Malware instructions followed 100%, removal not initially 100% (details).

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mikeshoe, Jul 28, 2008.

  1. mikeshoe

    mikeshoe Private E-2

    Just wanted to let people know what happened to me, what I did to recover and to thank MajorGeeks for their helpful instructions.

    Prior experience removing spyware: successfully cleared numerous people's computers a couple years ago using tips offered on MajorGeeks.com. Since moving I hadn't had a single problem in nearly 2 years.

    What happened: I heard at work that Flash had a recent exploit and I should patch it. I searched on Google for "flash exploit patch" or something very close to that. I clicked one of the links that sounded promising. The website I clicked was a trap! Despite the barricade of (badly non-updated) anti-spyware I have installed I got infected badly. Antivirus XP 2008, Blue eff-with-you background and screensaver, redirecting browser pages, the whole works.

    My initial ill-advised attempt to fix it: I updated Adware (sp?) from Lavasoft and ran it. It found all kinds of problems and "fixed" them. And it would work. For about 5 minutes. Then the BS would just re-install itself and take over again. I figured, we'll just go ahead and restart in safe mode and clean up everything. EEEEEET. That was only temporary too.

    How MajorGeeks helped: I ran home to mommy (MajorGeeks forum). CCleanered myself, Updated Java and got rid of the old versions, followed all the instructions. This SEEMED to work. It definitely got rid of everything except the browser redirection. I kept hesitating about posting the logs, but if I had, I would've saved myself a fair amount of time trying to figure out what the hell was still letting my browser get hijacked. Combofix's little log section that lists what programs have been recently installed finally got my attention. Some folder named fqbhune with a file named genapiapl.dll inside it was present on hijack this logs. After several web searches couldn't identify the purpose of this folder/.dll I ejector-seated it with Hijackthis. I am now 100% clean. I won't let my scanners get that out of date again and I really appreciated all the basic pre-cleaning steps that were suggested.
    I'm certain that without MajorGeeks, I'd be in the fetal position crying because I'd have been forced to do a disk format. Thanks geeks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We are happy to hear it helped you.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds