Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by princesslisa, Mar 10, 2009.

  1. princesslisa

    princesslisa Private E-2

    I recently upgraded AVG free 8.0 to 8.5. I wasn't able to open IE7 so I did some checking and a device driver package from microsoft for network was installed so I did a system restore. Awhile back I decided to check out muvee producer 5.0 preinstalled on my system. I created a default or example set up in the program. I ran AVG scan before shutting down sys and it found and quarantined Backdoor.Prorat!ct. It caused muvee producer 5 to stop working. I uninstalled muvee and then used the HP recovery manager to reinstall muvee 5.0 and avg quarantined again. I emailed muvee producer maker and got an email back from them and a link to reinstall. The first instruction was to uninstall the old so I navigated to the programs and features to uninstall and got an error that installshield has stopped working. I restarted and tried again to no avail. I called HP and they told me to do a recovery which is a start over. Suggested may be virus so I decided to use your cleaning instructions. Oh, I forgot to mention I went to the hidden Installshield folder and found setup file. Double clicked and the install shield reinstalled HD audio driver, no error for the install shield. I ran all scans and came up clean. Superantispyware 0 infections. Malwarebytes, etc. I will attach the logs for all. Thanks
     

    Attached Files:

  2. princesslisa

    princesslisa Private E-2

    I found Revo Uninstaller and removed the old install of Muvee Producer 5.0. It is a great alternate option to windows uninstaller, it removes registry entries, files and folders. I really don't think that I am infected, I posted just to be almost positive.
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, princesslisa

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    *In the meantime - please attach the SAS log.

    Thanks for your patience.
    dr.m
     
  4. princesslisa

    princesslisa Private E-2

    Thanks for the reply. The AVG 8.5 problem with IE7 had to do with Vista's UAC and AVG. It has been corrected by AVG. Anyway, thank you and I will wait for your reply.
     

    Attached Files:

    Last edited: Mar 15, 2009
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, princesslisa


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up your Desktop immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.

    Question: Is your copy of Spyware Doctor a paid copy or a free trial?

    Step 2:
    Using Windows Explorer - navigate to and delete the following:
    Step 2:
    Run Ccleaner

    Step 3:
    Go to this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  6. princesslisa

    princesslisa Private E-2

    I followed the instructions in your post and deleted the files except for (C:\Users\Lisa\AppData\Local\Temp\~DFACBC.tmp), I couldnt locate it. Spyware Doctor is paid version. Here is the attached file.
     

    Attached Files:

  7. princesslisa

    princesslisa Private E-2

    Oh, I didn't have any errors or problems running or using MGTools. My computer seems to be fine. I will wait for a response. Thank You.:)
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're Welcome!

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    Last edited: Mar 18, 2009
  9. princesslisa

    princesslisa Private E-2

    Thank you so much for the help. So, did I have malware and if so, what was it? The files I deleted were those also malware?
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, princesslisa -

    You're most welcome!

    It was mostly junk temporary files.. but there was a suspect unknown with no info found on the entire net concerning it --- which usually means its malware.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds