Do I have Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wrenchman, Jun 17, 2008.

  1. Wrenchman

    Wrenchman Private First Class

    Hi I'm Wrenchman!

    I would like...could you....I mean...would you....do I
    have malware?

    Don't get me wrong, I suck @ computer stuff!

    Early in the year the computer got a little slow so
    I decided to reinstall the whole thing!

    To make a long story short I ended up with a new/clean
    win xp + all the old stuff behind about 850000 files (AVG
    8 Free Scan)

    I would like you(Malware Expert*.*) to have a look, please!

    :)

    Wrenchman
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MGlogs alone will not tell us if you are clean. MGtools is not a malware scanning program. If you want to know if you are clean, you need to run all of the READ & RUN ME and attach all of the requested logs.
     
  3. Wrenchman

    Wrenchman Private First Class

    ...OK
    ...Attaching the requested files
    ...Over and out

    :)

    Wrenchman
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We just have a little to do.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Then you need to look on what ever drives E and F are (I assume they are removable media like a CD or a USB drive) and check for the below files and delete them if found:
    E:\nideiect.com
    F:\nideiect.com
    F:\i.exe


    After doing the above you will be clean. If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  5. Wrenchman

    Wrenchman Private First Class

    Hi there buddy!

    Ok so heres what happend:

    1.
    I did the REGEDIT4
    It asked me if I was sure, I wasn't, but I clicked yes anyway(J/K)
    It said that it had been executed with success!

    2.
    E:\nideiect.com
    Yesterday I was looking everywhere for this file but couldn't find anything!

    To my surprise, I found it this morning on me digital cam.,
    I was like, wait a minute, isn't that file from MG, when the screen went blue.
    I bought the digicam used, don't know if someone put that file in there on purpose?
    Btw. I've transferred a lot of files and it has never happend before.

    3.
    SUPERAntiSpyware uninstalled!

    4.
    Malwarebytes Anti-Malware kept!

    5.
    ComboFix, I didn't understand the message at first so I
    deleted the icon, so I had to reinstall ComboFix and then
    use execute/run!
    ComboFix has been removed!
    C:\cf folder from combofix deleted!

    6.
    fixme.reg deleted!

    7.
    HijackThis uninstalled!

    8.
    C:\MGtools folder and the C:\MGtools.exe file deleted
    C:\MGlogs.zip deleted

    9.
    "see the steps to Disable System Restore"
    I can't find anything that refers to that.

    Forget what I just said,
    Step 4: Toggle System Restore
    I haven't done that yet, I'll have a look at it later!

    10.
    How to Protect yourself from malware!
    Also later, a day only has 24 hours, you know!

    :)

    Wrenchman
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just do not wait too long to finish these steps.
     
  7. Wrenchman

    Wrenchman Private First Class

    Ok a quick update!

    Well let me see>

    1.
    Step 4: Toggle System Restore:
    Done.

    2.
    How to Protect yourself from malware:
    Getting there>
    Installed Online Armor!
    Deactivated the win xp firewall!

    I think that I'm done but what about the>
    E:\nideiect.com on me Digital Cam?
    that worries me a bit!

    :)

    Wrenchman
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just delete the file!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds