Old Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Captain Drift, Sep 19, 2008.

  1. Captain Drift

    Captain Drift Corporal

    Hello All,

    I am having an issue with a friend or a friends PC.
    Bought about 5 years ago and never been on to Windows updates, never had anti-spyware installed or removed, only had norton anti-virus.

    currently from switch on to desktop is 3-5 minutes.
    I have tried running through the XP cleaning thread, this was an excellent help but had a few problems.

    I have run Ccleaner (new version with updates), removed 4gig from PC Spybot S&D (with updates) and removed 50 items.
    I have run a quick Malwarebytes scan and removed another 11 items, but a full scan freezes, Combo fix wont run, it freezes.

    Can I run Combo fix in safe mode? If i run MB in safe mode a full scan takes 1 minute and does not find anything.

    Or should I remove the internal drive, connect it to a laptop and scan it as a removable drive?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Captain Drift

    Captain Drift Corporal

    Thank you for the help.
    I have found the problem.
    The Northbridge heat sink had come off the board, so will have to re-attach and test. Although I still managed to half the boot time and get it running to a slow but stable standard.
    Only found this out when deciding to connect the drive to another PC and scan it that way.
    Thanks again for the help
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...that could do it. Good luck and safe surfing. :)
     
  5. Captain Drift

    Captain Drift Corporal

    I have tested the PC and the start up is really slow and windows crashes very easily.
    I will run the XP cleaning tonight and attach the logs
     
  6. Captain Drift

    Captain Drift Corporal

    Hello TimW

    I have followed the guides with a few issues.
    Downloaded new sun Java Version 6 Update 7 in safe mode. rebooted into normal mode and i am unable to uninstall the old version, the windows installer freezes.

    I un-installed a few items from the add/remove programs, I am unable to get rid of Norton as that freezes during installation.
    All the other parts worked well, most were run in Safe mode.

    Cleaning XP
    1. I am unable to install SAS this freezes during installation.
    2. Spybot S&D i removed 45 items
    3. Malwarebytes Anti-malware- Full scan would freeze after 3 miuntes in normal mode, it would freeze while scanning AOL files or c:\windows\system\sound.drv.
    3. Combofix - This wouldn't run as the PC is running XP Home SP 1a, i cannot open Internet Explorer in normal mode to update to SP2
    4. MGtools- In normal mode this froze on the TrenMicro Hijack This Accept/Decline screen. I ran this in safe mode log attached.

    I haven't attempted the System restore yet just in case.

    Should I cut my losses and format and re-install or do you think with your help it can be resolved?
     

    Attached Files:

  7. Captain Drift

    Captain Drift Corporal

    Going through the log myself with the help of the excellent guide on understanding the log.
    Most of the stuff in hijackthis is rubbish.
    How can i get Hijack this to fix issues?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...now the next thing you need to do is run the Norton Removal Tool

    Also uninstall:
    Viewpoint Media Player

    Now tell me what these are:
    C:\Documents and Settings\Chris.MAIN-PC\Desktop\sepexamempty.exe
    C:\Documents and Settings\Chris.MAIN-PC\Desktop\March2007.exe
    C:\Documents and Settings\Chris.MAIN-PC\Desktop\March+2008.exe

    If you don't know, then delete them.
     
  9. Captain Drift

    Captain Drift Corporal

    sepexamempty.exe and march2007 and march+2008 are part of a BA training program.
    Will run the tool and let you know

    Thank you for the help
     
    Last edited: Sep 25, 2008
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can remove these from your start up:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let me know how the Norton tool did.
     
  11. Captain Drift

    Captain Drift Corporal

    TimW you are a genious!!!

    The PC is working great.
    The latest update
    I ran the Norton removal Tool, took about 30 mins.
    Then removed View point media player.
    Updated Java from V5 update 3 to V6 update 7
    I then managed to install SAS and ran a full scan (log below) and it still found things
    Then ran Spybot S&D and removed 1 more item, had to restart and this autoran before I logged on. This took about 40 minutes.
    Malwarebytes Anti Malware - Full scan nothing found (log below)
    Comofix- Still on SP1a so not run.
    MGTools- ran (log below)

    Once again Thank you very much for the help

    If all clear will install SP2 and SP3 tonight
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    If you are not having any other malware problems, it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:

     
  13. Captain Drift

    Captain Drift Corporal

    Thsnk you once again the PC is running great guns now.
    I will spend tonight instaling all the windows updates
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds