handcuffed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pauliwood, Aug 22, 2011.

  1. pauliwood

    pauliwood Private First Class

    Good evening fine folks and gracious givers of your time!

    I offered to help a co worker who was asking me my thoughts on his laptop and it's funny behavior. He is having issues with Firefox (his primary browser) locking up on him. He did a Firefox update to see if that worked, no luck. He thought it was related to Firefox, switched to MS IE. Same issue. Updated IE, no luck.

    I asked if he had firewall/virus protection, he said yes, a security suite offered through his cable company. He said he ran Malware Bytes and his virus scan, and nothing was found.

    I took his laptop believing it to be malware/rootkit/spyware etc.

    I had issues initially loading and running CC Cleaner and Super AntiSpyware. Initial searches for SAS and Malware Bytes froze the system. I re-booted and scanned in safe mode, found nothing. Loaded Spybot S&D, ran and found nothing. Loaded Ad-Aware, froze while running, re-booted safe mode, ran and found nothing. Ran TDSS Killer, found nothing. Went to the website advertised on here Reimage. Found other issues, but no malicious software or malware. Tried Combo Fix, which would not go past the loading screen.

    Went to Windows update, saw he had 13 important updates ready. Tried to install. Windows froze at 0% downloading updates.

    I noticed he also had Microsoft Security Suite running. Disabled that and re-booted. Was able to run SAS which then 1 Trojan for a total of 33 issues.
    re-booted to complete cleaning process.

    Ran MalwareBytes, which found something else. re-booted to finish cleaning process.

    Ran Combo Fix, which got to the end where it says Generating log, do not run anything else till combo fix finishes. Waited 6 hours. Finally shut Pc down.
    however, in the interim, Windows Update downloaded the updates i had seen earlier.

    re-booted, tried to run combo fix again, and once again, froze on the generating report screen. So I moved on to MG Tools.

    Was hoping someone could take a look and see if we have anything left.

    Logs attached, thanks for any time you are able to offer.


    Actually, it looks like there is a combo fix log. i was looking in the root c:\ directory, looks like it is located in c:\combofix folder. Says it file size 636 kb exceeds file limit. Will try uploading in a response to this message.
     

    Attached Files:

  2. pauliwood

    pauliwood Private First Class

    combo fix log, saved as a windows compressed folder.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest that you post in the software forum for further assistance with your browser issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  4. pauliwood

    pauliwood Private First Class

    Tim,

    Thanks so much for checking the logs.

    I did use the MS help function when the latest update failed to install SP1, it referred me to a file to replace or repair missing or corrupted files as MS Help Sites says that is the most likely cause of the failed SP1 update.

    I've downloaded that and ran it while at work today, so will try the update again later tonight.

    I will follow the steps to return the laptop to normal operating status and keep the malware/spyware programs I have loaded on there and see about keeping MS Security Suite disabled.

    Thanks again !

    Regards,

    Paul
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds