Infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by ToniW, Jan 20, 2009.

  1. ToniW

    ToniW Private E-2

    Hi, I originally was hit with the fakealert which I thought was taken care of. Apparently it was not the only one, as when I went through the cleaning process (hope I did it right!) Vundo also popped up and rouge.component (virus?).

    I am attaching the logs except I can't find the SASlog.txt. I found the combo log by accident, so Im unsure what I should do now.

    Thank you for any and all help!
     

    Attached Files:

  2. ToniW

    ToniW Private E-2

    I also forgot to mention (and I was too late to edit) that in my windows, I also found a whole bunch of files in blue with the names starting $ntuninstall and a bunch of number after. Not sure what this is, either and I'm sure they were not there before.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    This shows in your log which I don't understand....
    That has to be a mistake in the report. :(

    The SAS log is here:
    Code:
    C:\Documents and Settings\Mom\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log  Jan 19 2009        1131  "SUPERAntiSpyware Scan Log - 01-19-2009 - 16-02-55.log"
    
    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    You should also disable the guest account in user accounts.

    In the meantime,.....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  4. ToniW

    ToniW Private E-2

    Thank you so much, TimW!

    I wonder if there's some other problem that may show this weirdness on the memory? Do you think a defrag might fix this (assuming this might even do anything)?

    I see there's a thanks in the posts. I'd like to add a thanks from me there and I would, if I knew how......
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click my computer and choose properties.....on the general tab you will see what it reports as the installed memory ( or at least what is recognized).
     
  6. ToniW

    ToniW Private E-2

    Just got home and on #2 of the list.

    I went to start, run and entered the info into the box, but it seems to want to run ComboFix. What am I doing wrong?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    are you putting in the /u switch?

    You can manually delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
     
  8. ToniW

    ToniW Private E-2

    OK, I guess I should have known that! :-D

    Last couple of questions, then I'm good and won't bother you any further.

    When I pull up my windows in the c drive, there are numerous blue files that previously was not there ($NUninstall and a bunch of numbers after). Should I be concerned?

    When I'm saving a file/document, it takes awhile (like it's pausing for the longest time pondering whether it should do it or not and then I can't click on anything else as then I'll get the dreaded not responding message and lose it) before the folder to open up so I can continue (I know this is not the place for you to answer but if you can point me as to where I can get answers for this type of thing, I'd really appreciate it)

    Thanks again for all your help, TimW!!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome.

    The "blue" files on the c drive are the uninstall files for your MS updates. If an update causes issues, that would be how you uninstall it.

    The issue with opening folders and such would best be discussed in the software section. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds