I need someone to tell me if I am clean, now.

Discussion in 'Malware Help (A Specialist Will Reply)' started by bomber1712, Mar 14, 2009.

  1. bomber1712

    bomber1712 Private E-2

    I have followed all of the instructions in "READ & RUN this first". I have attached the logs as instructed. Please look them over and tell me if I need to take any further steps.

    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are still things to do. First, use windows explorer to find and copy:
    C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
    and then paste it here:
    c:\windows\system32\ ....if it asks to replace the current file, click yes.

    Now, disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now again use windows explorer to find and delete:
    C:\WINDOWS\ibidigipa.dll

    Now download and install:
    Java Runtime 6

    Now re-run Combo.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  3. bomber1712

    bomber1712 Private E-2

    Thanks for the help! I am very grateful for your assistance!

    I did OK with all of the instructions. I did get the "Success" message when running the fixMe.reg. I had trouble with ComboFix. I ran it, and it seemed to go OK. I got a log that popped up. I saved it and then closed it. Then, nothing happened! I was stuck at my "splash" screen. I let it sit for a while (half hour or so). No change. So, I turned off the computer manually and then restarted. The clock was messed up, so I figured Combofix had not finished. I waited a while to see if anything would happen, and nothing did. So, I reran Combofix. Same result.

    I have attached the log from the 2nd run. (I accidentally overwrote the first, sorry).

    I didn't run MGTools, because I wasn't sure how to finish the Combofix. I didn't want to run another program without fixing this issue first.
     

    Attached Files:

    Last edited: Mar 16, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the new MGLogs.zip. The Combo log looks fine. :)
     
  5. bomber1712

    bomber1712 Private E-2

    Here are the logs you requested. Should I just manually fix the clock?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...your good.Let's just finish you up. :)

    These instructions should reset your clock.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. bomber1712

    bomber1712 Private E-2

    I still have a problem.....When I am online, none of the graphics show up (that was a big reason why I sought your help!). Wherever there should be a graphic, I see a placeholder (small square with a red square, blue triangle and green circle).

    Also, the clock did not reset after following the steps. Are these just setting issues, or do I still have something infecting me?

    I have a program that I used before we met called SmithFraudFix. Can I just delete the files that are on my desktop?
     
  8. bomber1712

    bomber1712 Private E-2

    I also noticed that I cannot change the "Automatic Updates" settings. I tried to use the red sheild in the tray, but it told me it could not do it that way. It suggested that I use control panel, system. So I did. It says its enabled. Then, when I click the red sheild, again, it shows as disabled. I tried changing it via Start>Run>services.msc. When I attempt to change the aetting for Auto Update from disable to Automatic, I get an "Access Denied" message.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just settings.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.

    For the graphics not show there could be multiple reasons why so you should probably work that in the Software Forum. Most of the time it can just be a browser setting. Like with Internet Explorer, on the Tools, Internet Options, Advanced tab under Multimedia. You need to have Show Pictures checked. But you could also be blocking them with a firewall or something else.


    Yes.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may also be a topic for the Software Forum since you logs are clean. However try the below.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Now run this Resetting Registry and File Permissions

    After the reboot, see if you can change the Automatic Updates setting to automatic.
     
  11. bomber1712

    bomber1712 Private E-2

    Thanks for all of your help! I think everything is fixed, now! :celebrate

    Is there anything else I should do, or are we done?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    As long as you have completed TimW's final instructions we are finished.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds