I think I cleaned it. Could use another set of eyes.

Discussion in 'Malware Help (A Specialist Will Reply)' started by MagickalMemories, May 13, 2008.

  1. MagickalMemories

    MagickalMemories Private E-2

    Hi, guys.
    First off, I want to say how wonderful this site is for someone like me.
    I'm comfortable poking and prodding around the files on my computer when I have a guide, or know what I'm doing already, and I believe your site helped me remove a tenacious little B-stard from my computer.

    I followed all of the instructions in the "Read me first" and "Windows XP Cleaning Procedures," and my computer seems fine, now. No more Antisly Spider pop ups, WinPatrol isn't asking me if I want to allow a bazillion .dll's to run... All seems good.

    I was hoping one of you kind folks would look over my logs and be certain I got it all. I can't tell you how appreciative I'd be.

    For the record, I already had AVG, Spybot, Ad-Aware & WinPatrol installed on my computer. They saved me from a worse mess. As soon as I realized SOMETHING was going on, I ran AVG and it killed 3 trojans immediately.
    Continuous runnings of spybot & Ad-Aware found something new each time, but the IE pop ups kept happening.
    After manually deleting a few things I found (the html's & gif's that Antispy Spider put on my hard drive), I turned to you guys.

    Like I said, I think I have it all, but would appreciate a more educated viewer to confirm or deny.

    Thanks again, in advance, for your help.

    Oh... and you'll notice there are 2 SAS logs... Partially through the scan process the first time I ran it, the malware went crazy & opened hundeds of IE pages in rapid fire. I managed to keep a fair amount of control by right clicking & choosing to delete the whole group each time, but it eventually got the best of the program. The computer locked up & I had to reboot.
    Round 1 - malware.
    Round 2 was a knockout for SAS, though. After reboot, everything went off without a hitch.
     

    Attached Files:

  2. MagickalMemories

    MagickalMemories Private E-2

    Here are the other 2 logs. Thanks again!

    Eric
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    When you ran SAS the 1st time had you followed the instructions that said the below:
    I'm looking at your logs now.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A quick look at your logs shows that you are still infected. I'm working up a fix but you need to do the below while I prepare the rest of your fix.

    Uninstall Viewpoint Media Player as rquested in step 1 of the READ ME.

    You have some left overs from McAfee being uninstalled. Please run this: McAfee Consumer Product Removal Tool



    Is the below something you installed?
    c:\program files\alogg\chmxfit.exe

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
    O2 - BHO: (no name) - {630D959E-F031-474A-B574-CF8B859A5494} - C:\WINDOWS\system32\iifCVMfD.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. MagickalMemories

    MagickalMemories Private E-2

    Yup. I was unplugged entirely.

    Also, I have something unusual, now... When I click on start, then go to programs, and the list expands, some of the programs are highlighted in grey & some in white.
    What's that about?

    I'm going to follow the instructions in your other post, now.
    I'll post any applicable updates.

    Thanks again!

    Eric
     
  6. MagickalMemories

    MagickalMemories Private E-2

    Hmmm. Posted this once, but lost it when there was a database error.

    Trying again:

    I ran everything as per your instructions.
    All seems well, except that I got 2 pop ups from WinPatrol while following your directions. Both were about an attempted change to my homepage. I denied them both. Of course, everything seemed fine before I saw your post that I'm not fine, too. So there you go :)

    Not to the best of my knowledge. I Googled it and the only thing that came up on it was this thread... I'll have to presume not, then.
    I keep a pretty good handle on what is & isn't installed on the computer. Only my wife & I are allowed to install to it & she won't do it unless I'm in the room, because she gets lost with all of the WinPartol (etc.) pop-ups asking for permission to make changes.
    The night of the attack, she installed Picasa via download.com. After that, she updated it via IE. I'm presuming the attack came in via an IE Security hole.

    I've attached the requested files.

    Thank you again for your help. I can't tell you how much I appreciate it.

    Eric

    Oh... and my clock never went back to regular time. It's still stuck on 24hr. :shrug: I can always figure that one out later, though.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You needed to allow it. It was part of the fix!

    We will fix them.


    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    Did you run the ComboFix procedure without any issues? I still see things we were trying to fix. Shutdown WinPatrol and try the fix again and then attach new logs.
     
  8. MagickalMemories

    MagickalMemories Private E-2

    Thanks for the info on the clock. I've never changed it before, so it would have probably taken me a bit to figure it out on my own.

    I didn't allow the homepage change because it was the same pop-up I've been getting since the beginning (not necessarily the same web address... just the same warning/window). When I run the procedures at home tonight, I'll be sure to allow it when it tries again.

    I had no problems with ComboFix what-so-ever.

    When I fight the next round with this thing tonight, I'll be certain to shut down WinPatrol first. That scares me, though, as Scotty the watchdog has been good to me over the years. LOL

    I'll post my logs, once complete.


    Thanks again!
    Eric

    Now, it's time to go back to work: :zzz
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but the same protection software they is supposed to prevent you from getting infections like this often does a better job of protecting the malware from being removed. ;)
     
  10. MagickalMemories

    MagickalMemories Private E-2

    Ain' t that the truth.
    So, I ran Combofix without WinPatrol running in the background. My log is attached. I allowed the Homepage change. Out of curiosity, may I ask what purpose that serves (changing the home page)?

    I hope you wanted me only to follow the combofix step and not all of the ones in that post, because I only did combofix.
    Since you only specified that one, that's all I did. I'd rather NOT presume and be wrong than presume and be wrong.

    If I need to follow the other steps (MGTools, FixMe.reg & CCleaner), just say the word!

    Thank you.
    Eric
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To remove the malware homepage setting.

    Yes I needed you to complete all steps again since WinPatrol stopped things from working properly. So if you did not do the HijackThis fix, please do it now.

    Then apply the below new registry patch to remove those items I previously asked about.


    Copy the bold text below to notepad. Save it as fixRK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Then redo the fixME.reg patch and then run GetLogs.bat and attach the new MGlogs.zip file.
     
  12. MagickalMemories

    MagickalMemories Private E-2

    Okay, boss.
    I ran everything as requested - turned off WinPatrol before doing anything. The files are attached below.

    I wasn't totally certain if you wanted me to run analyse/exe or not, so I went ahead and did. Better safe than sorry. None of the following was on there any longer (I removed them when you told me to earlier):


    Question: Can I delete the .reg files from my desktop now, or might we need them again?

    I did get the success message when double clicking them.

    The computer still seems to be running fine. Of course, I'll wait for you to tell me it's clean before I presume that's really the case.

    Oh... and when I turned on my computer today, AOL security warning popped up that they found BiFrost on the computer and I had it quarantined. I got the same message yesterday, though I don't recall if it was the same program. that was found.

    Thank you again for restoring my sanity.

    Eric
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will clean everything up when we are sure we are done. Right now I want to be sure those last registry keys I was having you fix with the fixRK.reg patch actually got removed. To that end, I need you to run ComboFix one more time and attach another new log from just ComboFix. The last log still showed those entries.


    NOTE: Unless you get to this tonight, I will not be around until sometime Sunday evening EST. So I will get back to this thread then. In the meantime you are in pretty good shape. I just don't want to give you final instructions to remove all tools...etc until we are sure we don't need them anymore.
     
  14. MagickalMemories

    MagickalMemories Private E-2

    Alrighty, then. :)

    I'll run it again tonight (around 7PM Central) and post the logs before heading out for the evening.

    Thanks again for your help. What you guys do here (free of charge, no less) is just astounding. Hats off to you.

    Eric
     
  15. MagickalMemories

    MagickalMemories Private E-2

    Okay. Ran the test, the log is below.

    Also, I got the warning again via AOL's built in security center about finding bifrost on my computer. I had it blocked, of course.

    I will run SAS to see what it finds.

    Thanks again!

    Eric
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you get anymore of these and also anytime you need to tell us (or any other forum) about a detection, it is way more helpful/useful to us if you tell us EXACTLY what is being found and where it is being found and obviously which program is finding it. Thus where exactly is AOL finding this problem. It is possible that the reason it is not really fixing the problem is that it is just in System Restore. Is CA Pest Patrol what AOL is using or is your AOL AntiSpyware running in addition to CA Pest Patrol? Or is the "Safety and Security Center Uninstaller" from AOL actually an independent scanner? I see it in your Uninstall Programs list.

    Did you run it? What were the results?

    I have a feeling that WinPatrol may be getting in the way of our malware cleaning. Please uninstall WinPatrol now and then reboot your PC. (you can re-install later after we complete all of your malware cleanup). After reboot, continue with the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    You also still need to Uninstall Viewpoint Media Player as previously requested.
     
  17. MagickalMemories

    MagickalMemories Private E-2

    Just checking email before heading to bed.
    I plan on running everything tomorrow.

    I wanted to give you the answers that I had for you already, though.

    I only received the bifrost message twice; both times that I posted it.
    AOL Antispyware is also running. Should I disable it? It's that "Safety and Security Center" that comes with AOL.

    I uninstalled the viewpoint media player when you said to. That's weird.
    Could one of the pieces of Malware be reinstalling it? I don't even know what it is.

    I removed it again, via add/remove programs.
    When I turn the computer on again tomorrow, I'll look for it to see if it's managed to reinstall.

    Thanks again!
    I'll post more info & logs tomorrow afternoon/evening.

    Eric
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but I need to know WHERE it is finding it. You said AOL is finding it but without knowing where, it does not help me.

    Yes it is AOL foistware (something you were not told about and are not given the choice not to install it). This is documented in the Uninstall Malware link in step 1 of the READ ME. They will keep installing it if you install any AOL programs. Keep an eye out for it and always uninstall it. Run the below right now which may help:

    ViewpointKiller
     
  19. MagickalMemories

    MagickalMemories Private E-2

    Okay.
    I got the Bifrost message again today & let AOL's Safety & Security Center (allegedly) remove it... again...
    This time, I remembered to look and see where it was found:
    I ran Viewpoint Killer. I know you didn't ask for it, but I went ahead and attached the log it created. I figure, I'd rather give you more info than you asked for than not enough.

    I deleted Winpatrol. My doctor assures me that the DT's wear off, eventually. :-D

    I ran all the programs as you advised.
    I received the success message with fixme.reg.

    The logs that you requested are attached below.

    Thank you!

    Eric
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Apparently something is wrong with how you are creating the ComboFix script file. The fixes are not working. Let's try this another way.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe

    After clicking Fix, exit HJT.



    Now we need to use run ComboFix again since it is the only tool detecting certain problems. Make sure that you copy everything in the quote box beginning with the KILLALL: line and ending with the [-hkey_current_user\software\wget] line
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop (yes overwrite the previous file). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\avenger.txt
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 21, 2008
  21. MagickalMemories

    MagickalMemories Private E-2

    If this helps...
    I'm simply copying & pasting them.
    When I do that, they don't come across formatted in the same way you have them on the screen. They are in one line. I clicked on "Word Wrap," and they still didn't look quite the same, so I haven't been using that on them, either. I didn't want to take any extra steps without being instructed.
    Do I need to format them to look exactly as they do in the "quote" box?
    For the record, that's what I'm doing with everything I create in notepad.

    I looked for the listed files, folder AND registry entries. None were present.

    I did get it.

    Everything seems to be working fine.

    I cannot find Avenger.txt. I didn't delete it or save it any place weird. I've even run a search for it. I tried searching for "Avenger.txt," "Avenger.*" and "*Avenger*.*." The only files I come up with are the ones that extraced from the zip. I know I didn't delete it, but I have no idea what happened to it.
    Should I run the program again and try to get a new log?


    Thanks again!

    Eric
     

    Attached Files:

  22. MagickalMemories

    MagickalMemories Private E-2

    Hmm. I noticed that MGlogs.zip didn't upload for some reason.

    I tried to upload it attached to this post & got the following error:

    So, I renamed it to MGlogs1.zip and got the same error message (but with the new file name).
    I tried renaming it a third time, and...

    Any advice?

    Eric
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you did not rerun GetLogs.bat to create a new log and are therefore trying to attach the exact same log. Renaming will not help. It would still have the same contents. You need rerun GetLogs.bat as requested.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes they need to be how they appear in this thread. You must have some strange setting in Notepad or your may be using Wordpad. I can set notepad to have wordwrap on or off and it makes no difference. The symptons you are talking about with eveything on one line sounds like a UNIX vs PC issue where carriage returns are missing. The Avenger fix must also be saved properly. You must make sure the files are being saved as pure text and not binary.
     
  25. MagickalMemories

    MagickalMemories Private E-2

    What irks me is that I never had a cut & paste problem before, and I copy & paste other things properly, as well (just did a recipe last night) with no formatting issues. I wonder if it has something to do with pulling it out of a "quote" box. Seems silly, I know, but those are the only "pastes" that haven't formatted properly.

    Weird.

    So, unless you say not to, tonight I'll redo the entire last step you posted, then.
    When I get to copying & pasting, I'll Word Wrap and adjust the file for appearance, too.
    I'll also run getlogs.bat again.

    When everything's done, I'll post the logs & a follow up.
    Sound good?

    Thank you.

    Eric
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not for me or anyone else who has been getting help. ;)

    Yes you should do all of msg # 20 again.

    You should not need to do anything about word wrap. It should not matter. Try another text editor like one of the below and see what happens:

    Notepad++

    EditPad Lite
     
  27. MagickalMemories

    MagickalMemories Private E-2

    I know... and that is what has me so irked. It's not like it's rocket science. :) It's s simple copy & paste action. I taught my 10 year old how to do it, fo heaven's sake. :confused


    Done.

    I downloaded Notepad++.
    Same thing happened.

    So, I manually edited the quote for appearance. I mimiced the correct # of "enter" keystrokes to ensure that the new ones appeared like your quote boxes.

    I swear, you'll probably think I'm an idiot right now, but I swear, Avenger.txt and ComboFix.txt are NOT on my C drive... or my D drive... or my J drive. I ran a search for them. They simply aren't on my computer. I didn't delete them & my recycle bin is empty.
    Now, for clarity, I'll tell you that I do nothing but close the files when they open on the screen. I don't try to save them because they're supposed to save by themselves. Right? I just close the notepad when they pop up. It never gives me the option to save, which indicates that the file was saved. When I try to "X" out of the window without saving a file, it alerts me that the text in the program has changed & asks me if I want to save the file.

    So, they SHOULD be there... but they're not.

    ...and I got success messages during the times that i should have, as well. No errors or problems.

    The good news is that MGlogs.zip is attached.

    Do you want me to try to run Avenger & ComboFix from post #20 again, save a second copy of those files, and post them?

    Thank you. Sorry this has had so many annoyances & hiccups.

    Eric
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it wasn't! But I don't need a new MGlogs.zip file until you get the ComboFix and Avenger procedures to work. Giving me a new log without those steps being run properly will only give me the same information that was in your previous logs.
     
  29. MagickalMemories

    MagickalMemories Private E-2

    Dammit!!!!
    I know it was attached. I saw it in the "Attach files" section and even clicked on manage attachments to be sure the 3 spaces had shrunk to 2...
    (then checked the "Attach files" again, to be certain it was still there).
    ARGH!!!

    What the heck could I have done?

    ::deep sigh::

    Okay.

    I'm going to go take care of it again and be all anal about each step.

    Will post everything tonight.

    Thank you.

    Eric
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated, make sure you have gotten the Avenger and ComboFix steps to run properly first before you bother with MGlogs.zip. Once you get them to run, then you will need to attach what I asked for in message # 20, which was:
    • c:\avenger.txt
    • c:\combofix.txt
    • c:\mglogs.zip
     
  31. MagickalMemories

    MagickalMemories Private E-2

    Alright.
    I got all anal on it and ran everything carefully.

    I received the success messages that I should have. Everything seemed to go off without a hitch.

    The .txt & .reg files mirrored the exact formatting of your instructions and I saved second copies of the logs, in case the originals disappeared on me.

    I'm glad I did because they didn't show up on my C drive while I was searching for them to attach them. I looked for them via Windows Explorer, too. The Avenger & ComboFix logs are just gone. It's no matter, though... because I saved the copies to my J drive. They are attached, as well as the MGlogs.zip

    I hope this goes through fine. I'll check it after submitting to make sure the logs are all attached still.
     

    Attached Files:

  32. MagickalMemories

    MagickalMemories Private E-2

    Awesome. Still attached.
    Finally!
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    5. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    6. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. Go to add/remove programs and uninstall HijackThis.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  34. MagickalMemories

    MagickalMemories Private E-2

    Alright!
    Finally managed to get on here and do the final cleaning steps.

    I just wanted, again, to say thank you.
    I appreciate you, and the rest of Major Geeks, doing what you do on a daily basis for free. This is, obviously, one of the most upstanding sites on the internet. I can't praise you enough.

    I can tell you that I'll sing your praises at every available opportunity, though.
    Okay. That's a lie. I won't sing them. Nobody wants to hear that. What I WILL do, however, is extoll your virtues... without singing.

    Take care.

    Eric

    ...now to go download WinPatrol. I miss me some Scotty. :-D
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks for spreading the good work. Surf safely!
     
  36. MagickalMemories

    MagickalMemories Private E-2

    I've got one more issue that wasn't repaired. I know it's somehow related to this, but I don't know if it is related to the malware or one of the "fix" steps changing something & not changing it back.

    My menu settings have changed a little.
    It's nothing I can't live with, but I'd rather fix them, if I can.

    If this shouldn't be done in this thread, and I need to start a new one in a different forum, just say the word.

    http://i12.photobucket.com/albums/a206/MagickalMemories/Screenshot.jpg

    If you look at the screen shot above, you'll see 3 things "circled."
    two are orange & one is red.

    The red one is a problem with some, but not all of my programs. It used to be a gray menu bar all the way across. Now, the words on the menu bar have a white background & white lines between the words.
    Again... not the end of the world. Just annoying.

    The other 2 circles are orange.
    Some of the items are gray & some are white. The White seems to be in the most often used areas.
    This used to be all white, with no differentiation. I preferred it that way.

    Again, no horrible thing, but it's not how I had it.

    I've poked around the various links in the Control Panel and changed a couple settings I thought could be it (but changed them back when they didn't work). I think that, like the clock issue earlier, I could figure it out eventually... but haven't yet, and God knows how long it would take me.

    Thanks for any help you can provide.

    Eric
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see anything in your logs that was removed/fixed that could be related to this. It is most likely a registry setting. You would be better off trying to work this one in the Software Forum. You may have additional OS problems on your PC. Remember how notepad would not paste things in properly?
     
  38. MagickalMemories

    MagickalMemories Private E-2

    Okay.

    Thanks, man!

    Eric
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds