confirm cleaned?

Discussion in 'Malware Help (A Specialist Will Reply)' started by pauliwood, Jul 3, 2010.

  1. pauliwood

    pauliwood Private First Class

    PC has been running sluggish, so I read through the sticky. Checked for any installed malware using CCleaner, didn't see any. I disabled CD Emulators using DEfogger.

    As for cleaning procedures, I've updated Virus and Malware definitions and ran my scanners using:

    Avira Antivirus

    SUPERAntispyware
    Spy Bot S&D
    Malwarebytes Anti-Malware

    CCleaner - to clean out the garbage

    The only thing that was really found was tracking cookies via SuperAntiSpyware.

    Can I ask if someone would be able to check and ensure all the "garbage" has been removed, perhaps there are some lingering BHO's ?

    Thank you in advance!
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, pauliwood

    Please attach the 5 requested logs and I'll review them after work this evening.

    dr.m
     
  3. pauliwood

    pauliwood Private First Class

    Thank you Dr!

    MG log in my next post.
     

    Attached Files:

  4. pauliwood

    pauliwood Private First Class

    MG log file.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, pauliwood

    *You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new "Complete scan" of your system. And attach this new log.

    I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links.[ C:\Users\Pauliwood\Desktop] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    *Consider updating Mozilla Firefox (2.0.0.20) to the more secure current version 3.6.6.

    Question: Do you know what this is?
    c:\windows\WPBXJ4QCXJ4PBWI3

    Step 1:
    Please delete this as it's no longer needed:
    C:\Users\Pauliwood\Desktop\MGtools.exe

    Step 2:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 3:
    Did you set up this proxy? If not, add it along with the below analyse.exe entries: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 148.183.241.21:8080

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT

    Step 4:
    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Program Files\Mozilla Firefox\extensions\pdfforge@mybrowserbar.com
    c:\program files\pdfforge Toolbar
    
    :Registry
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
    
    :Commands
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt%21.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Step 5:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 6:
    Now install the latest Sun Java Runtime Environment

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated SASlog.txt
    • OTM log.txt

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  6. pauliwood

    pauliwood Private First Class

    SuperAntiSpyware has been re-intsalled, updated and a new quick scan has been run.

    Cleaned up desktop.

    Will update Mozilla, haven't done that yet.

    I do not know what: c:\windows\WPBXJ4QCXJ4PBWI3 is.

    Steps 1 & 2 complete.

    Not sure if I setup ProxyServer = 148.183.241.21:8080, I don't believe I did, so I deleted as suggested,

    Step 3 complete.

    Step 4, got a warning message from Microsoft thgat the file had been reported to be unsafe and the website contained links to viruses or other software that could harm my system or reveal personal information. Clicked on the option I believe this file to be safe and downloaded and ran OTM. - Step 4 complete

    Steps 5, 6 & 7 complete.

    Doesn't appear to be any further malware problems. I run Spybot, SuperAntiSpyware and Malware Bytes pretty regularly, my concern was they don't always scrub out the deeply hidden stuff that is found using MGtools.

    Wifey sometimes jumps on my laptop to check Facebook, much to my dismay, so I'm sure I get most of my tracking cookies and malware issues from there.

    Thanks again for you help.

    Attached are the logs you reuqested.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, pauliwood

    OK - Let me correct my command syntax.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :reg
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
    
    :Commands
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt%21.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file.

    Please attach the C:\_OTM\MovedFiles log file to your next message.

    dr.m
     
  8. pauliwood

    pauliwood Private First Class

    Ok, here you go.

    Pc running sluggish, could be my wireless connection, opening pages times out, yet I have a full signal on my Fios modem to my laptop.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    pauliwood

    I see no remaining malware in your logs - please create a thread in our Networking Forum about your remaining issues.

    If you are not having any other malware problems, it is time to do our final steps:
    • Double-click OTM.exe to start the program. This will remove all the tools we used to clean your pc.
    • Close all other programs apart from OTMoveIt3 as this step will require a reboot
    • On the OTM main screen, press the CleanUp! button
    • Say Yes to the prompt and then allow the program to reboot your computer

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  10. pauliwood

    pauliwood Private First Class

    Excellent work DR,

    Thanks so much for the help, much appreciated!
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds