1. Nishant5456

    Nishant5456 Private E-2

    I ran all the scans and I think I am clean.

    I think the viruses came from a older version of Java.

    Tell me if I need to do anything else.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You missed a bunch of things from the READ & RUN ME.
    • You did not uninstall Ask Toolbar
    • Also you did not uninstall the old Sun Java version you have running and update as requested in step 3 of the READ & RUN ME.
    • You forgot to run ComboFix as requested but it is probably not necessary if you are not having any malware problems.
    • Also you did not but your PC into normal startup mode with MSconfig as requested in step 4 and as a result you have some malware trapped in MSconfig registry keys. It you wish to fix this then do as requested and put your PC into normal startup mode. You should not be using MSconfig like this.
    After doing all of the above, download the new version of MGtools , run it, and attach a new log.

    The only item of question in your logs is the below. Did you add this to your hosts file and why?

    O1 - Hosts: 74.208.10.249 gs.apple.com
     
  3. Nishant5456

    Nishant5456 Private E-2

    Sorry for all the errors I have made, but I did uninstall the Ask Toolbar after the scans and a reboot, so this was not seen in the logs.

    During installing and uninstalling Sun Java, I kept getting errors but they seemed to be gone after all the scans and malware removals.

    I did not think Combo Fix was necessary because it is a strong program and I though I did not have that bad of Malware issues.

    Also when I selected "Normal Startup" in the MSconfig, it enabled all of my Startup programs which I have been told will slow down my computer and there is some programs which were Malware startup programs before and they are disabled.

    The answer to your question is that I added the apple.com host because I was told to do so to bypass a error during the update of my iPod Touch.


    -----------------------------------------------------------------------
    Also it would be really helpful if you could let me know what program to use to get rid of the malware stuck in the registry from not booting into Normal Mode.I don't understand what program to use after booting into Normal mode with MSconfig.

    Please reply to this ASAP, and thank you for the great help.

    I have added a new MGTools log as you requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC is still not in Normal Startup mode as requested. I'm going to give you a fix which will remove a couple malware items and a few totally unnecessary non-malware startups and then you MUST put your PC into normal startup. Step 4 of the READ & RUN ME gave you explicit instructions on doing this and on how to deal with startups.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now make 100% sure that you have run MSconfig and put your PC in normal startup mode. If you are not in normal startup mode, I will not continue until you are.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 15, 2010
  5. Nishant5456

    Nishant5456 Private E-2

    I uninstalled Windows Messenger as you said,Also I cleaned/organized my Desktop out.

    I am now running on Normal Mode and the startup was faster than I thought it would take and I had no lags.

    But during the startup of Firefox, it went a little slow.

    Also I checked the ComboFix logs and it quarantined Internet Explorer, does this mean Internet Explorer will no longer be usable?

    I attached the logs as you requested.

    Also I really appreciate all the help you are giving me.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal! Firefox loads slowly the first time you load it after each boot.

    No! It removed an inappropiately named link to Internet Explorer that was on your Desktop that looks like malware. Internet Explorer is still on you PC in the C:\Program Files\Internet Explorer folder


    I have one registry patch for you to apply to remove left overs from AVG8 that you got stuck in MSconfig registry keys because you used msconfig incorrectly.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. Nishant5456

    Nishant5456 Private E-2

    Thank you for all the help Chaslang!

    I really appreciate it!

    I used the fixme.reg as requested and uninstalled other programs such as Combo Fix and MGTools.

    Thank you for helping me and the others here!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds