![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello -
I have been hit by a variety of malware which I thought I had removed using the READ & RUN Summary sheet but it has returned. Am running XP SP3 and Computer performance had been deteriorating for about 2 weeks. I assumed it was aging laptop but ran Sophos and SAS and found some malware. Performed the Read and Run on the main user account in normal mode and the Admin account under safe mode. Within each log I have attached the Admin data at the bottom of the log. Perfromance began to deteriorate again after 72 hours. ran SAS to confirm my suspicions and there Adware flash tracker file. Would appreciate some help as I am suspicious that I have not rooted out the problem as this is similar to previous issues noted in attached log. SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 06/08/2010 at 07:42 AM Application Version : 4.26.1006 Core Rules Database Version : 5045 Trace Rules Database Version: 2857 Scan type : Complete Scan Total Scan Time : 00:58:26 Memory items scanned : 548 Memory threats detected : 0 Registry items scanned : 5398 Registry threats detected : 0 File items scanned : 20664 File threats detected : 1 Adware.Flash Tracking Cookie C:\Documents and Settings\Mai\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\38FRGBP8\BROADCAST.PIXIMEDIA.FR |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Hello -
I have been hit by a variety of malware which I thought I had removed using the READ & RUN Summary sheet but it has returned. Am running XP SP3 and Computer performance had been deteriorating for about 2 weeks. I assumed it was aging laptop but ran Sophos and SAS and found some malware. Performed the Read and Run on the main user account in normal mode and the Admin account under safe mode. Within each log I have attached the Admin data at the bottom of the log. Perfromance began to deteriorate again after 72 hours. ran SAS to confirm my suspicions and there Adware flash tracker file. Would appreciate some help as I am suspicious that I have not rooted out the problem as this is similar to previous issues noted in attached log. SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 06/08/2010 at 07:42 AM Application Version : 4.26.1006 Core Rules Database Version : 5045 Trace Rules Database Version: 2857 Scan type : Complete Scan Total Scan Time : 00:58:26 Memory items scanned : 548 Memory threats detected : 0 Registry items scanned : 5398 Registry threats detected : 0 File items scanned : 20664 File threats detected : 1 Adware.Flash Tracking Cookie C:\Documents and Settings\Mai\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\38FRGBP8\BROADCAST.PIXIMEDIA.FR |
|
#3
|
||||
|
||||
|
Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#4
|
||||
|
||||
|
1. Before we continue I would like for you to rename ComboFix2.exe back to combofix.exe.
2. Important Notice: A new version of SUPERAntiSpyware is available, and I would like for you to run it on both accounts and attach logs once done.
3. Why did you run scans in safe mode on the admin account? What issues did you experience that scans could not be run in normal mode? Normal user account: 1. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: Quote:
2. Now use Windows Explorer to find and delete the below bold folder: Quote:
Quote:
5. Run the new C:\MGTools.exe and attach the C:\Mglogs.zip that it creates. Admin Account: Delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day). Quote:
5. Run the new C:\MGTools.exe and attach the C:\Mglogs.zip that it creates. 6. Let me know how things are running now. ![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Hi Kestrel13 -
thank you for all the help. Its much appreciated. Answers to your points below Did all the steps you required. logs attached. SAS scan on the main account did pick up another flash issue. so not sure what is occurring. To clarify why I scanned Admin account in safe mode. I incorrectly assumed that my admin account could only be accessed via safe mode. Based on your query I have now realised that my main account is my admin account and performing the extra scans in Safe Mode had no true advantage. Please let me know how it looks. Best Regards Tarek |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Now, using the admin account, I want you to do the following in normal mode:
Go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.C:\MGTools.exe and attach the C:\Mglogs.zip into your next reply. I am not seeing any malware in any of the logs but just want to see fresh logs from the most current version of MGTools before I give you final steps for both accounts. ![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
Once again kestrel 13 I am very grateful for all your help.
Attached find the latest logs. regards |
|
#8
|
||||
|
||||
|
All clean.
Final steps for both accounts now:If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
yabasha71 (06-14-10) | ||
|
#9
|
|||
|
|||
|
Thanks again. I am grateful for your help
|
|
#10
|
||||
|
||||
|
Most welcome. Safe surfing.
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| XP-Pro,flash player 10 shockwave player 11 | mikessmith | Software | 8 | 11-06-09 14:48 |
| Flash Player 10 won't donload using IE 8 with Flash Player 7 add-on already installed | ITgirl | Software | 3 | 10-18-09 13:47 |
| Malware attack.. is it really gone? :S | DomBray78 | Malware Removal | 6 | 01-15-09 01:27 |
| Help! Malware attack | CanadaGuy | Malware Removal | 9 | 03-25-08 01:05 |
| malware attack | rockerz | Malware Removal | 7 | 01-04-06 14:13 |