Is my system now clean?

Discussion in 'Malware Help (A Specialist Will Reply)' started by yolkboy, Feb 19, 2010.

  1. yolkboy

    yolkboy Private E-2

    sys... xpsp3 legit (home), avg free, pc tools fw free.

    Hi. I got a trojan horse a few days ago. A few days later 'xp antispyware 2010' took over my desktop, but not my mozilla browser. It uninstalled avg and tried to make me buy its product, blocking other apps.

    I followed your guides and did everything that was suggested. xp antispyware 2010 was successfully eradicated, and now the there seems to be no trojan either.

    However, someone told me that the malware would have changed my registry and i'd have to manually delete things myself, to undo the damage. TBH i don't know if my system is 100pc clean or not.

    I will post the logs that were made in the cleanup, if someone could tell me if all the bad stuff is gone or not, i'd appreciate it.

    PLEASE NOTE, i put the roots repeal log at the bottom of the MBAM log as it's pretty much blank, to save sending another message.

    Also, when i boot up, windows gives me an option to boot into recovery mode... how do i get rid of this option so it goes straight into xp?


    Thankyou!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what these are:
    C:\Documents and Settings\Melanie\Local Settings\Application Data\NLF6AMiFd8F
    c:\windows\IDB.zip
    c:\windows\UDB.zip

    If you don't delete them. What malware issues are you having?
     
  3. yolkboy

    yolkboy Private E-2

    Thanks for replying, Tim.

    I deleted this... C:\Documents and Settings\Melanie\Local Settings\Application Data\NLF6AMiFd8F ... it was created on the day i got malware, so probably was dodgy.

    but the other two weren't there when i looked. I'd just run a virus scan, so maybe that had got rid of them.


    I seem to have cleaned up the bad stuff... like i said 'xp antispyware 2010' took over my desktop and tried to make me buy it, whilst blocking other apps. This came shortly after a trojan had got onto my pc.

    My concern now is that, although i got rid of that stuff, did it change my registry or do anything else that following your procedures won't have reversed the effects of. I don't want to run into any problems further down the line because i didn't get everything as it was before the trojan and malware came in.

    Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs were clean except for what I pointed out as leftovers. The scans took care of what little malware that existed on your system. You need not worry about any further infections as a result of this last adventure. However, do keep you AV and AS programs up to date and follow the guidelines on the below link:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to tahe cleaning procedures ian step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  5. yolkboy

    yolkboy Private E-2

    Ok that's all done, all finished.

    However, a couple of minor annoyances left over from the clean up

    1. Daemon tools wont start up or be uninstalled now...

    'initialization error 0
    This program requires at least windows 2000 with sptd 1.43 or higher
    Kernal debugger must be deactivated'

    2. When i boot up, i get the choice to load xp home OR go into recovery console...

    How do i get it to just load straight into xp without the recovery option?

    Any ideas with these? Thanks.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to post in the software forum for help with Daemon tools.

    As for you boot options, you want to have the recovery console installed in case you ever run into problems and it only slows you down for about 2 seconds. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds