Am Concerned I haven't caught everything....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ezeidan123, Jul 17, 2008.

  1. ezeidan123

    ezeidan123 Private E-2

    Hi this is my first post on your forum and I hope I'm doing this right.
    My OS is XP Home Edition: I was having problems with my PC running slow, freezing, crashing. Before I found your website I thought it might be my startup items so I ran through the list on Google and found a couple of items that were listed as possible Malware. I found your site had valuable info and used your Tutorial on removing Malware. I ran all through all the steps but was not able to run ComboFix it would just not run. So I am attaching all the other logs I have. I finished your guide all the way thru. At the time when things were the worst I was using a hardware firewall as well as Comodo Firewall Pro, AVG8. I also used A-Squared Free, CCleaner and Spyware Blaster. I continued to have problems after all the cleaning with my CPU usage up to 100% but nothing showing up on the Task Manager using that much. I think I had a conflict with Comodo and AVG and have since changed to Avast and it seems to be working better (no freezing). I would just like to know that I have gotten rid of everything or if there are still problems I am not aware of since I have not opened the MGTools log (not that I would know what I am looking at). I am not a novice but not really an intermediate. So any help would be appreciated. I use this computer for a home business and would really like to make sure it is safe. Thank you in Advance for any help you can share.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please complete the below instructions in the order they are written.


    Download Registry Search (see the link titled RegSearch Download Link)
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter TBSSaver in the top area of the form and then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.
    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O24 - Desktop Component 0: WebSearch Active Desktop - C:\PROGRA~1\Toolbar\SSAVER\BIN\TBSSaver.html

    After clicking Fix, exit HJT.



    Fixing Locked Desktop
    • Right click on your Desktop and select Properties.
    • Then click the Desktop tab
    • then click the Customize Desktop button.
    • Now in the next window that comes up click the Web tab.
      • Make sure at the bottom that Lock desktop items is unchecked.
    • Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK.
    • Click Apply. And click OK.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • the log from RegSearch
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. ezeidan123

    ezeidan123 Private E-2

    Hi
    Okay I ran exactly as you posted. In reply to the message I got in my email:

    Here is the message that has just been posted:
    ***************
    I am assuming that you uninstalled AVG and installed Avast after you ran the MGTools?

    Please delete this folder:
    C:\327882R2FWJFW
    C:\PROGRA~1\Toolbar

    Now right click the desktop / properties / desktop / customize / web and remove everything that is there except the default " My Current Home Page" and make sure no boxes are checked.

    We want to remove this: O24 - Desktop Component 0: WebSearch Active Desktop - C:\PROGRA~1\Toolbar\SSAVER\BIN\TBSSaver.html

    Now tell me what issues you are still having.
    ************************************************
    I did this part first, then went on to the post. Yes, I changed AVG after I ran the MGTools. I deleted the first folder but could not locate the second folder.
    I ran the rest of the post exactly as you stated. I did get a "Success" message on the fixme.reg
    Since posting the request I have had better luck with Avast. But I am now getting a pop-up for OPXPAPP.exe stating that it's missing. This only happens when I completely shutdown and start back up but not on a restart. I am still getting some "freezing" of windows but it comes back after a few seconds rather than completely being unavailable. While I was waiting for a reply I downloaded and ran Registry Booster from Uniblue. I thought it would help, let me know if I've made a mistake (?). I also added the Comodo BO Clean. I have been monitoring the CPU usage and it seems to be back to normal. When I ran the Regsearch it seemed to have started working and then did nothing for a while then the NotePad opened after about 10 minutes. So I ran it again and this time it showed that it was actually scanning something and was done in about 2 minutes. okay the logs are attached. Thank you for your help so far, I appreciate it.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure how this could be missing since it was showing as a running process in your last logs. It is for Softex OmniPass so either way this is not a malware issue.

    • Try uninstalling A-Squared and then reboot.
    • Did that help?
    • If not, then uninstall Comodo Firewall and then reboot.
    • Did that help?
    Yes is was a mistake. For future reference, anytime you start working in any forum like this (not just our forum) do not do anything on your own. Only do what is requested and nothing else. If you are going to work on your own then you should not be posting for help. ;) And we avoid using registry cleaners in the malware forum. I suggest you uninstall that program too.
     
  5. ezeidan123

    ezeidan123 Private E-2

    Hi
    Sorry it's taken so long to respond. I followed all your guidelines in your last response. I am sorry about going out on my own my "first-timer" mistake :eek:, won't happen again, if there is a next time.
    I uninstalled the A-Squared and it didn't help, I uninstalled Comodo and I was still having problems so I re-installed Comodo, uninstalled Avast and installed AntiVir. It seems to be working well now. I followed recommendations on the forum for the next best thing to Avast. I am hoping you found the logs I sent to be clear finally. I didn't receive a response on that front so I am hopeful that I'm done looking for Malware? Thank you so much for all the help you've given me I do appreciate it. My computer is running alot better than when I first went looking for help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not quite yet.

    First uninstall Ask Toolbar and then you will be clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. ezeidan123

    ezeidan123 Private E-2

    I have followed your instructions all the way through. UPDATE: computer is running great, I think I will stay with the AntiVir for now. Weird happenings because I'd had Comodo and Avast for a while, didn't encounter problems with it until the problem with the Spyware. Anyway thank you so much for your help! I am such a happy camper now. Have a great day!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds