Quick Question

Discussion in 'Malware Help (A Specialist Will Reply)' started by bosox09, Jul 15, 2009.

  1. bosox09

    bosox09 Private E-2

    Hey all,

    First of all, this site rocks. Anyway, I got a bunch of viruses (including a downloader) that I successfully got rid of by running "Run & Read Me first" (except I didn't run combofix). By the way, this was about a couple weeks ago. Everything was gone from my system after scanning with numerous programs, however recently Panda's online virus scanner detected some stuff. I'm pretty sure it's all just remnants that are harmless, but I just want to make sure. The log is attached. If they are just remnants, then can I just delete the files and toggle system restore?

    Thanks all

    Oh, by the way, I uninstalled Spybot, those files look like they were just quarantined or something, but again, I'm not sure.
     

    Attached Files:

  2. bosox09

    bosox09 Private E-2

    I'm OK with bumping myself to the bottom of the queue because I ultimately decided to run combofix. I've attached logs for mgtools, malwarebytes, combofix, and rootrepeal. Btw, I'm running on Windows XP SP3.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you can delete the files, but before you toggle system restore, I want you to use windows explorer to find and delete:
    C:\Program Files\Mozilla Firefox\extensions\{DE3A7FBF-EAFD-4A22-8436-124F69C527A0}\chrome\content\overlay.xul

    Then I want you to go to start / run / and type "sfc /scannow" without quotes and let it run at least twice ( you may be prompted to insert your xp cd).

    Let me know if you have any issues with doing the above, before we get to the final cleanup which will include toggling system restore.
     
  4. bosox09

    bosox09 Private E-2

    K, ran system file checker twice. I'm assuming there was nothing wrong because when it was done it just closed without any messages. Between my first post and your reply I had run another online antivirus and it deleted what you told me to delete in windows explorer for me. I just checked to make sure (all my files are unhidden), and the file wasn't there. Btw, are there any resources you can point me to so I can learn more advanced techniques for virus removal other than the run and read me? For example, explanations of things to look for in the combofix and mgtools logs? Anyways, I'm ready for the next step.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately we are too busy to offer training to anyone who is not already a recognized expert. There are a few websites that provide training rooms. The process can take awhile to complete since there is a lot to learn and the people training you are doing it in their free time. Make sure that you are serious about wanting to spend the time to learn and have the time to perform malware removal this because it takes a strong committment. Check out the below sites:

    BootCamp

    Geek U!

    What the Tech Classroom

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds