Quick review

Discussion in 'Malware Help (A Specialist Will Reply)' started by Scott0, Apr 28, 2009.

  1. Scott0

    Scott0 Private E-2

    Geeksters,

    Need someone to view my logs before locking down the OPSys with Deep freeze and Superantispywear. Thought I had it all cleared up but a few strange things happened while updating windows to SP3. Made an image of the cleaned up XP on a external drive using Acroness. Made sure autoruns was shut down before doing this. Still I may have goofed somehow. The concern comes from trying to update the virus protection and nothing happened. Just a big freeze. It may have just been just a system glitch. SAS and MB seem to work now but would like to be sure before locking the OPSys in concrete with Deep Freeze. Did an Ok clean up so the logs look short.

    Thanks in advance:-o
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :p

    Back so soon, Scott0?

    *Checking your logs...
    dr.m
     
  3. Scott0

    Scott0 Private E-2

    Dr. M,

    So,So sorry. Thought I had things A OK on this machine. Lots more machines to check out but may have (user error) goofed on this one. Appreciate your time looking after a user like me. I await your analysis of my potential error. Hope I didn't goof up too much. Was hopping I could treat this like a "Blue Carbuncle". You know, just throw in a drew and forget it.


    Scott0
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get this PC properly protected and that is not what Deep Freeze will do. You still need an antivirus, realtime antispyware protection, and a real firewall which the Win XP firewall and Ashampoo FireWall Free are not. You need active protection during your current operating sessions to avoid problems that malware cause. You could windup infecting other PCs, or USB drives....etc.

    Do you know what the below file is? If not, I suggest that you delete it.
    Code:
    2008-10-27 01:19 10558 ----a-w c:\program files\Common Files\bepe.com
    Also delete the below folder
    c:\program files\Viewpoint


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Other than the above, everything looks fine.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. Scott0

    Scott0 Private E-2

    I did not know that the Ashampoo Firewall scored so low on the Matousec test. Thanks for the heads up. Looked at there most recent tests and it looks like Outpost Firewall will work just fine for this machine. Will use Avast for spywear and have purchased Superantispywear with lifetime updates for real-time malware protection.

    The regedit worked perfectly. Thought I had cut off auto run on this machine. So much for my thoroughness. Should I use the first line of the “stop auto run” registry edit on each users account or was that taken care of by just running it from the one account.


    I am 95% sure that a number of my thumb drives are infected. What I have been doing is putting them into a PC that has auto run cut off and reformatting the Thumb drive. In this fresh state I either download any programs I need (from reputable sights) and save it to the thumb or just remove a now clean reformatted thumb. Is there a flaw in this procedure?

    Deep Freeze is a part of locking down the machine. The users of this machine are not tech savvy and/or doesn't wants to learn. Routine maintenance is a four letter word to them. "Defrag? File clean up? Virus scans? Malwear scans? What's that and who has time anyway." Thus Deep Freeze.

    I will now start working on my Personal machines.

    Again Thanks for all the help,

    Scott0:)
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're welcome, Scott.

    "Best Of Luck!"
    dr.m
     
  7. Scott0

    Scott0 Private E-2

    Dr. M,

    :-o I forgot to ask one last question. I have read a lot regarding the Win32:Vitro virus . Almost all of the reports say that the only way to get rid of the virus is to nook and pave the HD. Is this true or can the Geek procedures get rid of this bug. The reason I ask is that if I run across this nasty little thing, I wouldn’t want to waist the valuable time of you guys/gals in the forum.

    Again thanks for all your help. Will be back soon.

    Scott0


    He has the power of observation and that of deduction. He is only wanting in knowledge, and that may come in time.........Sherlock Holmes
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool

    Hi, Scott0!

    Win32:Vitro is very nasty! This is a very dangerous file infector that uses advanced polymorphic virus techniques that are meant to destroy an Operational System utterly and beyond repair.
    The virus is just too destructive in such a completely random and buggy fashion that the infected files remain beyond repair and danger of re-infection is imminent from infected systems and peripherals. The only solution is to f-disk, format and re-install.

    * Please read our "boilerplate" response to its detection on a machine.

    ""It is of the highest importance in the art of detection to be able to recognize out of a number of facts which are incidental and which vital."

    http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  9. Scott0

    Scott0 Private E-2

    Dr. M
    Thank you so much for the info. Hope I never run into the aforementioned nasty thing. But one must have a plan of action just in case. Will be back soon for more knowledge and guidance.

    Scott0



    "It is my business to know what other people don’t know.".....SH
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're welcome, Scott.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds