After The Malware Removal Guide:

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sidz, Mar 13, 2008.

  1. Sidz

    Sidz Private E-2

    First and foremost, I'd like to thank you guys and Major Attitude for the Malware Removal Guide. I appreciate the thoroughness of it all, and the work put into this site.

    Secondly, I just finished the Malware Removal guide, and I think I completed all the tasks as said, but I still think I may be infected.

    Just to be clear, and in case this information helps:

    My Computer:

    Dell Dimension DV051
    Intel(R)
    Pentium(R) 4 CPU 2.80GHz
    2.79GHz, 504MB of RAM
    Physical Address Extension

    OS: Windows XP Media Center SP2(Up to date)

    Current Browser: FF(Up to date) Although, I used to use IE7 till I started experiencing some problems a few days ago and was informed to use FF instead.

    I am still experiencing some of the problems that I noticed before. Mainly, it has to do with selecting text and items with my mouse pointer. IE: Highlighting text, Copy + Pasting. When I try to do some of these the functions themselves become screwy. Other problems include clicking and selecting certain normal objects such as the FireFox icon to open a window. When I try that, sometimes I either have to click twice to three times to get one open, and on IE7, it will open two windows off one click. So, in short, I believe that sometimes a single click counts as two and that specific problem can be noticed when I try to push the "Back" button on my IE browser. When I do that, it ascts as two clicks and pulls me back two pages in the history. However, now I only use FF and it seems to be not as screwy as IE, although, with similiar problems still.

    The other primary problem that I have noticed is with my Microsoft Word documents, and in fact, this was the first sign of the infection. Basically, my word documents, or more specifically, a certain word document of mine, I found, was being duplicated twice over. I think it duplicated when I saved it, but am not sure, and it may have duplicated without my help.

    Third problem, or what may be a problem, anyway, is a program that I never noticed before called "Mysearch Assistant"... I looked it up and I think it said it was something installed by dell, but am not totally sure...

    And lastly, I was told to do a search on a process dictionary on all my processes running on my computer, some were iffy, about 3-4, but most were fine... Until I found this one called "isass.exe" which was determined to be a malicious process and backdoor trojan... It was not removed and is still there.
    How can I remove this if indeed it needs to be removed?

    Also, now I just recently noticed this desktop.ini thing on my desktop as well as many new files or files I never noticed before which all seeem to have been duplicated many times over.... and WOW, I JUST noticed this txt file on my computer called "H" saying "System tested"... That creeps me out...

    Attached the logs.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any malware ...and yes you need to uninstall MyWay Search Assistant.

    The documents may be "recovered" docs from an error in Word...you can always go to help / detect and repair in Word.

    And the desktop.ini as well as other files you are now seeing is because MGTools unhides system files and folders.
     
  3. Sidz

    Sidz Private E-2

    Finished The Malware Removal Guide

    After The Malware Removal Guide​


    First and foremost, I'd like to thank you guys and Major Attitude for the Malware Removal Guide. I appreciate the thoroughness of it all, and the work put into this site.

    Secondly, I just finished the Malware Removal guide, and I think I completed all the tasks as said, but I still think I may be infected.

    Just to be clear, and in case this information helps:

    My Computer:

    Dell Dimension DV051
    Intel(R)
    Pentium(R) 4 CPU 2.80GHz
    2.79GHz, 504MB of RAM
    Physical Address Extension


    OS: Windows XP Media Center SP2(Up to date)

    Current Browser: FF(Up to date) Although, I used to use IE7 till I started experiencing some problems a few days ago and was informed to use FF instead.

    I am still experiencing some of the problems that I noticed before. Mainly, it has to do with selecting text and items with my mouse pointer. IE: Highlighting text, Copy + Pasting. When I try to do some of these the functions themselves become screwy. Other problems include clicking and selecting certain normal objects such as the FireFox icon to open a window. When I try that, sometimes I either have to click twice to three times to get one open, and on IE7, it will open two windows off one click. So, in short, I believe that sometimes a single click counts as two and that specific problem can be noticed when I try to push the "Back" button on my IE browser. When I do that, it ascts as two clicks and pulls me back two pages in the history. However, now I only use FF and it seems to be not as screwy as IE, although, with similiar problems still.

    The other primary problem that I have noticed is with my Microsoft Word documents, and in fact, this was the first sign of the infection. Basically, my word documents, or more specifically, a certain word document of mine, I found, was being duplicated twice over. I think it duplicated when I saved it, but am not sure, and it may have duplicated without my help.

    Third problem, or what may be a problem, anyway, is a program that I never noticed before called "Mysearch Assistant"... I looked it up and I think it said it was something installed by dell, but am not totally sure...

    And lastly, I was told to do a search on a process dictionary on all my processes running on my computer, some were iffy, about 3-4, but most were fine... Until I found this one called "isass.exe" which was determined to be a malicious process and backdoor trojan... It was not removed and is still there.
    How can I remove this if indeed it needs to be removed?

    Also, now I just recently noticed this desktop.ini thing on my desktop as well as many new files or files I never noticed before which all seeem to have been duplicated many times over.... and WOW, I JUST noticed this txt file on my computer called "H" saying "System tested"... That creeps me out...

    These are just some of the problems I've noticed, but it seems like I keep finding new ones.

    Logs will be attached in the next post, because I tried posting this thread already, and have failed, so I am trying to just post this seperate of the logs to see if it works.

    Thanks! :)
     
  4. Sidz

    Sidz Private E-2

    Re: Finished The Malware Removal Guide

    Well it says that my attached logs can't be uploaded because they are already in the other thread I tried to create but failed, I tried renameing each one and only mglogs made it through for some reason so here it is.
     

    Attached Files:

    Last edited by a moderator: Mar 14, 2008
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...the original log you attached was in post #1....and nothing has changed so it won't upload ...what you attached in this last post was an empty zip. Notice the size = 57.kb's

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  6. Sidz

    Sidz Private E-2

    First of all, I didn't see my first thread(Which actually seems to be this one) go through, and my last two posts seem to be from the redo thread of it.

    Out of the list of clean ups you just showed me, I think I did just the Mgtools and combofix ones, as they were apart of Major attitudes Malware Removal Guide which I completed... And I'm still not sure whether I have gotten rid of all the infections... Reason being that my computer still has screwy things happen haveing to do with selecting items, scrolling, copy + pasting and such, and my clicks and actions still count as two. IE: I open a browser with single click and get two windows, or I try right clicking on something and it takes many clicks to get the right-click box to stay.

    Also, I uninstalled mysearch assistant and got this critical update from windows.

    Thanks.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then if you would:

    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  8. Sidz

    Sidz Private E-2

    Ok, here's the attached Bitdefender log.
     

    Attached Files:

    • BD.txt
      File size:
      16.6 KB
      Views:
      1
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bitdefender found nothing...so at this point I would suggest that you post in the software section. :(
     
  10. Sidz

    Sidz Private E-2

    Ok, I forgot to mention that I ran the scan once before and it did find something, but I accidentally saved it wrong. I saved it as html. I thought I mentioned that, sorry. Is there any way I can recover the first scan to be still useful for you?

    Also, so if you were referring me to the Software Forum, then are you inferring that it is a valid program or something that may be malfunctioning or incompatible?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....and you may need to either do a repair install or run SFC /scannow.
     
  12. Sidz

    Sidz Private E-2

    Alright, I think I'm good now. I just changed the mouse and everything's normal again, but it's good I got rid of the Malware too.

    Thanks very much Tim!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ..safe surfing.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds