Want to be sure removal worked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JTre77, Feb 21, 2009.

  1. JTre77

    JTre77 Private E-2

    Thank you for such a great site. I came across this site after trying a specific removal of virtumonde and smitfraud from another site. After completing the steps everything in normal mode was severely slowed down and rendered virtually useless. But everything in safe mode worked. While running the cleaning process I was unable to install the Sun Java and SAS. I kept going, finished and then tried SAS again. That worked and then I was also able to get the Sun Java to load. It now seems like everything is working...but I want to be sure.

    I am running Windows XP Home Edition 2002 SP 3

    As a side note. Before being infected I have used McAfee Security Suite. I have been unimpressed and now have Spyware Doctor with Antivirus. Should I just uninstall McAfee and go with Spyware Doctor?

    I have attached all the log files from the scans. Thanks.
     

    Attached Files:

  2. JTre77

    JTre77 Private E-2

    The last log files.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean other than a few minor items to remove. You can use McAfee Removal if you plan on keeping Spyware Doctor as you should not be running two AV's at the same time. I do not have knowledge of how good the pro version is, but you can ask in the software section for other users opinions.

    Let's do this:
    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    You may wish to use one of these:

    Startup Manager

    Startup_CPL
     
  4. JTre77

    JTre77 Private E-2

    OK, I did the suggested steps and yes it did give a success message about adding to the registry.

    I was ok for a while after doing the removal steps. But now I am experiencing slow/freezing in normal mode again. I had to run the steps you suggested in safe mode, but was able to complete them. Also, an item I forgot to mention before as a step that I couldn't do, was I received a message that the computer couldn't find msconfig when I tried to run it. Any further action you could suggest? Thanks in advance.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This will get your msconfig back:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    What couldn't you complete? Have you re-run SAS or MBAM to see if they report a problem?
     
  6. JTre77

    JTre77 Private E-2

    I did get a success message. Then tried to run msconfig and it still couldn't find it.

    I have been able to complete everything but the msconfig step. I will re-run SAS and MBAM now. Thanks Tim.
     
  7. JTre77

    JTre77 Private E-2

    Alright. I did the following with the following results:
    Ran Spybot S&D: Found nothing but some cookies
    Ran SAS: Produced no threats
    Ran MBAM: Produced no threats
    Ran Spyware Doctor Full system scan: Found Trojan-downloader.MisLeadApp!sd6 and Fixed it.

    What should I do next? I still can't use normal mode as it will slow way down and then freeze. This is so frustrating.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what Spyware Doctor is reporting. And I want you to try running SAS and MBAM in normal mode.

    Then go to start / run / type "sfc /scannow" without quotes and have your xp cd handy. Run it at least twice.
     
  9. JTre77

    JTre77 Private E-2

    Here is the details of the file that Spydoctor found. I will be trying the other suggested items as soon as I have time. Thanks,
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is finding a piece of malware in your system restore folder. Nothing will remove that. You need to toggle system restore to remove it.
     
  11. JTre77

    JTre77 Private E-2

    I toggled the system restore and then re-ran SAS and MBAM. MBAM found one item and I have attached the log. SAS found nothing.

    I haven't found my xp cd to use the scannow sfc tool yet. I'll keep looking, as I recently moved and need to find where it ended up.

    Computer is still slooow/freezes in normal. However, I was able to do the scans in normal mode as requested.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do a windows search for autorun.inf and remove all that are found. (Make sure any thumb drives are connected when you run the search.)
     
  13. JTre77

    JTre77 Private E-2

    I searched for autorun.inf and here is were it was found:
    C:\Program Files\Earthlink Setup - removed
    C:\drivers\mouse\onboard - removed
    C:\Program Files\Microsoft Plus! Digital Media Edition\PlusDME11.cab - unable to remove

    My computer also just downloaded and installed a windows update. Normal mode now seems to be working fine. Could I possibly be malware free?

    I have been unable to locate my xp cd to do the scannow step.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That all is ok.....if you cant find the cd, perhaps you could borrow one ( has to be the same version though).

    I will suggest one more thing to try:
    Using BitDefender Online Scan
     
  15. JTre77

    JTre77 Private E-2

    The same version as in it has to be XP Home - Version 2002 sp 3? All I was able to find was a CD for XP Professional including sp 2 at my in-laws. There computer says they have the exact version as me though.

    I ran the BitDefender scan and it found nothing new. It did find some files quarantined by ComboFix, which had not been deleted, but nothing else new. I've attached the report.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The build is the same but the version is what you need...if you have home installed, then you need the xp home edition, not the xp professional.

    This is a software issue, as your logs are clean. So I suggest that you pursue this in the software forum for further assistance.
     
  17. JTre77

    JTre77 Private E-2

    Thanks for all your help to this point. I'll definitely recommend this site to anyone I know has problems with malware.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome....hope they can assist in the software section. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds