Ran All Scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by mem0rex, Dec 21, 2009.

  1. mem0rex

    mem0rex Private E-2

    Well I ran all the scans and have all the logs. I just need someone to please review the logs to see if i'm clear.
    -Thanks
     

    Attached Files:

  2. mem0rex

    mem0rex Private E-2

    Ok, so here is what happened I woke up this morning and got on my computer. The cursor was constantly moving to the left. So if I highlighted an icon on my desktop it would highlight the one farthest to the left. If a alert message of any kind came up the button to the left would always be selected and the only way I could click anything else would be to click as fast as I could on the other button. If I opened firefox the blinking cursor be moving to to the left so fast that if I typed it would look like this: home page=http://www.google.com Now if I typed my name (Austin) very fast this is what would happen: http:/n/www.igotosgle.ucAom. This is so hard to explain. So I thought this might be some sick virus, so I came across this website and read the thread about how to scan. I followed every step and downloaded every program, and scanned. I compiled all the logs and uploaded them.

    The reason why I am posting again is because I thought this problem was over, so I started playing Quake 3 demo as I waited for someone to reply to my previous post. A couple seconds into the game my guy kept moving in a circle. It was doing it a again, So I rebooted and came back to this site luckily its not doing it right now so that I am able to post this.

    I have no Idea what this is, but my computer is completely unusable. I really need some help here.
    Please help asap.
    (BTW I do not think that the problem is cause be Quake because I have had and played that game every day for the past 4-5 months and I got it from Download.com)

    Thanks
    -Austin
     
  3. mem0rex

    mem0rex Private E-2

    Thanks for all the replies guys. To many to read. What a great site.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off, we work from oldest to newest. So your wait has been because you had not yet come up in our queue.

    The scans took care of any malware on your system. The only thing you need to do is to go to add/remove programs and uninstall your old java:
    Java(TM) SE Runtime Environment 6

    Reboot and then download and install:
    Java Runtime 6


    Now please go to C:\MGTools\analyse.exe and run it. Tell me what happens. If it runs, please attach the log.
     
    Last edited: Dec 24, 2009
  5. mem0rex

    mem0rex Private E-2

    Let just start off by apologizing I was really aggravated at the time and was angry posting. I did not realize that you started for oldest then to newest. It make since as to why you would do that. So I am sorry. Ok so I haven't updated me Java yet but I will, but I did runt the analyze.exe anf hijackthis came up, i don't know if that's what you wanted. I got a log file from Hijackthis. I will attach it.

    Thanks for all the help
    -Austin
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. :)

    The HJT log is good. No malware in it, I just wanted to make sure it could run as it was missing from the MGLogs.zip. We can clean up the left over junk that is not malware related and then give you the final clean up instructions.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    I would also suggest that you remove uTorrent from your start ups. You can use either of these to manage your start up programs:
    Startup Manager

    Startup_CPL

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. mem0rex

    mem0rex Private E-2

    Ok I uninstalled all the programs except the one you suggested I keep. Made the registry file and ran it, it was successful. And I disabled utorrent from the startup. I use AceUtilities and I ran all the little programs in that. I love that program. Well thanks for all the help man.

    I have one question though, what do you think the initial problem was? It was like someone was holding the left arrow key on my keyboard. Do you think that it was cause by the malware? Or maybe the batteries in my keyboard were going dead?

    Thanks so much
    -Austin
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you check your logs, you will see there was some malware removed by the scans. The keyboard issue may have just been a coincidence. Hard to say. And just because you used download.com, does not guarantee that it is free of malware. If you are playing online....then it is possible that your online account was hacked and you would need to change passwords ( preferably using a different computer).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds