Malware – “Database” - 2014.04.12

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by manilka835, Apr 12, 2014.

  1. manilka835

    manilka835 Specialist

    Dear MajorGeeks Forum,

    Malware – “Database” - 2014.04.12

    Unable to surf Internet although the connectivity is indicated.

    Therefore unable to update
    • SuperantiSpyware
    • Malwarebytes Anti-Malware (updated Manually)
    • SpyBot-Search & Destroy

    I have run READ & RUN ME FIRST but the problems are still persisting.

    Hitman Pro did not run with either setting for with or without Internet Connection.

    The relevant logs are attached.

    Thanking you.​

    Yours Sincerely,
    Manilka​
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have Comodo Internet Security installed as well as Avast. Does Comodo include antivirus or is it just the firewall?
     
  3. manilka835

    manilka835 Specialist

    Only the Comodo Firewall is installed and not the Antivirus.

    Also, since Sunday when I connect the USB Pen Drive, it is not detected by the CPU even though it is detected in other CPUs.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing any malware in those logs. Go ahead and post in the software forum regarding any problems you're having. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a static IP address configured ( Dhcp Enabled. . . . . . . . . . . : No )
    Is that what you want for your network or are you supposed to be using DHCP? DHCP is the norm. Static is an exception.
     
  6. manilka835

    manilka835 Specialist

    Today the USB Drive was indicated and I was able to re-install Comodo Firewall with Comodo Firewall 7.0.315459.4132. This fixed all the problems. In another computer where the Comodo Antivirus + Firewall were not updating, the same procedure resolved the matter.

    In addition to Malwarebytes Anti-Malware, having the SUPERAntiSpyware- free version useful?

    Updating Sun Java
    In the earlier READ & RUN ME FIRST. Malware Removal Guide it was recommended to Save fixme.reg to the desktop and Double click it to merge with the registry. Is this now not necessary?

    Adjust Active X security settings: Is this now not necessary?
    1. “In Internet Explorer, click Tools, Internet Options, and Security.
    2. Click on the Internet globe.
    3. Then select Default Level, and then click OK.
    4. Now select Custom Level and scroll down to the ActiveX controls and plug-ins section (some may already be set correctly):
    5. Set Download signed Active X controls to Prompt
    6. Set Download unsigned Active X controls to Disable
    7. Set Initialize and Script ActiveX controls not marked as safe to Disable
    8. Set Allow paste operations via script or Script ActiveX controls marked safe for scripting to Disable
    9. scroll down to the Miscellaneous section (some may already be set correctly)
    10. Set Installation of desktop items to Prompt
    11. Set Launching programs and files in an IFRAME to Prompt
    12. Set Navigate sub-frames across different domains to Prompt
    13. Click OK and OK again.”
    Disable the AutoRuns Feature used to spread Malware: Is this now not necessary?
    1. “Vista
    1.1. Open up the Start Menu and right-click on “Computer”, and then select “Properties”.
    1.2. Click on the “System Protection” link on the left hand side.
    1.3. Now select the “System Protection” tab to get to the System Restore section.
    1.4. Click the “Create” button to create a new restore point. You’ll be prompted for a name, and you might want to give it a useful name that you’ll be able to easily identify later.
    1.5. Click the Create button, and then the system will create the restore point.
    2. Windows XP
    2.1. Click Start, click Run, type %SystemRoot%\system32\restore\rstrui.exe, and then click OK.
    2.2. On the Welcome to System Restore page, click Create a restore point, and then click Next.
    2.3. On the Create a Restore Point page, type a name for the restore point and then click Create
    2.4. After the restore point has been created, click Close.
    2.5. install WindowsXP-KB950582-x86-ENU.exe now
    2.6. After installing the patch, reboot your PC even if it does not ask you to do so.
    3. Save AutoRunDisable.reg to your desktop. Be sure the "Save as" type is set to "all files".
    4. Once you have saved it double click it and allow it to merge with the registry. You need to make sure that you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work and you will have to inform someone in our forum about your problem.
    5. Reboot your PC again after applying the above registry patch.”


    The following is recommended for Windows Vista & 7. Can they also be used for Windows XP?

    “Delete programs that are never used.
    1. Start > Control Panel > Programs and Features
    2. Select a program, and then click Uninstall.

    Limit how many programs load at startup by StartupCPL.

    Defragment the hard drive by IObit SmartDefrag

    Clean up the hard disk by
    1. Start > Programs > Accessories > System Tools > Disk Cleanup
    2. Select the check boxes for the files you want to delete.
    3. Click OK.
    4. Click Delete files.”

    Use MSconfig to setup for Normal Startup Mode: Is this now not necessary?
    1. Click Start > Run > type msconfig and click OK!
    2. Select the General tab and select Normal Startup.
    3. Then click Apply, OK, and reboot PC before continuing.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent! :)

    Yes I would say so!

    This is not a standard part of our procedures, the reg patches are given as and when needed. If we have given someone a reg patch, we tell them they can just delete the fixme.reg in the end when following final steps.

    Everything you asked "Is this still necessary?" then yes it is if it's still in the R&R. ;)

    Obviously you go about things in different ways for different operating systems, so sometimes instructions are operating system specific.

    Hope that addressed all you were asking. :)
     
  8. manilka835

    manilka835 Specialist

    All the items which I inquired were in R&R during previous years but now they are not there. That is why I wanted to know whether they have been removed as they are not necessary.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds