virus infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bad Panda, Dec 11, 2008.

  1. Bad Panda

    Bad Panda Private E-2

    This computer had multiple virus/spyware infections. Here are the logs.
     

    Attached Files:

  2. Bad Panda

    Bad Panda Private E-2

    Here is the last log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Curious ---> is this your computer?

    I've seen you have had at least 9 threads in malware since June.
     
    Last edited: Dec 14, 2008
  4. Bad Panda

    Bad Panda Private E-2

    Is this my laptop? No. It belongs to a friend of mine. I try to help with what I
    know about computers when I'm asked. I have a lot of people that know I work on them when I'm not doing my normal job.
    Is there a limit or something? If so I'm in trouble because I always have a stack of computers that people leave at my place.
    Panda
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is not a question of limits. We are happy to help people with Malware issues, but our resources are limited, Where the problem arises is that we work with the users. If we are doing numerous repairs for one user, then it appears that we are being used for someones commercial benefit.

    It would be much better to direct your "friends" to join MG's and work with us one on one.

    I will work this computer...but in the future, please have your friends join the forum so they can learn something about being protected.
     
  6. Bad Panda

    Bad Panda Private E-2

    Judging by what you just said, it does appear to be a problem. Most of the people who come to me aren't the type of people who are comfortable (or even know of) much of what you guys do.
    I don't want to make waves especially since of how helpful MG has been, but I don't want to stop helping out the people I do help...but I don't know enough of what you do to be thorough. Do you have a suggestion of where I can go to either learn more about finding these bugs, or perhaps another support option that is either non-cost or low cost?
    That aside, what more should we be doing for this computer?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They only need to know how to join the forum and start a thread....not something very difficult seeing as many know how to download torrents. :)

    I wouldn't be a bad idea for a "Senior Network Engineer" to learn how to remove malware.
    You could start HERE.
    I will review the logs when I finish with the threads I am working ahead of you. There is only two of us doing this at this time ( with two people in training. So we are very backed up.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would appear as though the scans took care of the malware, so there is just some clean up to do:

    First use add/remove programs to uninstall:
    Viewpoint Media Player

    Now disable the guest account in user accounts.

    Now Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download and install:
    SP3.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds