Ran Read Me and still having malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by vlashka, Dec 19, 2008.

  1. vlashka

    vlashka Private E-2

    A couple of days ago my computer started acting weird. All the icons and the start menu will disappear every 10 seconds and appear again after around 10 seconds. I noticed that I have forgotten to activate the antivirus program. I ran it and I found that I had a few Trojan horses. The antivirus program could not fix the problem so I ran the malware removal guide that you have here. The tools that you recommended discovered even more viruses and spyware. My computer started acting normally again but my husband ran some of these tools again today and they were still finding Trojan horses. It seems like we were not able to get rid of all the viruses. I have attached the logs that you requesed.

    We would really appreciate it if you would help us fix our computer as we are both not very good with computers. Thank you very much for your help in advance!

    Dilyana and Harry
     

    Attached Files:

  2. vlashka

    vlashka Private E-2

    Attached is the log from MGTools.

    Thank you again!!!
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    Thanks for your patience
    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is out that should help with some of your problems. Please uninstall your current version (this is necessary). Then download this SUPERAntiSpyware Install and update the database during installation. Then run a new full scan of your system. And attach this log later.

    1) Please go to Add or Remove programs and uninstall the following softwares:

    • J2SE Runtime Environment 5.0 Update 4
    • Java(TM) 6 Update 7
    2) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O15 - Trusted Zone: *.antimalwareguard.com
    O15 - Trusted Zone: *.antispyexpert.com
    O15 - Trusted Zone: *.gomyhit.com
    O15 - Trusted Zone: *.imageservr.com
    O15 - Trusted Zone: *.spyguardpro.com
    O15 - Trusted Zone: *.storageguardsoft.com
    O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
    O15 - Trusted Zone: *.antispyexpert.com (HKLM)
    O15 - Trusted Zone: *.gomyhit.com (HKLM)
    O15 - Trusted Zone: *.imageservr.com (HKLM)
    O15 - Trusted Zone: *.spyguardpro.com (HKLM)
    O15 - Trusted Zone: *.storageguardsoft.com (HKLM)


    After clicking Fix exit HJT.

    3) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
     
     
    KILLALL::
     
     
    File::
    C:\WINDOWS\_delis32.ini
     
     
     
     
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4) Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime


    5) Now Run Ccleaner!

    6) Now we need to make sure that your system is really clean. Please run the new version SUPERantispyware again and also attach this second log so we can compare to the first.


    7) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the below new logs:

    • the two new SUPERAntiSpyware logs
    • C:\combofix.txt
    • C:\MGlogs.zip
    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited by a moderator: Dec 22, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds