Malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by saltydog7seas, Aug 19, 2008.

  1. saltydog7seas

    saltydog7seas Private E-2

    I had malware and ran superantispyware, spybot, malwarebytes and Combo Fix. All of them found problems, what else do I need to do?
     
  2. saltydog7seas

    saltydog7seas Private E-2

    also ran MGtools
     
  3. Lev

    Lev MajorGeek

    Post up the logs as an attachment as requested in the Read and Run Me First link. You will need to make two new posts to do this as you can only attach 3 logs to one post.



    READ & RUN ME FIRST. Malware Removal Guide

     
  4. saltydog7seas

    saltydog7seas Private E-2

    Here are the first three.
     

    Attached Files:

  5. saltydog7seas

    saltydog7seas Private E-2

    And here is the other one.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. You just need to do the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now if you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. saltydog7seas

    saltydog7seas Private E-2

    I did receive a successful message.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! Then make sure you finish all the other steps if you have not already done so.
     
  9. saltydog7seas

    saltydog7seas Private E-2

    Already done, thank you for all of the help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  11. saltydog7seas

    saltydog7seas Private E-2

    Actually I'm not sure if this is related but I have just started not being able to use the keyboard when the computer strats up. I have to reboot it a couple times. I was told to type REGSVR32 /i MSHTML.DLL under run, but I get an error saying MSHTML.DLL was loaded but the DLL.RegisterServer entry point was not found MSHTML.DLL does not appear to be a .DLL or .OCX file. Any suggestions?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the Software or Hardware Forum. Also find out and post in one of those forums whether the problem also occurs in safe boot mode. Also if this is a special keyboard that requires drivers, reload the drivers.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds