Help please with Malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by MOKeefe, Aug 31, 2010.

  1. MOKeefe

    MOKeefe Private E-2

    WinXP Pro SP3 build 2600, Intel Celeron 2.53HGz, 2 gig RAM, Biostar U8668D mb, Phoenix-Award Bios v 6.00pg

    This computer was removed from service simply to replace with a newer computer. It was used to run a billing application.
    I was doing normal testing and maintenance on the computer when I noticed Malwarebytes would not run. That was the only symptom that got my attention.

    Current status:
    I can run Spyware S&D with no results.

    I cannot run HijackThis. It does not even begin to open.

    I uninstalled Malware bytes then downloaded a new install program, renamed the install to Bam.exe. It installed OK but upon initial launch it closes immediately. When Malwarebytes is run from icon, it opens to desktop and closes quickly.

    I could not install Windows Defender. On the first attempt to install I got the message’Windows Installer is not running.’ I started Windows Installer manually and Defender installed. I cannot get Defender updates but get ‘error code 0x80240022.’
    I can scan with Defender but no problems are reported.

    I ran SmitFraudFix and got a scan report that these were detected and to use a Rootkit scanner: xpdx xpdt huy32 pe386 lzx32 msguard
    I located xpdx huy32 in HK_CU/Microsoft/Search Assistant/ACMru/5603 and deleted both .

    I finally decided to use the MajorGeeks detailed instructions beginning with ‘Getting Started’ and followed each step of downloading programs then running per the instructions under ‘Windows XP Cleaning Procedure’.

    The results are these files: MGLogs.zip rootrepeal.txt and ComboFix.txt
    SUPERAntiSpyware did not detect anything and did not create a log file.
    I cannot run MalwaBytes to create a log file.

    I appreciate your help in interpreting the logs to track the varmint.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Why am I also not seeing any AV software installed?

    Have you tried running SAS and MBAM on this user: Coahoma Electric

    What about safe mode, do they run there?
     
  3. MOKeefe

    MOKeefe Private E-2

    Thanks TimW for such a quick reply.

    I have logged in as Coahoma Electric - I successfully got MalwareBytes updates and am running a scan now. I will run SAS as well. I know I tried both users yesterday with the same results because I was following the directions. But I did not try to run Malwarebytes today as Coahoma after completing all of the steps. I just sent the log files. I will do more thorough testing now as both users and post the results - hopefully tomorrow morning.

    We have a Sonicwall firewall with client AV services. Do you recommend having an AV installed on each computer as well as having the firewall AV client services?

    I very much appreciate the assistance.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are running this through a server, then no. Although I don't recall seeing the client software installed.

    Attach the logs when you are ready, and make sure to identify which user account it is. Also run MGTools on that user account.
     
  5. MOKeefe

    MOKeefe Private E-2

    I ran Malwarebytes and SAS successfully as both users, Michael & Coahoma with no threats found.

    I then ran MGTools as each user and have attached both log files.
    MGLogs.zip as Coahoma and MGLogs Michael.zip

    It appears some malware lurker was removed during the initial process of running through the complete process.
    It was a really good learning experience.
    Now, I will be alert to testing each user on a computer.

    Re: Server AV, I am checking with Sonicwall to make verify the client side of the server AV is configured.

    Many thanks for your time.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. What issues are you having, if any?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  7. MOKeefe

    MOKeefe Private E-2

    TimW

    No issues to pursue. Just a good ole standard WinXP box which can be safely put back in service.

    Thank you for the detailed instructions to complete the process. I will do so immediately.

    It has been a pleasure working with you.

    We can close this thread. ( if there is something I need to do to close the thread let me know.)

    Michael
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is nothing you need to do to close the thread.

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds