Given a PC, IE Homepage was Netspry, plenty of malware...

Discussion in 'Malware Help (A Specialist Will Reply)' started by shotgunsnthehall, Aug 28, 2008.

  1. shotgunsnthehall

    shotgunsnthehall Private E-2

    This PC was given to me and it seemed to run alright, but when I hooked it up to the internet I was suspicious(mostly due to the Netspry perpetual homepage trick), so I began to clean it up. Now, my efforts lead me here and attached are my logs. Hopefully it's not too messy.
     

    Attached Files:

  2. shotgunsnthehall

    shotgunsnthehall Private E-2

    .........

    [EDIT NOTE]

    emachines, running Windows XP Home SP3, McAfee Security Center(Actually Blue-screened me when I first tried to scan with it)
     

    Attached Files:

    Last edited: Aug 28, 2008
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\fa2a1953baa10733108068

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. shotgunsnthehall

    shotgunsnthehall Private E-2

    Certain Temp files refused to be deleted-said they were in use by another program...

    I'm running Windows XP Home and McAfee Security Center, but the latter has no option to just kill it from the taskbar...I have to open the program and manually turn off my protection, however I think it may still be in the memory banks running something, but what? Should I kill any McAfee processes through task manager before I continue with the clean-up?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have disabled it from the program, go ahead and do the fix. I doubt that it will block it from working.
     
  6. shotgunsnthehall

    shotgunsnthehall Private E-2

    Bump....Still awaiting further diagnosis of my Second MGlog.zip
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay (weekend, etc.)

    Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:
     
  8. shotgunsnthehall

    shotgunsnthehall Private E-2

    Hey thanks for all the help. The PC seems to be running much better now. I decided on keeping HJT, along with SAS, MalwareBytes, and Spybot...I appreciate all the professional level help and just wanted to borrow your expertise one last time to look over one last log. The log was made through HJT, thanks in advance, I will refer everyone I know experiencing trouble to your site!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you want to keep HJT, then you need to install it properly. You have it as:
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    You need to change it to:
    C:\Program Files\Trend Micro\HijackThis\Analyse.exe

    Are you having problems?
     
  10. shotgunsnthehall

    shotgunsnthehall Private E-2

    I'm guessing I just needed to rename HJT, so I did and the re-ran. The new log will be attached.

    I'm not actually having problems with the machine. No obvious crashes or spy-ware indicative symptoms, although what strikes me as odd(and leaves me paranoid)is that certain malicious software removal apps(like Spybot, SAS, etc..)will only spot some, not all, spyware. Perhaps I would feel better if that were explained to me. How is it that one scanner will not recognize what another scanner can and vice-versa?
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All scanners are dependant on the program developers. Meaning, that as malware surfaces, the companies need to respond to them with what you experience as an update. Some respond faster than others.....so you need to be aware that NO program is 100% effective. That is why we suggest that you work thru the below link:

    And unless you know what you are doing with HJT, I would suggest that you remove it. It is not a malware removal program.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds