Permission to post logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by BFRieck, Sep 11, 2008.

  1. BFRieck

    BFRieck Private E-2

    May I have permission to post logs created by various virus removal programs per your instructions as to how to remove malware?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you referring to the logs already requested in the below?

    READ & RUN ME FIRST. Malware Removal Guide

    If so, you don' t need any permission to attach them. ;) If you are referring to some other logs then what are they. But do note that I said attach them not post them.
     
  3. BFRieck

    BFRieck Private E-2

    Yes, they are the ones. I mis-spoke when I said post - I meant attach. Unfortunately, I can't find the logs that were saved by the program(s). The programs said they were saved on
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions explained how/where the logs are. You can get the logs from SAS and MBAM from inside of the program or you can look for them in your Application Data folder. ComboFix is C:\combofix.txt and the MGtools log is C:\MGlogs.zip

    Do not attach individual logs (like the procdll.txt you attached). Only attach what we asked for.

    Also please explain if you are still having any malware problems.
     
  5. BFRieck

    BFRieck Private E-2

    Sir,

    This is my first time at this so I'm not sure how it's supposed to work. I didn't mean to send something I wasn't supposed to. Anyway, I think most, if not all, the problems are fixed and things seemed to be working pretty well. I had been working on whatever I got and had run a program called SmitFraudFix which at least got my desktop back. I was still missing some icons and getting periodic full screen popups. Running your protocol brought back the missing icons and apparently got rid of the popups so hopefully I'm back to normal. Should I do anything else at this time?
    Bruce
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you attach the 4 requested logs we can check to make sure that everything was really removed.

    If you are happy with how things are now, then you can just take the below steps.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. BFRieck

    BFRieck Private E-2

    Here are what I think you requested in terms of data logs.
     
  8. BFRieck

    BFRieck Private E-2

    I hope this is what you wanted me to attach:
     

    Attached Files:

  9. BFRieck

    BFRieck Private E-2

    And here's the fourth one:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is a little more to do.

    Your ComboFix log shows that it did not run properly. What problems did you run into while trying to run it. You don't need re-run it. I just want to know what happened.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7DD11780-910B-4372-913D-79802B5C6FDB} - C:\WINDOWS\system32\hgGvUKcA.dll (file missing)
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.

    Now delete the below two files. Let me know if you succeed.
    C:\WINDOWS\system32\AcKUvGgh.ini
    C:\WINDOWS\system32\AcKUvGgh.ini2

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. BFRieck

    BFRieck Private E-2

    Okay, I've done all that. Here are the answers to your questions:

    1. I didn't know Combofix didn't run correctly, so I don't know what happened.
    2. I successfully uninstalled the following:
    Java(TM) 6 Update 2, Java(TM) 6 Update 3, and Java(TM) 6 Update 5
    3. I was not able to fix: O2 - BHO: (no name) - {7DD11780-910B-4372-913D- 79802B5C6FDB} - C:\WINDOWS\system32\hgGvUKcA.dll (file missing) because it did not show up as a choice to fix; the other one did and I fixed it.
    4. Search could not find either of these two files: C:\WINDOWS\system32\AcKUvGgh.ini, or C:\WINDOWS\system32\AcKUvGgh.ini2 so I could not delete them.
    5. I got a success message with respect to the Regedit4 request.
    6. The requested log is attached.

    Generally, things are working pretty well. No complaints, all of the negative aspects of the virus seem to be gone.

    Thanks so much for all your help. You are great. What now?

    Bruce
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. I missed another old Java version to uninstall last time. Please uninstall the below too:
    Java(TM) SE Runtime Environment 6


    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. BFRieck

    BFRieck Private E-2

    Okay. I think I've done everything I'm supposed to and there doesn't seem to be any further problem with my computer. I did your suggestions as to preventing malware but I have at least one question:

    I bought SuperAntiSpyware and turned it on. I also installed Online Armor as my firewall, and I installed Spybot S&D and enabled the recommended items, and I installed Spyware Blaster and enabled everythjing. Should I also install one of the suggested antivirus programs (e.g., Avast?) I had AVG installed, but uninstalled it as it seemed to not be as recommended as some of the others. I also have something called SmitFraudFix installed and wonder if I should uninstall it.

    Thanks so much for your help and patience. I was pretty scared when I got attacked and you were so helpful.

    Bruce
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes you must have an antivirus program installed so pick one and install it.

    You do not need SmitFraudFix. It is a specialty program and anytime it is needed, you need to download and use the current version anyway so there is no sense in keeping it.
     
  15. BFRieck

    BFRieck Private E-2

    Okay, I installed Avast as my antivirus - it looks like I can't set it up on a scheduler to run at a pre-determined time so I'll just run it manually from time to time. How often would you recommend? I have super antispyware set up to run in the middle of every night. I also installed Spyware Blaster and that's up to date. I've made sure I have all the updates from MS Windows for XP which I use. I also installed OnLine Armor as my firewall and substituted Mozilla Firefox for my browser. Finally, I got rid of SmitFraud Fix as you suggested. What about the following programs that were used in the cleaning process:
    -Malware Bytes Anti-Malware
    -CCleaner
    Should I retain those on my computer for later use or should I uninstall them?

    Again, thanks so much for your help and patience in rescuing me from a fate worse than death (or seemingly so).

    Bruce
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once a month for a full scan unless you do lots of surfing or you do lots of P2P or torrent downloading. It you do the later, you should scan weekly.


    See step 1 of msg # 12 and step 4 of the How to protect yourself link as this was already covered. ;)

    Your welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds