Help with scans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CrystalDii, Jul 30, 2011.

  1. CrystalDii

    CrystalDii Private E-2

    I joined the site today and followed all the instructions with the downloads and scans. I've been having problems obviously for a minute, a few months ago I clicked a link in an email that turned out to be a virus. At that time, I ran my McAfee anti virus and Anti Malwarebytes, thought it was all removed, until yesterday I got a blue screen error that said it was shuttin my laptop down to prevent a serious error. I found your site and began your steps. I was able to do Super Anti Spyware, Anti Malwarebytes, Combofix and MGTools. SAS reported 11 threats, 9 trojans and 2 malware trace.

    The rar file extension with RootRepeal would not let me open it after downloaded to run the exe file. It kept asking me how I wanted to open but wouldn't let me check desktop, just offered internet browsers, so I couldn't ever get to the .exe file to open it. So I just skipped that step and went on to MG Tools. With MG Tools, I got confused with how to save the log, and noticed that you state not to upload any logs from the folder so I didn't, but I did do the scan. Please let me know what I need to do with those two since i don't have the results to provide for you.

    I will attach the first 3 logs from the others that I did get back, and would like help with the next steps. Thanks in advance, and I appreciate the site for helping me this far.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes it tells you not to attach anything from inside the MGtools folder, but that is because it also tells you the logs we need is not in that folder. The log is C:\MGlogs.zip

    You need to attach this file.
     
  3. CrystalDii

    CrystalDii Private E-2

    Ok I found it! Its attached.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than what has already been removed, your logs are clean. Are you actually having any malware problems now? If so, exactly what are they?
     
  5. CrystalDii

    CrystalDii Private E-2

    Ok, first off let me say a BIG THANK YOU for your expedited help, it is much appreciated!!! so far I don't think i've had any problems. I do have a question about browsers, as i'm not sure this has anything to do with anything or not, and I forgot to mention this initially....

    Even though I clicked the link in the email, It seems that I got infected with this stuff ironically not too long after I downloaded Google chrome. So when I initially ran my scans a few months ago after the first blue screen error, I wasn't up to speed on turning the system restore off, thus maybe why I was reinfected or they weren't completely removed. So because of the system restore I had to redownload Google chrome. Now fast forward to the second blue screen/shutdown, and after I did your scan I thought about this and went back to IE. Once I went back, there was a message about an hp add on that was not compatible, so when I selected to find a compatible one, after generating the fix it thingy on microsoft, I noticed my McAfee On Access had blocked about 5 file actions. Turned out, there wasn't a compatible add on found, so I just fixed it manually and selected that IE run without it. Should I be worried about any of this? Also should I remove or update Google Chrome? Is there a recommended browser that should be used? I'm not too pc savvy, so I hope my questions don't bother u....i'm just in the middle of getting my teachers certification and have no back up laptop and this last scenario has freaked me completely out! :confused Please advise....

    I've also created a limited profile, and have started using that one to use the internet.
     
  6. CrystalDii

    CrystalDii Private E-2

    I have to retract my statement of thinking everything was fine. Since I didn't have any problems I went on about surfing, and downloaded IObit Malware Fighter(with the key that was given on here), and apparently it picked up more malware, or the same malware I don't know. I never got anymore info on what to do next after the first scans, and I was not able to run RootRepeal. I am in limbo one way or the other because I don't know what to do now. Again, I thought I was clean after no issues and no further response on here so I re enabled the system restore along with the other directions in the READ ME if you are clean (I have not removed any of the software/files that I was told to download)... But then noticed that in the quarantine list of IOBit it says something about C:/System Volume Information/restore. I mistakenly deleted two other things that showed up in the quarantine, but they all did say trojan. I wasn't sure if I was to disable my McAfee realtime on access scans while IObit scans, so I did not. There have also been system blocks in the IObit as well as file action blocks from my McAfee Onscan Access. I tried to update my McAfee and it would allow it. IE has been lockin up very often recently as well. Please help with further instruction.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Items in system restore will no longer be detected by iobit once you have followed final steps.
    What blocks exactly are you referring to?
    Would or would not?

    Not necessarily a malware problem. If Chas said you were clean, then you are clean. (Unless you did something afteerwards) :)
     
  8. CrystalDii

    CrystalDii Private E-2

    Well i'm not sure if I did follow accurate final steps specific to my issues because I was never given any by your team, I followed some of the steps I read from that page because I thought I was clean. So then I went ahead and downloaded IObit because I received a key, and it picked up several more threats. This is when I started to question whether I was clean or not,and when I noticed other threads receiving final step instructions (I haven't done anything during or afterwards), also because no one ever responded to see what my further problems were or to determine if those problems were malware related, or to tell me yes or no for sure. If I was clean, again I never received final instructions in this thread from your staff to verify a close out.

    The blocks I am referring to are "file action blocks", "registry action blocks" from my McAfee On Access Scan and the IObit has three tabs; system, web and USB, and the system tab is usually listing that there have been blocks i'm guessing within the system.

    My McAfee would not, will not update.

    Also when I ran the Advanced Care that came with the IObit, there were numerous things that were picked up and supposedly fixed. I cannot tell you they were, all I can do is find the logs if they are needed.

    I still have all this stuff I was instructed to download in order to scan the "READ ME" stuff and I was not knowing what to keep or remove and what else to do. So if I am clean, no final instructions were ever given. I took it upon myself to find out final steps because I thought I was clean, then right as I was doing that and further question my specific final steps, thats when I noticed other things/threats were being found. And FYI, I never was able to run RootRepeal because of the file type.

    Basically, while I was waiting for confirmation and final instructions from being clean, other things were picked up. So i'm not really sure everything is good.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IObit is not immune to false detections similar to many programs. Also I would not recommend having IObit's active protection at the same time as McAfee since they could likely conflict. Also as Kestrel mentions, things in System Volume information are not really issues since they are in restore points and could only be a possible problem if you restored your system to that restore point. Our final instructions ( which I will give now as I planned to give previously after asking if you were having problems ) will remove old restore points.

    So what I recommand is that you uninstall IObit and use the license on another PC that does not already have a full protecion suite like McAfee.

    I also recommend that you uninstall SUPERAntiSpyware since you did not install it properly anyway. You installed all the files to your Desktop which you should not do with any program. You should always install programs to their recommended default folder which is normally a subfolder within the C:\Program Files folder.

    The do then below.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. CrystalDii

    CrystalDii Private E-2

    Ok so I mentioned that for whatever reason my McAfee will not allow me to update it. When I purchased the laptop this is the anti virus that came with it, so do you recommend that I keep this? If it is not allowing it to update, will it still provide adequate protection? I am referencing your advice to remove IObit(i don't have another pc to use it with) and keep the McAfee, as opposed to getting new antivirus that may be compatible with it. I just want to be ok with protection with whatever is done next, as well as not cause any complications.

    Also, I wasn't aware that I was not to download the anti malware programs to my desktop, I read that one of the programs advised to do this so my error for thinking thats where they all were supposed to go. It was not previously mentioned that I had done it incorrectly. Would it be wise to reinstall them afterwards? since it is recommended in the final steps that I have them ( Super and Malwarebytes) Please let me know. I will move forward with the listed final steps. Thank you for your response and help thusfar.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Has your free trial subscription expired? Perhaps that is why you cannot update it.

    NO!

    You are confusing the words "download" and "installing". You can download the installer files and save them to your Desktop if you really want but I would not leave them there. I recommed downloading files to a Downloads folder. However, you installed the actual program into your Desktop folder and you should never do that with anything. The Program Files folder is the normal location for all installations.

    So you need to uninstall SUPERAntiSpyware and then delete any files leftover from it after uninstalling. Then you can reinstall it and this time take note that it will default to installing in the C:\Program Files\SUPERAntiSpyware folder
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds