Much malware, popups, browser highjack please check logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by trisha, May 29, 2011.

  1. trisha

    trisha Corporal

    This is a friend's computer. She is running a PC with Windows XP Home SP3.

    She was experiencing a problem with what she called pop ups with a lighthouse.

    Anyway, when I looked at her computer and clicked on the link in question inside her *Incredimail*, what was happening was the links were trying to open Netscape Navigator browser which she does not have.

    Anyway, after cringing when I saw she had Incredimail, I checked to see what other *programs* she had installed.

    Among some of them were the following:

    MyWay or MyWay Search Assistant
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Viewpoint Toolbar
    Viewpoint Toolbar (Remove Only)

    She also had a bunch of files saved to her desktop. I selected them all and dragged them to a folder on the desktop for a temporary fix. I then sent the files on the desktop to the recycle bin. When I ran CCleaner, oops, the recycle bin was emptied along with her *important files* I am sure you are laughing right now because you know what I have in that folder is shortcuts to those files. Poof, her *important files* are history.:cry

    I did create a System Restore Point before creating beginning any work. I am thinking if I restore that point the files will return to the desktop. Am I right?:confused

    My friend is not happy.

    Running the scans and doing the uninstalls of the various programs took almost 10 hours. She had a lot of bad stuff on the computer. I did convince her that Incredimail is not a good thing, even though the dog was cute that would run onto the screen to announce the mail arrival.

    Configured Outlook e-mail accounts for her.

    Incredimail has made itself the search engine of choice even after running all of the scans and clean up.

    I couldn't run Root Repeal. It did the same thing it did on my own computer the last time I tried to run it. It stalled and then said virtual memory was too low. It did not matter that the system had a fresh reboot.

    Please check scans and advise. Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you want to do? Do you want to do a system restore? It will replace those files/folders, but you would need to start the malware process all over again.

    If you do that, this time put ComboFix directly on your desktop, not here:
    Running from: G:\ComboFix.exe

    Do you want to remove everything Incredimail?

    As it stands right now, your system is clean. What malware issues are you still having, if any?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NO!!!! System Restore is not a backup program. It does save certain system files and registry info. It does not backup personal info.


    Also note that CCleaner is no longer part of the READ & RUN ME because new malware is hiding and moving important system files in temp folders and running cleanup programs ( like CCleaner ) would delete these important system files. Thus we no longer ask for CCleaner to be run in the READ & RUN ME.
     
  4. trisha

    trisha Corporal

    If I have to do a system restore to get those files back, then that is the trade-off - having to do the malware process all over again. My friend really needs those files back.

    OK. I thought I did send that one to the desktop from my usb drive.

    Yes. I was under the impression the Incredimail is some sort of malware. Am I incorrect in having that impression?

    The Search provider is still Incredimail even after the clean up and uninstall.
     
  5. trisha

    trisha Corporal

    So I can't get those files back on the desktop by doing a system restore to the point I created before I started the work on the computer?


    OK. So do you still recommend running CCleaner on a clean system?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can always try a system restore, but it may not get some of your stuff back. If not, you can undo the restore.

    Incredimail is not malware. That's why I didn't give you a fix to remove it all. However, we can do that if you go through the procedures again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds