Mywebsearch, trojan ms-fake, vundo, hiberfil.sys?? Logs attached.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by maddog808, Aug 23, 2010.

  1. maddog808

    maddog808 Private E-2

    Hi again,
    I am trying to clean my cousin's old computer now. It is an "Emachines T4130" with an Intel Pentium 4 at 1.3 GHz, with 256 MB of RAM. I know it is low on memory, and according to Crucial.com, the max is 512 MB. I will see about upgrading the RAM once I am finished cleaning. It was running Windows XP SP 2, but I went to Microsoft Update about 10 times, and fully updated to SP 3 and about 75 other miscellaneous MS updates. Next I installed "Microsoft Security Essentials", and made sure Windoes Firewall is working. I then went through the steps in "READ & RUN ME FIRST", updating Java, running CCleaner, etc. My cousin said it was so infected that he just put it in a closet, thinking he would never be able to use it again. So here I am with some logs for you guys again. I was able to do everything except root repeal. I got this error message while it was scanning:
    [​IMG]

    So I clicked OK and it looked like this for about 30 minutes:

    [​IMG]

    So then I clicked Save Report, and got this:

    [​IMG]

    The computer has 2 hard drive partitions, each with about 10GB. The OS and programs are on the C drive, and "my documents" is on the E drive. Maybe the problem is that the E drive is a "NTFS" format? Anyway, thank you in advance for your help on this one. The 4 logs that I could create are attached.

    Thanks,
    Matt
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would appear that the scans took care of the malware. Your logs are clean. However, you are running out of hard drive space on both hard drives and you have way too little RAM installed to support running XP SP3:

    Code:
    Total Physical Memory    255.42 MB    
    Available Physical Memory    86.77 MB
    What malware issues are you having, if any?
     
  3. maddog808

    maddog808 Private E-2

    Wow!! That was a quick reply, Tim! Thanks a lot! I don't seem to be having any malware issues at the moment. You are correct, I think the scans took care of that. I just wasn't sure if I should reformat the "E" hard drive partition for Fat32, to see if Root Repeal could finish its scan. Is it not that important?

    Thanks, Matt
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    RootRepeal fails on about 50% of the system that we try to run it on. It's not important that it didn't run for you.

    You can change a fat hard drive to ntfs, but you cant change it back.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  5. maddog808

    maddog808 Private E-2

    OK. I followed the steps and uninstalled Combofix, MGtools, etc. Other than being EXTREMELY slow, everything seems to be running ok. I found 4 sticks of 256MB RAM that is compatible with his machine on Amazon. I also uninstalled some crap on the hard drive and now have a little over 1GB free for him. Just for clarification, when you guys say the "logs are clean", are you saying that the logs produced by the scans that I completed are telling you that they have removed all the malware? Not that there was never any malware to begin with, correct?

    Thanks so much for your help Tim.

    Sincerely,
    Matt
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, the scans that you ran, particularly SAS and MBAM, found and removed the malware on your system. That is why we recommend you keep both of those programs for running when you suspect malware. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds