marus new thread

Discussion in 'Malware Help (A Specialist Will Reply)' started by marus, Aug 23, 2010.

  1. marus

    marus Private E-2

    Hi Kestrel 13,

    I think I have attached all the needed files, but, would not be surprised if I missed one. @ this point I am looking forward to hearing from you again.

    Always Thank you!

    M
     

    Attached Files:

  2. marus

    marus Private E-2

    Re: .Net issue on XP

    Hi Kestrel 13,

    No a big deal easy enough to start another thread.. Do please say the final word.

    Attached is the MGlogs zip file. I reran it again as well as the Super Anti Spyware as well the Malware which both found at least one hit; because again I tried to clean my back-up hard drive with the Super Anti Spyware and after finding a few contaminations the whole system just shut down (turned off). This computer is in a cycle that has to be broken via another direction first, or toss my external hard drive. If you think it wise I can also rerun the rootrepeal and combo-fix.

    Thank you,

    M
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Done ;)

    Will review your logs ASAP, but right now I'm hungry so going to eat. :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, I am not seeing any malware in the combofix log or in any of the logs contained within the mglogs.zip file.

    Try this:

    For the external Hard Drive and a USB stick.

    Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
  5. marus

    marus Private E-2

    Hi Kestrel 13,

    It seems to have worked out very nicely. I my fear/s after using the 'Flashdisinfector' I reran both the Anti-malware and Super-AntiSpyware tools with on reboot while running the Super AntiSpyware midstream. Restarted and got an all clear. Then proceeded on to the external hard drive and found nothing of concern using those two tools. Hooray for me, you are a Goddess :) !

    So now I guess itis time to put things back together unless you think it wise to re-run any tool on either drive?

    I'd like to have your further instructions at your convenience..

    Thank you again, as always I am grateful.

    M
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sounds like you're all set. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. marus

    marus Private E-2

    Hello Kestrel 13,

    I thought I did it correctly, but alas not out of the woods yet. :(

    Put back in COMODO got updated info. started running scan and of course the eyetem shut down again.

    Takes half hour to boot up so far 10 instance of svchost.exe running in task manager cpu stuck at 100% 2 instances of atievxx.exe running. I understand both are normal drivers.. Normally 52 or 53 processes running now only 39 and going no where.

    Did a hard reboot and system restarted almost normal.

    Same occurred again when tryin to run Super-AntiSpyware.

    So close yet so far!

    Not sure where I went wrong, Scratching my head here, close to bleeding :)

    Bummer,

    M
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmmm not sure whether this is a malware issue or not but please run combofix and then MGTools and attach logs from each. If they come out clean, then you will have to visit the software forum for further assistance.
     
  9. marus

    marus Private E-2

    Heya Kestrel 13,

    Thought I'd let you know that the ole computer seems to have settled down. I at some point started the COMODO in paraniod mode and it found an regedit file which it stopped. Since then things have been much more stable. Back off the peranoid and run several cleaning/s once a day and only now catching a few adwares from the typical sites like msnbc etc.

    Starting to try to patch back my lost gaps of data. Don't know if it's worth going another round with inspections for deeper issues or not. Still has issues but not sure where to look or how they are related beyond the common start of this whole process.

    You had also mentioned possibly removing old updates of the JAVA some other way as the program removal icon was ineffectual on those updates as well as other programs.

    Anyway, thought you'd be curious to hear. Thanks for your help! and good thoughts.

    M
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for letting me know. Yes, do visit the software forum for any further assistance with any remaining issues. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds