Help / review of my fix for My Computer Attacking Winifixer.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dobbie, Aug 3, 2008.

  1. Dobbie

    Dobbie Private E-2

    Hello
    It s been a while ... I was having a proble with MY computer attacking a winifixer.com site. My norton is now told to apply a block to this and it has stopped. This started when I down loaded a file and failed to scan it before double clicking on it (got to slow down!!!)

    My internet setting have placed this site in the "security - restricted sites"
    I have ran the procedures as shown and in the order shown.

    I have attached the logs because I dont know how to read them and want to be sure this problem is taken care of.

    Also befor running the procedures I was getting an error that a file in a temp folder could not be found when I was booting up. It no longer happens.

    Could you tell me if I am safe and what was causing this problem??? The
     

    Attached Files:

  2. Dobbie

    Dobbie Private E-2

    Sorry for posting in the thread.... could you direct me to the proper location???? Its beenquite a while since I have posted a log and forget where t o post them...
     
  3. Dobbie

    Dobbie Private E-2

    Failed to finish reading the instructions on what to do after processing the MGTools program.

    Here is the zipped log file from the C:\drive

    Hope this is in the correct location :eek:

    Dobbie
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Being safe and being clean are two different things. Our final instructions will cover being safe. You need to run Malwarebytes Anti-Malware as requested in the READ & RUN ME and attach the log we asked for. We did not ask for or need a Spybot log.


    Is your copy of Spyware Doctor a paid version that actually blocks and removes malware?

    You also need to uninstall all the below old Sun Java versions as requested in step 1 of the READ & RUN ME. These are actually making you unsafe.
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) SE Runtime Environment 6 Update 1
     
    Last edited: Aug 5, 2008
  5. Dobbie

    Dobbie Private E-2

    I want to thank you for your rapid response to my posting.

    I am going to redo the whole procedure again starting from step 1 (my goof - over looked the Java steps....

    I always thought that java uninstalled older versions when it installed the latest one.... Ill have to watch out for this java thing....

    JUst got home and to late to do tonight ... got a very early sun rise tomorrow so have to get some shut eye.

    Ill get the re processed files up there very shortly...

    Again... thank you and I hope to get this done tomorrow after work...:(
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to run everything all over again. Just remove the old Java versions and run Malwarebytes Anti-Malware and attach the log from it. Then we will continue.
     
  7. Dobbie

    Dobbie Private E-2

    Good day....

    I read your last reply after I had reran all the programs... I really wanted to do it the right way.. I really plan on doing this on a regular basis....

    First, I have cleaned up all the old Java versions, down loaded the latest from the site and have installed it.

    I have reran all of the programs recommeded. I have removed spy bot and replaced it with the version I have DL from the site.
    After running the programs I removed the webroot washer program. I have emptied the recycle bin. I have toggled off system restore, shut down the system. I have then restarted the computer and toggled the restore system back on.
    I am normally pretty careful but getting the trojans that I had (which really suprised me that I had) really shocked me.

    Hopefully, I have removed all the malware on the system.

    I have attached the 4 files mentioned (three on this message and 1 on the next) and I am hopeing you can look them over and tell me that I am now cleaned of the trojans and virus.
    Normally, norton protects me but I guess it really cant catch the trojans.
     

    Attached Files:

  8. Dobbie

    Dobbie Private E-2

    :) I am sending the 4th file under this message.....

    Got to hit the sack now.... getting later and sun comes up early....:wave

    Want to again thank you for your assistance in this and any advise will be well taken....
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're in pretty good shape. I have couple of things for you to do alnog with final instructions.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Delete the below two files if found?
    C:\WINDOWS\system32\system_.ini
    C:\WINDOWS\system32\ud.exe

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. Dobbie

    Dobbie Private E-2

    Good Evening.....

    You have resolved my problem I think????

    I cleared all of my Norton Logs and I am getting the following alerts -

    8/6/2008 7:12:24 PM UNAUTHORIZED ACCESS LOGGED

    ABOUT THREE TIMES EVERY MINUTE
    from
    Event Details:
    Actor: C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE (PID=1380)
    Target: C:\Program Files\Common Files\Symantec Shared\ccLgView.exe
    Action: Unauthorized access
    Reaction: Unauthorized access stopped :(

    Is there anyway I can get this stopped??? Isnt this a windows program??
    I dont remember this happening befor....


    Now.... I want to thank you for your help in this matter.... it puts my mind at easy.

    I would like to mention the the reg fix worked.

    I did not notice a ud.exe file but I did see a "ud " 1kb file dated 6/10/08 11:50 PM. I did not delete this file in the windows\system32 directory. Can I???? :(

    I did the system restore routine.

    Would like to see if you have any guidance on teh above UNAUTHORIZED ACCESS LOGGED problem and the "ud " file.

    Again, Thank you for your help in this matter....

    Dobbie:) :wave
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not malware. It is Windows Defender scanning your Symantec files. In the How to protect yourself from malware link I gave you, it stated the below
    Thus I suggest that you uninstall Windows Defender anyway. Otherwise you will have to tell Symantec not to block Windows Defender.


    Did you check for the ud.exe file before running the final steps? You have not being showing file extensions anymore and ud may really be ud.exe. You may have to redo the below to be sure you can see file extensions:

    How to view hidden, system files & folders!
     
  12. Dobbie

    Dobbie Private E-2

    Good Evening

    I have unhid files and folders as originally suggested and again have double checked as suggested.

    I found the file called system_.ini the first time and deleted it but did not find the ud.exe........ just "ud" file.
    I still have not found the ud.exe

    will this cause problems??? or should I not look a gift hourse in the mouth??? :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt you need to file but just to be safe, rename it to ud.BAK and then wait a few days to see if anything complains about a file missing. If not, then delete it.
     
  14. Dobbie

    Dobbie Private E-2

    OK renamed file and no complaints from the box...

    I want you to know that I understand that this takes a lot of you time, working on these problems, and that I really appreciate your help.

    Again, thank you and have a great weekend (if it is your weekend that is:))

    Dobbie
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and enjoy your weekend too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds