I hate to give you guys more work, but...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mimsy, Aug 8, 2009.

  1. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    ...it was spelled out to me that I can't know for sure that my malware is gone unless someone who actually knows this thing looks at my logs. I'll try to be good and give you as much relevant detail as possible, without clogging it with a bunch of irrelevant noise.

    Background:

    My Avira AntiVir umbrella icon went from open to close, which means it went from showing "real-time guard enabled" to showing it as disabled. I opened the program control page and checked the status of everything, and found the status to be, "AntiVir Guard - Deactivated". I reactivated it, but when it happened again later the same day, and a couple of pop-up windows flew past my desktop too quickly for me to see anything other than a flash of gray and red color, I decided it was time to do something.

    When I got stuck practically on the first step of the Read & Run I grabbed a pen and paper and started taking notes. Oh, and whenever it said to turn off my anti-virus I turned off my wireless adapter first, which meant I had to repair my internet connection a few times after turning that back on.

    SUPERAntiSpyware:
    Set the Preferences to what the R&R says, and the clicked update, and everything froze. Including the entire laptop. Waited patiently, then opened Task Manager where every single SAS part (updated, program et cetera) was marked as "not responding'. I started to end processes, and the plan was to uninstall and reinstall SAS, but when I killed the updater process the Update Wizard suddenly appeared on screen and that worked beautifully. The scan said it found nothing, but I got the log anyway.

    Malwarebytes AntiMalware:
    Said it found two Trojan-Agent-something. I told it to remove and fix them, and rebooted when prompted.

    This is where I shut the laptop down and went to bed, since it was very late and I was tired. When I started it up again after work today, to continue, XP wanted to run updates. I said no, and continued the R&R cleaning.

    ComboFix, RootRepeal, and MGTools ran without any issues or unexpected stuff, aside from Combofix making IE my default browser and putting a shortcut to it on my desktop. At least I assume it did, since showed up after the Combofix reboot. I set Firefox back to default and deleted the shortcut, since I think IE sucks. :)

    My Ubuntu dual-boot I had created through Wubi-installer is now gone though. It was there before I ran the cleaning procedure, but now it's gone. Wubi runs from within Windows and sets up the dual-boot tat way, which is great for a system lacking an optical drive, which my laptop does. I now see it as an option on boot-up, I can select either Windows Recovery Console, Windows XP, or Ubuntu, but selecting Ubuntu leads to a reboot. There is no visible trace of it in Windows anymore. :(
     

    Attached Files:

  2. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Here's MGLogs as well. :)
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your fine, Mimsy. The scans took care of the little bit of malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    That's what I was hoping for. Thanks! :) I'll remove Combofix, do the SystemRestore toggle, and all the other steps after I've had dinner. Thanks again.

    Have I mentioned recently you malware fighters rock? :major
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome, Mimsy. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds