Malware scan on advice

Discussion in 'Malware Help (A Specialist Will Reply)' started by asjemenou, May 14, 2010.

  1. asjemenou

    asjemenou Private E-2

    From a previous post, my pc was diagnosed to have a probable malware problem so I ran the entire sequence this afternoon.

    I couple of remarks first.
    I read about the keygen warnings.
    In my naivete I became a keygen user after reading that a keygen will, due to the stucture, always give malware warnings though supposedly being harmless.
    I always ran them in sandboxie to be safe.
    Using them might declare my issues.

    Secondly I read this afternoon that, when using the sleepmode, mistakes and errors run in the system software.
    For months I have used this with a regular start up only every two days or so, so this might explain some strange windows behavior too like the xp explorer oftenly crashing.

    thirdly about the scans.
    I didn't see until after running Malware bytes that for every program the user guide had to be read.
    The first was SUPERantispyware which I ran with the standard options linked.
    Later on I ran it again after having read the instructions. I will only provide the last log.
    The second was the Malware bytes scan, and I scanned the entire system.
    Later I discovered that only a fast scan was required so I have two logs.
    The first one though seems to be interesting so I'll post them both.

    I attached all the logs in one zipfile.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not having malware problems. Your logs are clean. The a7uw7ih0.sys
    file you mentioned in your other thread is just a temporary randomly named file that was use by Daemon Tools that you have installed. You will not find info on them anywhere since they are randomly named.

    I suggest that you continue posting in your other thread in the Software Forum for any problems with Windows.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  3. asjemenou

    asjemenou Private E-2

    well, that's a relieve, thanks.
    I suppose that when I shutdown daemon tools the a7uw7.... problem will be over. let's try.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know! If you created somekind of boot CD on your own while it was running and that temporary driver became part of the boot CD environment, then perhaps that is why you now get an error. Or if you are trying to run from a disk emulation environment rather than from a REAL CD, then that could also be a problem. Either way, you need to continue in the Software Forum.
     
  5. asjemenou

    asjemenou Private E-2

    I just reminded that one of the malware cleaners, I don't recall which one, removed many Glary Utilities files.
    Is it unsafe?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was ComboFix. Recently it started having detections about Glary. Not sure why but likely the filenames and extensions are triggering something. Likely just false detections.

    You can restore these with ComboFix if you did not already complete my final instructions which removed ComboFix or you can just reinstall Glary Utilities. Do not use it for controlling startup processes. As mentioned in the READ & RUN ME, the improperly use registry keys that belong to Microsoft's MSconfig.
     
  7. asjemenou

    asjemenou Private E-2

    Well, I ran in all kinds of instabilities so a decided to reinstall xp completely.
    I slipstreamed the boot cd with the help of HALO so I presume it is decent.
    No problems whatsoever so far.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds