Trying to clear this machine

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vikingsfan, Jan 4, 2010.

  1. Vikingsfan

    Vikingsfan Private E-2

    I'm working on a machine running XP and have gone through the clean up, and malware removal process as described on these forums. I am new to the forum and have used the recommended procedures on other machines with successful results.

    The computer has since become more unstable and I am posting this as quickly as possible before it crashes again. I have attached the logs I found but want to post this much up first. The machine did not have an anti virus program when I got it, and was very out of date for microsoft update. I've downloaded all the security updates to service pack 3 but am now having problems with that.

    Any thoughts, suggestions, directions are appreciated. I will add what I can to this post as I find new information.
     

    Attached Files:

  2. Vikingsfan

    Vikingsfan Private E-2

    So I have thought of a few things I didn't initially post. First off the background has changed on its own twice. Once since running the first three programs. I can't remember when it changed. It looks like an open folder I am going to add a screen shot of it. (It seems the picture is too large to upload and I am unfamiliar with resizing a picture to post) I do have the shot saved if need be I can send it or upload with a little help.

    I am also going to add the log from superanti...whatever the heck its called I can't remember right now and am too lazy to check. The other issue I was having but am no longer having after running combo fix was a crash to blue screen. The blue screen was suggesting a driver problem or possibly updating bios...? It has not happened since running through all the procedures.

    Lastly and most importantly I guess, I've added AVG and ran a scan that found no issues. I'm feeling mildly comfortable but still unhappy about the background situation which leaves me feeling there is still a problem.

    BTW at one point I could not get to "my computer" it showed two document folders but no C drive or D drive. Which was returned after running one of the programs but I don't remember which one. That is the reason I could place combofix where the READ ME suggested.
     

    Attached Files:

    Last edited: Jan 5, 2010
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We need the requested log from MGtools to continue. Please attach the C:\MGlogs.zip file.

    Also your Malwarebytes log shows you took no action. Did you actually fix what it found and save the log before fixing???
     
  4. Vikingsfan

    Vikingsfan Private E-2

    Wow I'm quite confused and sorry. I don't know what happened with the Malwarebytes, I could have sworn I fixed what was found I don't know when I saved the log. It was late and apparently my frustration got the better of me. I will wait for your instructions to see if I should run the process again or what to do now.

    I am adding the MGlogs.zipfile. Sorry for the delay and not having everything together.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on these logs you are in pretty good shape. The biggest remaining problem is the fact that this PC has no protection software installed (as you have mentioned in your 1st message). However there are a few minor things to do before getting to final instructions.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O24 - Desktop Component 0: Privacy Protection - (no file)

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    After doing the above, if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot to mention one other major problem that has nothing to do with malware but will cause this PC not to work properly. And that is that it does not have enough memory to properly run Windows XP. The logs show
    Code:
    Total Physical Memory 256.00 MB 
    Available Physical Memory 32.04 MB
    At a minimum, it needs 4 times what it has... i.e., 4 x 256 MB = 1 GB.
     
  7. Vikingsfan

    Vikingsfan Private E-2

    Thank you very much. ;)

    Does it appear that I did in fact remove all of the many items that came up in Malwarebytes? (this is my main concern and didn't want it to get lost in the post)

    Thank you for the reminder about memory I forgot to post that I had checked that and realized it is substantially less than what Major Geeks recommends. I will suggest that we upgrade ASAP.

    Lastly I have installed AVG, checked for current updates and ran a scan that came up clear.

    Thanks again so much for your help, its quite kind of you all to give of your time and knowledge.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes, but you could run it again just to be sure. ;)


    Just a quick note that as stated in the How to Protect Yourself link, AVG is quite a resource hog and will slow the PC down even more. Even if you update to 1 or 2 GB, it still impacts performance significantly.
     
  9. Vikingsfan

    Vikingsfan Private E-2

    When I open Hijack this I am not seeing the same items you've suggested I check. There are other items on there that strike me as things you may want me to address (ie Extra button Party Poker.Net, extra button messenger)

    I am fixing the few (I believe 2 items you suggested I fix) I will save a log and take a screen shot if I can.

    Please advise.
     
  10. Vikingsfan

    Vikingsfan Private E-2

    Two other things.

    First I still have the problem with the desktop background. I have read through the software forum and searched around through the internet but can't seem to find a fix.

    Second is there a less resource hungry anti virus I should look into? I have no preference.
     
  11. Vikingsfan

    Vikingsfan Private E-2

    I posted another question earlier but I am unsure what happened to it. It basically read...

    I performed Hijackthis. I only found three of the five or six suggested values to remove.

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    These are the items I could not locate, or to be more precise were not on the list.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That just means they are already gone even though they were in the previous logs you attached. Not a problem

    Junkware! Not malware and it was something you or someone else installed. You can remove them if you wish.

    Try the below but you must make sure that you close ALL browser windows before doing this.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    In the link I gave you in final instructions you will see Avira and Avast.
     
  13. Vikingsfan

    Vikingsfan Private E-2

    Thanks so much for your help. I went with Avira and I like the program.

    I already fixed the desktop, I'm not exactly sure how but I posted on the software forum so anyone who has had a similar problem can certainly check that post out.

    I've removed the junkware from the registry and am going to finish removing the programs that we've installed. The computer seems to running smoothly and I'm a happy camper for the moment.

    Thanks again for all your help.

    Mike
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds