..please tell me if I did right..

Discussion in 'Malware Help (A Specialist Will Reply)' started by rialyz, Mar 8, 2009.

  1. rialyz

    rialyz Private E-2

    ..and that I am clear of malware or something....I did not cheat but I scanned using malware bytes first instead of spybot S&D.. ..was trying to use spybot first but desktop keep getting "blue screen : driver irql not less or equal.. ..when I used malwarebytes before spybot, spybot was able to finish scanning..desktop was getting really slow, and then last January, I had to reboot the computer several times before I can get it to run properly.. ..I mean that it does not hang or stop when I open IE too early/ fast or sometimes too late....decided to try malware help....also, an avg update kept the avg program from running/ starting, so I downloaded your recommended PC Tools antivirus and used it instead....the blue screen is pretty recent, like just this week, after started using pc tools and registry mechanic I think..

    ..included is a log from spybot..

    ..please tell me if I still have deep problems with malware..
    ..thanks..
     

    Attached Files:

  2. rialyz

    rialyz Private E-2

    ..also, can't run firefox (might be a symptom)..

    ..again, I tried using spybot first, but only after I used malwarebytes instead that spybot was able to run and finish its scan..
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for you patience during this time.

    Kes
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) You still have AVG8 installed and running as well as PCTools AV. If you intend to stick with PCTools then please shut down and uninstall AVG8 now before we continue.

    2) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT


    4) Are you setting up to use this proxy?

    5) Now we need to use ComboFix

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DirLook::
    c:\program files\temp01
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    6) I would like to caution you about the use of such software as: Registry Mechanic 8.0 Software like this tends to be a little agressive and over ambitious, so you must take care when using it, I would advise that you use Ccleaner instead.

    7) Now goto this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    8) Run the new MGtools and attach the log it generates.

    9) Also attach the log from running ComboFix.

    10) Let me know how things are running now

    Thanks
    Kes
     
    Last edited: Mar 11, 2009
  5. rialyz

    rialyz Private E-2

    ..forgot about the avg.. ..been trying to remove it but I keep getting an Installer Initialization Failed error.. ..currently downloading new avg to try and uninstall with it..

    ..removed windows messenger..

    ..fixed O2 BHO no name..

    ..don't know anything about the proxy..

    ..actually uses CCleaner.. ..registry mechanic was installed by mistake..

    ..will get back with the logs after I have uninstalled avg..

    .thank you so much..
     
  6. rialyz

    rialyz Private E-2

    ..hello..
    ..only the combofix and mg right..?
    ..don't know anything about the proxy..
    ..able to finally uninstall old avg.. ..uninstalled PC Tools and using Avg 8.5 now..
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to stop putting all the .. in your messages! They are unnecessary and it is causing them to get trapped by our spam filters.
     
  8. rialyz

    rialyz Private E-2

    of course. a habit.
     
    Last edited by a moderator: Mar 14, 2009
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry :( Beacause the spam filter was catching that I missed your logs until now. I'll get straight to reviewing them and get back to you with a set of instructions as soon as possible.

    Thanks
    Kes
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac <--- fix this line too as long as you didn't set this proxy up yourself.

    After clicking Fix exit HJT

    2) Now we need to use ComboFix again,to restore a couple files and get rid of some leftovers.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat.vir
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat.vir
    
    Folder::
    C:\Program Files\Common Files\PC Tools
    c:\program files\temp01
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    3) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\Temp
    • C:\Documents and Settings\user\Local Settings\temp

    4) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    5) !! Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!!

    Thanks
    kestrel13!
     
  11. rialyz

    rialyz Private E-2

    definitely better.
    does not 'hang' anymore when I start this PC, and faster.

    attached files at requested! :)

    ran disk cleanup including temp files but when I checked folders you asked, files that were there can not be deleted, 'are in use'.

    able to run disk check for one of the drives, the other one is NTFS? will restart and get back with info.

    will try to run defrag too.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please use Windows Explorer to find and delete the below, as the software is not installed anymore, so let's tidy up:

    2) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3) And finally....

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. rialyz

    rialyz Private E-2

    wow. thanks!

    will try other desktops at home.

    seems we have something that creates *.exe folders but avg/ pc tools, super antispyware, spybot search & destroy and malawarebytes couldn't detect the problem.

    thank you again. til next time.!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome surf safely, and do begin new thread(s) for different computer(s)

    Take care :)
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds