Could someone have a look at these log files?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sfo54, Oct 13, 2009.

  1. sfo54

    sfo54 Private E-2

    I have run through the cleaning procedures for my WinXP machine. Some threats were found and quarantined and my machine seems to be running better. But I don't think everything that was found was fixed. So I would appreciate it if someone could have a look at these log files please.

    Here's the first four.
     

    Attached Files:

  2. sfo54

    sfo54 Private E-2

    And here's the last set from MGTools.

    Thanks for your help.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than what has already been removed, your logs are clean. I do suggest that you delete the below startup files unless you know exactly what they are:
    Code:
    c:\documents and settings\TEMP\Start Menu\Programs\Startup\
    prfEF4.tmp [2009-8-23 0]
    c:\documents and settings\TEMP.MAIN\Start Menu\Programs\Startup\
    prf2B8.tmp [2009-9-26 0]
    

    Also you seem to have some leftovers from Symantec.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. sfo54

    sfo54 Private E-2

    Thanks for your help. I have gone through the cleanup steps.

    I am glad you mentioned the two startup files since these are involved with a problem that started at the same time I first started suspecting malware problems. The lingering problem I have is that one of my user accounts is now disconnected from its My Documents folder and now connected to these TEMP and TEMP.MAIN My Documents folders. If I delete the prf???.tmp files they will get re-created when I log back onto that user account. They are apparently being created by Windows but I can't figure out just why or why it started happening. But since the malware seems to be removed I think I will take this over to the software forum.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know, but as you stated, this is a topic for the Software Forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds