Help! Removing Viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by dant17, Mar 15, 2009.

  1. dant17

    dant17 Private E-2

    Hi, I am new to this forum and hope you guys can help.
    I have recently had many viruses on my PC and had thought to have solved them, but i have run MBAM and I seem to be wrong.
    I'll attach the log and any help would be very gratefully received.
    Thanks
     

    Attached Files:

  2. dant17

    dant17 Private E-2

    Sorry guys, didn't read the read me file before in haste, so i have now attached all the logs from SAS, MBAM and MG.
    Hope you can tell me if my PC is now fixed or give me any info on how to fix it further.
    Thanks in advance
     

    Attached Files:

  3. dant17

    dant17 Private E-2

    Also the ComboFix log.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fortunately, the scans took care of most of it. You should not allow all users to have admin. privileges.

    Please use add/remove programs to unnstall:
    J2SE Runtime Environment 5.0 Update 4
    Messenger Plus! Live --> the source of most LOP infections!
    Viewpoint Media Player

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now lets clean up some leftover junk:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste LiveUpdate into the box that opens, and press OK
    Do this for these also:
    LiveUpdate Notice Service Ex
    LiveUpdate Notice Service
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-Run C:\MGtools\analyse.exe and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Be sure to tell us how things are running.
     
  5. dant17

    dant17 Private E-2

    Thanks TimW

    I have removed the said programs.
    The fixME.reg file was successful.
    Also MGlogs zip file attached.

    Thanks again for your help
    Dan
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. dant17

    dant17 Private E-2

    Thank you so much for your help guys.
    Computers running fine now.

    Dan
     
  8. dant17

    dant17 Private E-2

    Although i cannot open iTunes store in iTunes now.
    An error message appears saying " Make sure your network connection is active and try again" but i am connected to internet, firefox and internet explorer run fine!
    could i have removed something i shouldn't have??

    Dan
     
  9. dant17

    dant17 Private E-2

    False alarm.
    It was the firewall not granting iTunes access.
    Sorry.

    Dan
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :-D:-D No problem!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds