Is it clean?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Somemelvin1, Jan 31, 2011.

  1. Somemelvin1

    Somemelvin1 Private First Class

    I suspected a virus because my system was slow. I executed the major geeks malware removal steps with varing results and I have attached the logs.
    Note:
    1) Malware bytes removed 3 items from Microsoft\Security Center. Afterwards I had a red icon on try saying that my automatic microsoft updates were turned off. I then manually turned them on. And it says "windows found 80 updates." ***Should I install them??
    2) root repeal did not execute properly. (It downloaded and extracted fine.) When I tried to run it, I got "Could not read the boot sector. Try adjusting the Disk Access Level in the options dialog." After a couple of times hitting the button, it eventually started. but it appeared to freeze up. I have attached, what looks like, a partial log.
    3) After rebooting after combofix, I received a "windows installer" window saying "preparint to install." And "doscan.exe" used 163,912K of memory for quite a while.
    4) superantispyware appeared to eliminate a virus.

    Any advice would be appreciated.
    Thanks.
     

    Attached Files:

  2. Somemelvin1

    Somemelvin1 Private First Class

    ...and the last log
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Somemelvin1

    Don't be concerned about RootRepeal or it's partial log - it can be "iffy" at times. I'll review your logs and will post back.

    dr.m
     
    Last edited: Jan 31, 2011
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Somemelvin1

    You should increase your installed RAM to atleast 1GB for running XP SP3 without experiencing system lags.
    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\lincofa\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    *It seems that the scanners took care of the malware but I would like to gather some info:

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :service
      Heilupcaent
      :filefind
      *Heilupcaent*
      :regfind
      Heilupcaent
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    I would recommend that you use the below links to verify updates are needed:
    dr.m
     
  5. Somemelvin1

    Somemelvin1 Private First Class

    I didn't realize the vulnerability of the desktop. Are .doc and .jpg files ok to keep there?

    I will look to purchase 1GB of memory.
    I completed the Microsoft updates.
    SystemLook log attached.

    Thank you.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    It would be best to only have shortcut links on your Desktop.

    *What can you tell me about this stopped and disabled service - I can't find any info on it:
    Heilupcaent
     
  7. Somemelvin1

    Somemelvin1 Private First Class

    I am unfamiliar with this term.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Somemelvin1

    Please run the below online scanner. NOTE: This scan can take over 1 1/2 hrs. - please be patient.
    ESET Online Scanner

    Please attach the eSet Online scanner results to your next reply.

    dr.m
     
  9. Somemelvin1

    Somemelvin1 Private First Class

    Per your request, I have attached the results although it doesn't look like it includes very much in it. This scan did find malware. (I selected a copy to file option.)

    Also...
    1) Will there be a noticeable difference upgrading to an additional 1GB vs an additional 512MB?
    2) I have verified that Microsoft automatic updates is turned on. However, I'm not sure what you mean about "the service status needs to be Started and the Service type needs to be Automatic."

    Thank you.
     

    Attached Files:

    • eset.txt
      File size:
      103 bytes
      Views:
      4
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! In fact 2 GB is highly preferred for Win XP. 1 GB is the minimum we recommend. The fact that you have only 512 is a problem. So if you are going to update, it would be better to go to 2 GB.


    There are many reasons for Windows Update not working and quite a few of them are not due to malware. Windows Update had been a notorious problem for tens of thousands of people thru the years which is one reason there are so many "possible solutions" on Microsoft's own website for this. Frequently, try everything suggested still results in failure. If you are having a problem with ONLY Windows Update and no other problems, it would be better to work them in the Software Forum. However please run the below.


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  11. Somemelvin1

    Somemelvin1 Private First Class

    log attached
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. Somemelvin1

    Somemelvin1 Private First Class

    I'm not sure why my log doesn't have the file listings like your example.
    So I ran it again. Just to verify: both boxes are checked under Objects to Scan (Services and Drivers, Boot sectors)
    I've attached the new log, however there are no more files in it than the last log.
    I also tried running it after I disabled Symantec. no change.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • When you click the Start Scan button, does it run a scan and show a running list of Objects which are being scanned?
    • When it finishes the scan, do you see a Scan completed form?
      • If yes, on this forum does it say Infection: not found
    • After you click the Close button to exit the Scan completed form, did you click the Report button to generate a report ( even if nothing is found a report can be made).
    Looks like you may be clean anyway. Are you having any malware problems?
     
  15. Somemelvin1

    Somemelvin1 Private First Class

    Sorry for the delayed response, we had to reinstall the OS. In my effort to "clean-up," I must have deleted a couple of system files.

    Thanks for the help.
    All is clean now.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds