Wife's Notebook PC scrubbed - Log Files Missing

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tucquan, Feb 21, 2009.

  1. Tucquan

    Tucquan Private E-2

    Hi,

    Last Sunday, I completed the Read Me First and Vista Procedures on my wife's notebook PC (as well as my desktop). I posted the logs from my desktop and dr. m helped me get that PC all fixed up. I want to do the same for my wife's notebook PC. I had the logs saved in a desktop folder but they were deleted and the recycle bin emptied.

    Should I go back through all the procedures again to generate new logs or is there another method I should follow to regenerate the logs?

    Thanks much,

    Wayne
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the only way we will have logs now unless you still have them in their default locations too. Look for

    C:\MGlogs.zip
    C:\combofix.txt

    And also look for the SAS and MBAM logs in the below folders (note that you need to substitute your wife's real user name where I have the word User

    C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs


    C:\Documents and Settings\User\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs
     
  3. Tucquan

    Tucquan Private E-2

    Re: Wife's Notebook PC scrubbed - now have the logs

    OK, I've got them and here are the first three.

    BTW, I couldn't get into Documents and Settings because Vista won't allow it even with administrator rights. I was able to launch SAS and MAMB, go their log tab, launch the log and then save it with notepad.

    Thanks for helping me work through this!

    Wayne
     

    Attached Files:

  4. Tucquan

    Tucquan Private E-2

    And here's the 4th log file.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Wife's Notebook PC scrubbed - now have the logs

    Sorry about that. I forgot you said it was Vista. Vista logs are not in Docs and Setting your logs are here:

    C:\Users\Sugarchile\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

    C:\Users\Sugarchile\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs


    Your logs are clean but you do need to fix the below which is remapping your Symantect LiveUpdate links.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 67.238.46.168 liveupdate.symantec.com
    O1 - Hosts: 67.238.46.168 liveupdate.symantec.com

    After clicking Fix, exit HJT.


    Then if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. Tucquan

    Tucquan Private E-2

    Hi chaslang,

    I began to follow the steps in your last post and when I got to the HijackThis screen after pressing Do A System Scan Only, the list that it presents doesn't include

    O1 - Hosts: 67.238.46.168 liveupdate.symantec.com
    O1 - Hosts: 67.238.46.168 liveupdate.symantec.com

    I've attached a screenshot. Of interest, I have been getting Norton Virus Definition updates and I can successfully ping this IP address. Should I just skip this step and continue to button this PC up following your final steps?

    Thanks much,

    Wayne
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Something must have removed them after you attach your initial logs.
     
  8. Tucquan

    Tucquan Private E-2

    Thanks for all the help chaslang! I've got it buttoned up and will be walking my wife through the preventative steps.

    Wayne
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds