I've gone as far as I know how....

Discussion in 'Malware Help (A Specialist Will Reply)' started by Edrox, Dec 4, 2008.

  1. Edrox

    Edrox Private E-2

    This series of logs is from my wife's compy. I ran through the readme, and all cleaning procedures. I feel like I got MOST of the issues out, but there are still 2 things that I know of left unresolved. When the comp is restarted, I am getting 2 popups every time (a screenshot is attached). One is telling us to restart the machine, the other is for a java launcher that is not activcating. So, if you can review the logs, make sure I am clean, and advise on these two issues, I would be very grateful.

    Thanks for all your help and for providing this resource.
     

    Attached Files:

  2. Edrox

    Edrox Private E-2

    continued with MGtools log and screenshot
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The message to restart your machine could be related to one of the scans you ran or to finalize an update that was installed (I see in the screen shot that you are alerted to a MS Update).

    The scans removed a ton of malware.....perhaps you should uninstall your outdated AVG 7.5 and replace it with an AV program that is current. You also need to install a firewall.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6"
    Java 2 Runtime Environment, SE v1.4.2"
    Java 2 Runtime Environment, SE v1.4.2_09"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    None of this is malware.

    Reboot and install:
    Java Runtime

    Tell me what problems you are still having.
     
  4. Edrox

    Edrox Private E-2

    Hello Tim, thanks for helping me.

    The popups to restart the compy happen every single time I start. I can power the comp down completely, restart, and i get that message every time.

    I followed all of your steps, restarted machine and it still pops up. We didnt get this problem until we were infected, so I tend to think it is somehow related.

    Other than the restart message it appears to be working fine.

    As a side note, can you recommend a decent firewall, and an active virus protection?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After downloading Avast....then uninstalling AVG...you should run Avast and let me know what it reports.

    PCTools Firewall would be a good choice.

    All of these can be found HERE.
     
  6. Edrox

    Edrox Private E-2

    The good news? Avast found nothing - 100% free

    The bad news? Still getting that popup saying I ned to shut down to continue the update. It doesnt appear to be affecting the performance at all, but still would love to know what the heck it is and how to be rid of it.

    Its not a big deal to decline the shut down, but still...

    Thanks a million for your help, Tim. I know this is a volunteer thing but your assistance is greatly appreciated.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....

    The pop up is a result of something you installed, or at least started to install.

    I suggest you post in software regarding that issue. You could start by going into msconfig and one by one disabling some items to see what may be causing this. Be aware that msconfig is not a solution, just a diagnostic tool.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds