Did I fix my computer correctly? Had malaware and spyware from virus.

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrsgarde, May 13, 2008.

  1. mrsgarde

    mrsgarde Private E-2

    Ok, I have McAfee, and I still seemed to get a really bad virus. Long story short, I thought I found all the viruses and spyware crap and manually deleted them all, since McAfee didnt detect anything. So I thought everything was fine, untill I was getting pop-ups literally every minute and it was impossible to be on the internet. I found the thread "Windows XP Cleaning Procedure" and followed it. I downloaded and ran all 5 programs. By the 3d one, Malwarebytes Anti-Malware, the popups seemed to stop, but I continued with the others. I did end up deleting the SpyBot becasue it kept trying to scan my comp every time it rebooted, and kept prompting me to accept or deny registry changes. So, I got to the last one, MGTools.exe, and have attatched the log files from the scan. Please let me know if my computer is fixed, and if I can delete these programs I used to fix it. Also, what software should I have to protect my computer, as McAfee isnt doing the job!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you start at the Windows XP Cleaning procedure or did you start with this READ & RUN ME FIRST. Malware Removal Guide Based on your logs it appears that you did not start with the READ & RUN ME as required.

    If you started at the XP Cleaning procedure then you need to start at the beginning.

    Either way, you need to attach ALL of the requested logs in the XP Cleaning procedure. There are 4 requested logs.
     
  3. mrsgarde

    mrsgarde Private E-2

    Ok, I did go through most of the things, but I did not run CCleaner. So, do I have to run the CCleaner and then do ALL of that all over again? It literally took me all day!!! My computer is running faster and with no popups at all. Did you see any malware or spyware ?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to see all of the logs! MGtools is the very last thing not the first.

    You skipped more than CCleaner. Old Java versions are still installed too. And MSconfig is being used.
     
  5. mrsgarde

    mrsgarde Private E-2

    Ok, I will do the java removal and the cclean, and I guess I didnt understand about the msconfig, Ill have to read it more thoroughly. I just want to say that if I dont select certain things for the start up, then it will run everything, and Ive heard that that is bad because it slows your computer down, and in my experience, it does! So thats why Ive always used it. I had a very smart IT guy help me with that a long time ago and he said you had to select certain things otherwise it takes up too much memory on your computer. Well, Ill do whatever it says and re-run all the programs and show you all the updated logs. Ill get back asap.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wrong approach! See the infor given in the READ ME. MSconfig was not designed for this purpose. Other tools were. And if you don't need the software to run, the first option should be to uninstall it if it is unnecessary.
     
  7. mrsgarde

    mrsgarde Private E-2

    Yeah, I did everything on the "read me first" this time, and I ran the ccleaner and decided to delete startup programs from there, like you said. I did notice that there were programs in there that were not even on my computer anymore? is that just a glitch? I deleted them anyways, but now Im worried that there are fragments of the program floating asround in my computer, and yes, I did defrag. I do that on a regular basis too.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is due to using MSconfig and then uninstalling while still using MSconfig. This was mentioned in the READ ME.

    Please attach the other logs requested in the read me along with a new MGlogs.zip file that was obtained after completing all the other steps. If you do not do this, we cannot help you.
     
  9. mrsgarde

    mrsgarde Private E-2

    Ok, I did everything like you told me, but since yesterday I ran the 5 programs, It didnt detect many viruses. Altho, One kept popping up in things and it was Trojan.Vundo. So, I dont know, that was there yesterday and it came back today. Well, here are 3 of the logs...
     

    Attached Files:

  10. mrsgarde

    mrsgarde Private E-2

    Ok, heres the last one. Now after you look at all this, please let me know if I can delete all these programs, or if I need to keep them. Thank you.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    On the contrary!!! Malwarebytes found a ton of problems however it shows that you did not fix them. Why didn't you have MBAM fix what it found? You will need to re-run it and fix everything and attach a new log. Meanwhile I will look at your other logs.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you really use the below SupportSoft software and remote assistance? Do you really want to have a service running all the time to allow remote access into your PC??
    O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe

    Uninstall the below software:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {75BFF33B-F35E-4547-BEBF-08E055B8D0F6} - C:\WINDOWS\system32\ssqNGAsQ.dll (file missing)
    O2 - BHO: (no name) - {DE85C1B9-C373-46D8-82CB-DC7C9FF83CD5} - C:\WINDOWS\system32\qoMffFxW.dll (file missing)
    O2 - BHO: (no name) - {F90CF001-2474-4C30-A754-D7B2AA7859F0} - C:\WINDOWS\system32\ljJaBTli.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - Startup: PowerReg Scheduler.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    • And don't forget a new MBAM log that shows that you fixed everything too!
    Make sure you tell me how things are working now!
     
  13. mrsgarde

    mrsgarde Private E-2

    Hi. Thank you for helping me with all this. Well, I didnt realize I skipped the viewpoint stuff. So Ill delete that and do everything on the list. As far as the SupportSoft thing, I really didnt know I had it running on there and It wasnt something I realized was something bad. So, tell me how to delete it. And also, the second time I ran the MBAM, It found no infected files. Maybe I posted the wrong log from the first time. But there is the log I just ran. It found nothing.
     

    Attached Files:

  14. mrsgarde

    mrsgarde Private E-2

    Ok, I did it all... everything is running fine. I got the sucess message that you were hoping for as well. here are the logs...
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not malware! It is just something you may have gotten with your PC (maybe from DellSupport) or from an ISP. If you don't use it (and most people don't), there is no sense having it on your PC. Allowing a service to run all the time that can be used for remote access is not only a waste of system resources, it is also a potential security risk. What would you like to do with this? You logs are otherwise clean.
     
  16. mrsgarde

    mrsgarde Private E-2

    Well, Im glad everything is cleaned out finally! I was so shocked at all the viruses those programs found the first time! So now, I would like to get rid of the Support soft. Do I manually delete it? I dont see it in the add/remove programs list. Also I would like to know if I can delete all the programs I used to fix my computer and What type of antivirus program I should have. I have McAfee now and it seems to be ok, but maybe not becasue I had so many infected files! What do you reccomend?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the below.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SupportSoft RemoteAssist
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Then reboot. After reboot look for the below folder and delete it:

    C:\Program Files\Common Files\supportsoft

    Covered in my final instructions.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  18. mrsgarde

    mrsgarde Private E-2

    ok, great! one more question. Can I delete spybot? or should I keep that. and thank you again for all your help. I think this virus was actually a good thing that happened, becasue now I have my computer running better than it has been in years! thanks again.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keep it as recommended in the How to protect yourself thread.

    You're welcome. Surf safely!
     
  20. mrsgarde

    mrsgarde Private E-2

    ok. thanks! You will definitely be my go-to guy if I ever have any more problems, but I will keep all your threads in my favorites to go to as a reference. I do feel weird uninstalling McAfee, but if you reccomend the others, I trust you. My computer is saved thanks to you. Take care.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you like McAfee and do not have a problem with how it impacts system resources and don't mind paying for a yearly subscription then you should keep it. When you decide you don't like it anymore, that is the point where you should change your AV.
     
  22. mrsgarde

    mrsgarde Private E-2

    I do have another question. I uninstalled my McAfee with the tool you have on this website, and I installed AVG. Ok, my question is, that I tested the program and searched for porn in my google toolbar. A bunch of websites popped up, and to my surprise, there was a green check by EVERY ONE! I had McAfee, and there would have been a ton of red exclamation points. Is AVG really ok to use? I feel like its just ok with every website on the web! I havent seen one website that didnt have a green checkmark, and its making me wonder about how effective it is. I also installed the a-squared as well.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you speaking about AVG 8's LinkScanner. Do you have it enabled? You can get a user's manual here: http://free.grisoft.com/ww.download?prd=afe#tba3

    It may not be as current as McAfee's SiteAdvisor.

    If you feel that you need a website advisor program ( I personally don't like them but some people think they need them ) that protects you from yourself then maybe you still need McAfee. You can also reinstall just site advisor from here: McAfee SiteAdvisor
     
    Last edited: May 30, 2008
  24. mrsgarde

    mrsgarde Private E-2

    Hi, Its mrsgardea again. It seemed that everything was fine after I de-contaminated my computer and got rid of McAfee, but once I installed all the programs you had suggested, my computer once again is running EXTREMELY slow. Like unberably slow, and gets stuck a lot. I really don't understand how a computer can run this bad when it says I have about 75% free disc space. Is there anything you can suggest to help me?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the current version of MGtools.exe and run it and then attach a new MGlogs.zip file.
     
  26. mrsgarde

    mrsgarde Private E-2

    ok, here's the zip file...
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future make sure that you follow the instructions for downloading and running tools. You ran/opened MGtools.exe directly from the download link as the below shows it running in your Temp Internet Files folder:

    C:\Documents and Settings\Zsazsa\Local Settings\Temporary Internet Files\Content.IE5\CW67C3G2\MGtools[1].exe

    There will be many cases where if you do not follow instructions, things will not work properly and you could even cause serious problems.

    Uninstall A-Squared to start and see how things look. If still slow, continue.


    You can also have HijackThis fix/remove the below unnecessary startups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    After clicking Fix, exit HJT.


    Do you use all of the Roxio software? It has 5 services running. I have seen many instances where this is the cause of PCs slowing down. You only have 512 MB of RAM and have to be careful how much you allow to run. You also have services from Google and Dell that are unnecessary.

    Your other alternatives are to try another firewall other than Online Armor and then try using another antivirus (like Avast) instead of AVG8 if that still does not help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds