Logs for review XP- clean now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by wondering1, Feb 1, 2010.

  1. wondering1

    wondering1 Private E-2

    Had a few problems but seems okay for now.

    1) To add/remove programs, had to turn off the internet each time (disabled the wireless radio). While connected to the internet, when I tried to remove the listed programs, it would bring up a message saying it was unable to remove them because Windows Installer wasn't present/safe mode/etc. I was not booted in Safe Mode. Did get everything removed, I think!

    2) After running SAS, I rebooted the computer. It rebooted itself again and offered me safe mode/normal/etc. I selected normal and it booted successfully.

    3) About halfway through the procedure, Windows Firewall finally "stuck" to be ON when booting. Prior to getting about halfway through, I had to manually enable Windows Firewall each time.

    Everything else went okay. Here's the logs.
     

    Attached Files:

  2. wondering1

    wondering1 Private E-2

    Last log. Thanks so much for all your help!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, not seeing alot to do here, let's start with this:

    1. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2. If the below is just a useless trial which wont fix anything anyway then please uninstall it.

    • Spyware Doctor 7.0
    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    iWinTrusted
    
    File::
    c:\program files\iWin Games\iWinTrusted.exe
    
    DirLook::
    c:\documents and settings\Owner\Local Settings\Application Data\wmlpln
    C:\Virus Removal
    C:\Program Files\Common Files\system\Virus Removal 
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    c:\program files\iWin Games
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. wondering1

    wondering1 Private E-2

    Excellent! Attached are the two logs.

    How are things going? Great!

    I just ran Avira AntiVir and it found DMXGameLaunch.exe detected as ADSPY/BetterInternet.VC.

    All seems well!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What was the complete file path of where it found it?

    That's good. But it apears you didn't attach the logs for me to confirm this. Also answer my question about the threat found by Avira!
     
  6. wondering1

    wondering1 Private E-2

    Sorry!

    AntiVir does report many "warnings" for graphic files so I'll include that log, too.


    Not sure what happened to the logs except that it was a long time between when I uploaded them before I clicked the "submit reply" button (was watching the Antivir scan).
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes your AV was just doing it's job.

    Delete these empty directories:
    Is there anything else inside of the "system" folder?


    You should not have so many users on one machine all with admin priviledges, it's not a wise idea.


    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. wondering1

    wondering1 Private E-2

    Ah, I now realize that these items are stuck in system restore until I reset the restore point.

    Deleted wmlpln & Virus Removal (my folder with the tools I downloaded to follow the directions and save logs)

    c:\program files\Common Files\system\ contains the following:

    ado directory
    msadc directory
    Mapi directory
    Ole.DB directory
    directdb.dll
    wab32res.dll
    wab32.dll

    I will talk to the owner about the accounts, etc.

    I'll talk to the owner about removing the DellGames and WildTangent/DellGames because AntiVir flags all the images in these directories as "warnings" (internal error, file could not be written, etc).

    I've completed all the steps.

    Thank you for all your help and time!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK then, leave that alone, it's legit.

    You're welcome, and safe surfing :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds