Need help with Malware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Virtumondehatesme, Apr 4, 2010.

  1. Virtumondehatesme

    Virtumondehatesme Private E-2

    Now, before I start, I just want to say thank you to the incredible help from here, you helped me 2 times already, and I thank you a lot for it.

    Now, since last time I asked for help, everything was working fine up until my computer being completely obsolete. I bought myself a new computer, and my parents got themselves one too. However, after coming home, it seems that someone in my family downloaded Malware and it infected the whole computer. It was labeled as "Security Tool", and it could not be removed from the Add/Remove Programs (I had to find the location of the malware through safe mode and once I deleted it, the problems stoped).

    This computer did not have any protection previous as well, so I decided to go through all the checks in the READ ME FIRST post, as well as the Vista cleanup proceedure. My parents are planning to get proper security for their computer in a few days (as early as tomorrow), and I'll be sure to try and prevent my parents from downloading malware.

    I have followed the instructions, and have attached the following logs listed. I'm just very unsure if there is anymore to deal with before I can assume the computer is clean again. Thank you all for the help. :)
     

    Attached Files:

  2. Virtumondehatesme

    Virtumondehatesme Private E-2

    This is the last log. I just want to point out that I actually did ComboFix 2 times; I forgot the log the first time, and attempted it after the MGtools part.
    Thank you for the help once again, you guys rock! :D
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should know by now to put ComboFix directly on your desktop, not here;
    Running from: c:\fix\ComboFix.exe

    It appears as thought the scans took care of the malware, so there are only a few leftovers to remove;

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. Virtumondehatesme

    Virtumondehatesme Private E-2

    Well, my last problem was awhile ago, and I was in a rush myself since I have other stuff to do so I must have skipped that step.

    Thankfully, everything did work out, and the registry did merge (yes, I put it on the desktop like you said).

    I appreciate your help a lot, and once again, you saved another computer, so I thank you very much. I'll be sure to try my best and keep my family from downloading malware so this doesn't occur again.



    Also, as a side note, I'd like to know from you guys what the most suggested firewall and anti virus/spyware is? I remember when I had Norton Internet Security before, it definitely missed a lot of viruses/malware compared to some other programs. What do you suggest? (I am willing to purchase them)
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We don't recommend that you purchase anything. We also do not recommend using security suites as they often bog your system down. What we do recommend is on the link page for How to Protect yourself from malware. You just need to find one that works for you and make sure it is updated on a regular basis.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds