May still have malware/virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by dark fenix, Oct 7, 2008.

  1. dark fenix

    dark fenix Private E-2

    While using the computer today, all of a sudden, the date and time got messed up. The date turned to, can't remember the actual date, sometime in the year 1999. And the time was all screwed up too, I think it went to like 3 am or something. This all happened automatically, so I ran Nortan AntiVirus Corporate Edition and found 4 virus, which was quarantined and deleted.

    I also ran Ad-Aware and found like 5 malwares, which I deleted.

    Also, on a side note, I was not able to set the option on seeing hidden and protected files. Everytime I change the settings for it, it would always automatically return to not being able to see it... Ok, scratch that. After doing the steps, I am now able to see hidden files.

    I did all the steps and deleted some stuff, but I have a feeling there are still some stuff remaining. So I want to make sure that my comp is clean. Thanks
     

    Attached Files:

  2. dark fenix

    dark fenix Private E-2

    Here's the rest of the attachments.

    O yeah, I had an error running MGtools.

    I was missing a .NET file I think, but none of the errors matched what I had.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. dark fenix

    dark fenix Private E-2

    Hello chaslang,

    I've done the combofix. It seems it went smoothly.

    The registry fix worked properly.

    MGTools gave me an error again. It was a .NET Framework Initilization Error? I think I was missing a .dll again or something.

    O, and another thing, do I have kazaa in my computer?

    Is my computer clean or still needs work?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we are just cleaning up some items mistakenly added by ComboFix.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. dark fenix

    dark fenix Private E-2

    Oh, ok. That's good to hear! :]

    but i have a question. Is there a reason why I should remove hijackthis?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a tool you should use on your own and you always need to use the current version. In addition it is embedded into the MGtools folder (at least the one that we have you use), thus removing MGtools will remove HJT too. And while you don't really need to remove MGtools, if you do not, when/if you have malware again, you will be tempted to use MGtools tha you have and it will be out of date. It already is 2 versions behind even right now. Current versions of all tools must always be used.
     
  8. dark fenix

    dark fenix Private E-2

    ah, ok. I get you.

    well, thanks for your help again. It was much appreciated.

    Have a good day! :]
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds