Please review my logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by jtu50, Nov 8, 2008.

  1. jtu50

    jtu50 Private E-2

    Hello folks, attached are my logs from Mgtools, combofix, and Malwarebytes. Please review and let me know if this machine is clean. Thanks
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Were you able to run SUPERAntiSpyware? If so, please attach the log.
     
  3. jtu50

    jtu50 Private E-2

    here is my SAS log
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs are clean, run the below to perform some needed maintenance.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.


    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Please download, install and run CCleaner

    Step 4:
    Finally, I would like you to install the current version of Sun Java: Sun Java Runtime Environment

    Once you complete the below, reboot and let me know how things are running.
     
  5. jtu50

    jtu50 Private E-2

    Everything working fine. Thanks for your help
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you are not having any malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. jtu50

    jtu50 Private E-2

    I think I wrote prematurely that everything was working properly. When clicking on active links in an email I get a blank internet explorer screen. I use AVG free version for antivirus, it's link scanner seems not to be working, although the program indicates it is - no green checks next to site links, and lastly some attachments sent in emails won't open - I use Eudora as email client.
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs are clean so I don't believe your current problems are malware related. I would recommend the Software Forum for the issues you're experiencing now.
     
  9. jtu50

    jtu50 Private E-2

    Didn't have this problem prior to infection and removal. Could it be due to something done during disinfection?
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It wasn't something that occurred during the disinfection however it could have been something that got corrupted or something when the infection was present. It's hard to say how it happens but I will say I don't believe its malware causing it. Like I said before, I would post this in the Software Forum so they can help you from here.
     
  11. jtu50

    jtu50 Private E-2

    Still having issues. When clicking on some links I get an about blank window. This seems to happen from links in received emails, but not all links. For example I could reach Major Geeks from the link posted in a reply, but get a window labeled about blank when trying to access Kodak Gallery from an invitation sent to me. Any suggestions? As you indicated above, all logs are clean, so I'm at a loss.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    As stated previously, I would recommend the Software Forum. If you think you have been re-infected feel free to attach new logs for review.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds