XP Cleaning Procedure logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tammyjoey, Sep 7, 2009.

  1. tammyjoey

    tammyjoey Private E-2

    I was able to follow every step of the Windows XP Cleaning and the Read Me First section. I am attached my logs, but my AV-Kaspersky says I still have malware in my recycle bin, which is password protected and in my system restore.

    I received my first virsus when I was using google and click on an link and tons of the virsus detected stuff popped up. It looked like is was part of microsoft. I unplugged my network cable immediately. Then my computer worked ok still. That was 4 weeks ago. Then about 2 weeks ago my nephew went to a website called kohit.net and then that is when my AV detected virsus...tons of them. (FYI:I did advise him to never use that site.)

    Anyway, my computer is extrememly slow and my AV keeps detecting a hacker from site too. I have attached my logs and I combined 2 of the logs due to the 4 attachment limit.

    Thanks!!!!

    Please help!!!!!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks![QUOTE=tammyjoey;1382362]I am attached my logs, but my AV-Kaspersky says I still have malware in my recycle bin, which is password protected [/QUOTE] Not sure what you mean. Did you password protect your Recycle Bin or are you saying that Kaspersky is saying there is password protected malware in your Recycle Bin?


    The cleaning procedure remove any malware that you had. We do have some minor things to do and we will restore one file that ComboFix should not have deleted. However your slow PC issues are primarily due to what you are running at lack of adequate memory to run current versions of Windows and all the software you have running. Your logs shows the below:
    You need at least twice this much memory. That is you should have at least 1 GB.

    Don't worry about things in system restore. We will remove them when we get to final steps. If Kaspersky is finding problems elsewhere, you will have to attach a log showing what is being found since nothing shows in your logs.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\DeQuarantine.txt from combofix.
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. tammyjoey

    tammyjoey Private E-2

    "Did you password protect your Recycle Bin or are you saying that Kaspersky is saying there is password protected malware in your Recycle Bin?"

    No I didn't password protect my Recycle Bin...KA is saying there is password protected malware in my recycle bin. I have attached all my KA logs.

    Thanks so much for your help. I followed all of the steps. I am also attaching the logs you have requested.

    I am also getting a network attack. I am attaching that log too, named kaspersky.txt.

    I really appreciate all of your help. This site is amazing!!!! I am a computer teacher for Web and animation design. I will be sure to share with my high school students this amazing site!!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    The last time that was in your log was 9/6/2009. If you emptied your Recycle Bin and ran CCleaner it should be gone. It was not malware anyway. I suggest you also dump your Kaspersky log as there is too much old info in it.

    Not a problem. Kaspersky is just doing its job protecting you from a bot that is hunting IP addresses for unprotected systems. See more info in message # 1 of the below and also how to disable the warning message if it is bothering you.

    http://forum.kaspersky.com/index.php?showtopic=36390


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds