComboFixFolder.jpg

    I do not have a ComboFix log file.




    ==============================================
    SCAN RESULTS ("Windows XP Cleaning Procedure")
    ==============================================

    ---------------------
    (1) SUPER ANTISPYWARE
    ---------------------

    Detected 2 Macromedia tracking cookies.
    Quarantined
    PC rebooted itself.

    Re-ran SAS configured to start scanning from parent folder of where the Macromedia tracking cookies were reportedly found.

    Detected 2 Macromedia tracking cookies.
    Quarantined
    SAS ended normally this time.




    ----------------------------
    (2) MALWAREBYTES ANTIMALWARE
    ----------------------------

    OK




    ------------
    (3) COMBOFIX
    ------------

    C/F prompted to search for updates. I answered 'Yes'.
    (Did not notice how many stages completed)
    (Did not notice any messeges displayed)
    Computer crashed with the following Blue screen:

    A problem has been detected and Windows has been shut down to prevent damage to your computer.

    BAD_Pool_Header
    etc...

    Stop 0x00000019
    0x00000020 (0x884E60DB, 0x884E64F0, 0x1A830001)
    etc...


    Re-ran C/F.


    C/F prompted to search for updates. I answered 'Yes'.
    Completed 50 stages.
    Briefly displayed messege in same DOS box "Deleting file...". (Didn't notice a filename).
    Computer crashed with with the following Blue screen:

    A problem has been detected and Windows has been shut down to prevent damage to your computer.

    BAD_Pool_Header
    etc...

    Stop 0x00000019
    0x00000020 (0x88974158, 0x88974570, 0x1A830007)
    etc...




    --------------
    (4) ROOTREPEAL
    --------------

    OK




    -----------
    (5) MGTOOLS
    -----------

    During the phase: "Running Processdll.exe to find loaded DLLs", a dialog box titled "processdll.exe - common language runtime processing services" popped up stating:

    Application has generated an exception that could not be handled.

    Process ID = 0x840 (212), Thread ID = 0xECC (3788)

    Click OK to terminate...
    Click Cancel to debug application.

    Clicked OK to cancel
    Manually restarted PC
    Re-ran MGTOOLS

    During the phase: "Running Processdll.exe to find loaded DLLs", a dialog box titled "processdll.exe - common language runtime processing services" popped up stating:

    Application has generated an exception that could not be handled.

    Process ID = 0xCC0 (3264), Thread ID = 0xAC (172)

    Click OK to terminate...
    Click Cancel to debug application.

    Terminated process in Windows Task Manager.
    MGTOOLS completed and created ZIP file.




    ==============================================
    CONSIDERATIONS
    ==============================================

    Computer crashed with the following blue screen while unattended this morning.

    A problem has been detected and Windows has been shut down to prevent damage to your computer.

    KERNEL_STACK_INPAGE_ERROR
    etc...

    0x00000077 (0xC0000185, 0xC0000185, 0x09358000)
    etc...


    Performed a CHKDSK /F /R

    --------------------------------------------------------------------

    I currently have a file on my desktop called "CFScript.txt" containing the following single line:

    KillAll::

    --------------------------------------------------------------------

    I have a C:\ComboFix folder which shows up as a small blue-screen computer in the Folders list of Explorer. When I expand the folder by clicking on the [+], it displays the same info contained in Desktop\My Computer. This is a recursive folder. See attached image.

    A symptom of this is: When I perform a Windows Search, the Search Results continually repeats the same results for each level the search recurses down to.

    I am worried that if I make changes to this folder, It will reflect in ALL higher folders. Similarly, if I delete the ComboFix folder, I am worried it may delete EVERYTHING from my drive. - Please confirm what I should do about this.

    --------------------------------------------------------------------

    I routinely manually delete files from my Temporary folder - which explains the absence of 100's of files.

    I routinely delete Cookies using Internet Options - which explains the absence of many files.

    I routinely manually delete entries from:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    and

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

    which explains the absence of many startup entries.

    Most of the batch files scattered about the drive are my own creations - I write DOS batch files so please do not be overly concerned about these.

    --------------------------------------------------------------------

    Thank you kindly for your help.
     

    Attached Files:

  10. paultomasi

    paultomasi Private E-2

    Dear TimW

    Here is the JPG image of the ComboFix folder as described in my previous comment.

    Thank you.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. What symptoms are you experiencing?
     
  12. paultomasi

    paultomasi Private E-2

    TimW

    Thank you for your VERY speedy reply.

    (1) I just have a 'gut-feeling' (paranoia perhaps) that all is not what it should be.

    (2) On at least 2 occasions my mouse has stopped responding - required a reboot.

    (3) Unexplained disk activity.

    (4) 3 recent Blue-Screen-Of-Deaths

    (5) Inability to successfully complete ComboFix, MGTools and a recent GMER scan without problems (is 'something' trying mask detection?).

    (6) Occasional (rare) ad popups

    Just niggly little things....
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest that you post in the software forum for additional assistance. If you have your OS disc, you can try going to start/ run / and type:
    sfc /scannow.

    As for the BSOD's, right click my computer, properties, advanced, and set the recovery from errors to not automatically restart the computer. That way you will have the exact error message and will see what is causing the error.
     
  14. paultomasi

    paultomasi Private E-2

    Dear TimW

    How do I deal with the ComboFix 'folder' left on my system?

    Thank you for your valued time.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Here are the final cleanup instructions, which will deal with Combo, among other items.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  16. paultomasi

    paultomasi Private E-2

    Dear TimW

    I have completed all you have instructed me to do so.

    Thank you for your valued assistance and time.

    Paul.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds