Have been experiencing problems...lol

Discussion in 'Malware Help (A Specialist Will Reply)' started by manfromchiron, Aug 29, 2009.

  1. manfromchiron

    manfromchiron Private E-2

    OK, so I got momentarily hooked on the farm game on facebook, :-o the real issue which started several months ago,and which I thought I'd fixed until farming was too slow all the time, was a virus one of my kids picked up which , when last initiated, ran sys Restore. OK, so I ate it. then I found a user account as I was setting the machine for use again, one that I hadn't ever seen. I played with admin and disabled it, traced it and thought I had rid myself of it.
    As I can see from the attached logs and the ones I'll post on the continuation, (I'm XP pro) I have at least one serious problem lurking in the software. can You guys help me get rid of it/ or them?

    Lately the problems have just been the sow PC, this is an older VIAO 2.8 gig which I recently upgraded to 1gig ram with little or no noticeable improvement.

    BTW, I love you guys, I wish I knew where/how to get the education to make a near 50 yr old single dad a true geek, I'd gladly join the team if I qualified :cool

    Super AntiSpyware didn't find a single thing so I didn't actually save a log, my shame, sorry. the rest are attached or in the continuation

    malwarebytes log here; Malwarebytes' Anti-Malware 1.40
    Database version: 2711
    Windows 5.1.2600 Service Pack 3

    8/28/2009 5:19:55 PM
    mbam-log-2009-08-28 (17-19-55).txt

    Scan type: Quick Scan
    Objects scanned: 91169
    Time elapsed: 28 minute(s), 8 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.

    Edit: Inline ComboFix log deleted
     

    Attached Files:

    Last edited by a moderator: Sep 2, 2009
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must remember that no logs should be posted inline with messages. I deleted your inline ComboFix log since you also attached it.

    Other than what ComboFix already removed, your logs are clean. However your MGtools log is too incomplete for it to be useful. You need to make sure that you allow it to run thru to completion. Also I suggest shutting down your protection software before running it. In fact shut down you protect now, and do the below:


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
     
  3. manfromchiron

    manfromchiron Private E-2

    Thanks for the quick reply,
    I had been at the PC cleanup for too many hours and was hitting a bottle a bit..:-o so I'm lucky it went as well as it did.

    I closed AV, unplugged online connects, and ran MG tools again. below is the attached zip.

    I took another long look at my logs and also hijack this. I agree, I appear to be clean at this point in time. I guess it's time for a newer PC :major Unless you find something in the zip logs then I guess it's time to retire this old laptop and move on to bigger and faster boards. I've upgraded as far as I can go and probably can't tweak it any further with the lack of knowledge I possess. ROFL, I'm already running with add on keyboard, screen and mouse just because the original stuff doesn't work any longer
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is still very incomplete.

    Please run the below and attach the logs requested:

    Win32KDiag - How to run

    GMER - running with a random name


    Now do the below:
    • Also download Junction to your Desktop.
    • Extract the junction.exe file from the ZIP file to your Desktop too.
    • Click Start, Run and enter %userprofile%\Desktop\junction -s c:\ > C:\junclog.txt into the run box and click OK.
    • When junctions finishes its scan, attach the C:\junclog.txt file
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds