how clean is it now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by tuffluck, Aug 20, 2010.

  1. tuffluck

    tuffluck Private E-2

    i was having some problems with my work computer in the first week i got it. IE or FF would lock up when you tried to load a new page. found out they forgot to install a virus protection program. i installed antivir and found malware (TR/HM.Agent). removed it but the problem was still there. i followed the "windows xp cleaning" procedures on this website and got through combofix, which seems to have fixed all my issues so far. ironically i ran mbytes last night and that also seemed to fix things, for the next 12 hours until they returned this morning (and this morning i ran combofix and now everything is running very smoothly).

    i figured i'd complete steps 4 and 5, so i tried to run rootrepeal, but it gives me the error that i do not have disk access. i presume this is due to my laptop being owned by my company and me not having the rights to the disk. things are working fine at this point, but i wonder if it's REALLY clean, especially if i can't finish RR and MGTools? i was on myfico.com this morning and typed in my SSN and was about to hit enter when i thought, "wait a second, what if there is still malware on this PC? that would be dumb to load a webpage with your SSN on it," so i cancelled the webpage.

    BUT, i can't have that fear forever. thoughts? is it really fixed?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In order for us to help you, we need to see the logs from running:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip --> from running C:\MGTools.exe
     
  3. tuffluck

    tuffluck Private E-2

    thanks tim. our IT department got involved because i put in a ticket earlier and they called me back. they install mcafee virus scan and caught a virus and malware. however the problem is back again. in the process of trying to fix the problem they also removed all of the previous programs i had run, and i can not find the log for mbytes and super anti-spyware. should i run them again? i did have an extra copy of the combofix log and they ran a hijackthis log as well. i have posted those but if i need to run the other programs again please let me know (in the instructions for cleaning xp it says only run the programs once so i don't want to screw anything up...besides i'm not sure if they would catch the problems again). mcafee virus scan did pick up and remove a virus called "pink slip trojan," but like i said the symptoms of delayed and non-responsive IE and Firefox are back.
     

    Attached Files:

  4. tuffluck

    tuffluck Private E-2

    tim,

    i'm sorry i can't edit my original post. i was able to retrieve the super anti-spyware and the mbytes log files as well. there were 2 mbytes log files because the IT department also ran this program on their own even though i told them i did it already. i wish i had just let you guys help me rather than deal with them as they screwed up this process. here are all the files again, minus the hijackthis file. here is the order they were run:

    super anti-spyware
    8.19 mbytes
    (combofix log in previous post, but it was run in between mbytes sessions)
    8.20 mbytes
    (hijackthis log now, file below)

    please let me know what else you need from me. thanks for the help.
     

    Attached Files:

  5. tuffluck

    tuffluck Private E-2

    sorry i wish i am able to edit posts and i would not be posting over myself so many times, but i forgot to mention that MGTools wasn't run because the IT department has locked McAfee virus scan so that it can never be disabled. if there is a way around this, i will run MGTools and then post the log, but that is why i did not post that log so far.

    again, sorry for the multiple posts. please let me know if the 5 attachments i have provided thus far are helpful enough for you.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the C:\MGLogs.zip. If need be, run it in safe mode.

    Do you know what these are:
    c:\documents and settings\All Users\Application Data\Microsoft\zfoola6\zfoola.dll
    c:\documents and settings\All Users\Application Data\Microsoft\zfoola6\zfool.dll

    If not, delete them.

    You need to put ComboFix directly on your desktop, not here:
    Running from: c:\documents and settings\20407110\My Documents\Downloads\ComboFix.exe
     
  7. tuffluck

    tuffluck Private E-2

    tim,

    i attached the document.

    looked for zfoola6 and it is not found, also not a hidden folder either. it must have been removed from the computer by the mcafee scan or the later mbytes scan that was done by the IT department. is it possible the file is still there and i can't see it?
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I am seeing is this:
    C:\WINDOWS\eooqxeevsa --> delete it.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  9. tuffluck

    tuffluck Private E-2

    thanks for the help. since i did not do combofix from the desktop, is there any harm in it not being uninstalled? rather, is there a way to uninstall it otherwise? i google'd this and saw to type combofix /uninstall but that returned a "combofix could not be found," probably only because i deleted the file before the IT guys worked on my PC, since i didn't really want them knowing that i was trying to solve the problem on my own and get in trouble with it.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it's not a problem. But a word of caution. In the future, since this is a business computer, it would be best that you allow your IT dept. to handle these situations. There is always the chance that if working with us or some other malware site, if something went wrong, we could be held liable. :major

    On the run box, paste this in:
    "c:\documents and settings\20407110\My Documents\Downloads\ComboFix.exe" /uninstall
     
  11. tuffluck

    tuffluck Private E-2

    whoops, i did not know that. sorry, i will be more careful next time.

    i pasted what you said in there and i guess it didn't find the file because i deleted it. i downloaded the file to that spot again, and when i tried to uninstall, it tried to reinstall and start all over, so i just clicked "no" when it asked me if i accepted the disclaimer at the start. then i just deleted the file again. i won't worry about it not being officially uninstalled.

    also...last question i promise, every time my pc boots it pauses briefly on the "start windows xp or start windows recovery console," and i guess this is because combofix installed windows recovery console. is there a way to remove windows recovery console to avoid this screen when it boots?

    thanks again, i appreciate it.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can go into msconfig from the run box and under the boot tab, remove the recovery console option. If you need further assistance with that, please post in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds