Okay, now what...

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimmyz, Feb 21, 2011.

  1. jimmyz

    jimmyz Private E-2

    We believe we have the Windows Security Tools virus. I went to a previous thread and read what he was asked to do. I followed the instructions for removing malware. I did all the initial things before starting to download anything as suggested. I downloaded CCleaner, SuperAntispyware, Malwarebytes Anti-malware, and MG Tools. I then ran them each as requested. These malware tools found many viruses. I only hope they removed the main one!

    Now I am supposed to attach the logs to a post, correct? Please verify as I do not want to mess anything up!

    Thank you!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. jimmyz

    jimmyz Private E-2

    Hope this works!:) I was able to attach the MGTools file and the malwarebytes log. However, when I proceeded to try to obtain the file from Super Anti- Spyware, it asked me to "run" it again and said it would have to uninstall what was already there to run again. I do not get how to pull the log .
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\Jerry\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 02-21-2011 - 21-03-49.log There it is.

    Also why did you not run Combofix? Can you do so and attach the log? C:\combofix.txt.
     
  5. jimmyz

    jimmyz Private E-2

    Thank you. I thought I had run Combo Fix. I shall do so now and add both logs on next post.
     
  6. jimmyz

    jimmyz Private E-2

    One More Try...
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put ComboFix directly on your desktop. Not here:
    c:\documents and settings\Jerry\My Documents\Downloads\ComboFix.exe

    Your logs are clean. It appears that the scans took care of the malware.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  8. jimmyz

    jimmyz Private E-2

    Man, I feel so dumb. Anyway, I assumed it did download it to my desktop. However, that's probably why I "forgot" to originally run it because I did not see it there.

    Anyway, I re-installed this to my desktop, BUT now when I go to uninstall it, I get this message "Windows cannot find the C:|Documents. Make sure you typed it correctly and then try again." I am not in this location. Any ideas?

    I apologize for being a nuisance!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you redownload it to your desktop or did you simple slide it out of this folder --> c:\documents and settings\Jerry\ onto your desktop? If you downloaded it again, the script:
    "%userprofile%\Desktop\combofix" /uninstall would have removed the one on your desktop. But you would need to run this script to remove it from the c:\documents and settings\Jerry\ location:
    c:\documents and settings\Jerry\My Documents\Downloads\ComboFix.exe /uninstall
     
  10. jimmyz

    jimmyz Private E-2

    Okay! Now that is settled, I'll be doing all the other steps! Thanks so much for your help. So far I have not had any more strange pop-ups since the removal.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds