Read & Run Logs. Thank you

Discussion in 'Malware Help (A Specialist Will Reply)' started by justpk, Mar 25, 2009.

  1. justpk

    justpk Private E-2

    Thank you in advance for your time.* While running the Combofix, the computer shut down and restarted then the Combofix continued,* I couldn't disable McAfee.* I hope is didnt mess up my logs. There are 4 user accounts, do I have to run each procedure on each user account?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally the answered would be yes especially if they are having problems. But you must work on one user account at a time to avoid confusion in the thread.



    One of the very first instruction is the READ & RUN ME state the below
    You appear to have ignored this. You have both of the below installed.

    McAfee SecurityCenter

    Norton Internet Security
    You must uninstall one of these immediately before doing anything else. Odds are now with both installed you may have problems getting either to uninstall properly so you will need to run one of the below too based on which you chose to uninstall:

    Norton Removal Tool (SymNRT)

    McAfee Consumer Product Removal Tool


    Also in the future, please only run the scans once and then attach the logs as requested. Your logs show that you ran SUPERAntiSpyware on March 23, March 24, and March 25 for the current user account.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 1, 2009
  3. justpk

    justpk Private E-2



    When I clicked on the above link it says address not found. Here are the combo logs. I am sorry for not following exactly.

    Can I disable all the user accounts so I don't have to run these procedures 4 different times?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I fixed it so please try it now.

    Do you need these user accounts? Will you ever use them again? If you don't clean them, and they have infections, they could potentially cause problems for everyone. If you don't need the user accounts, DELETE them and make sure you have it remove all files and folder for the user accounts during the deletion.
     
  5. justpk

    justpk Private E-2

    I deleted all other user accounts along with their files. Here is the mg logs.

    Since I deleted those accounts is there any other scans I need to do?

    I haven't been using this computer, because I was waiting till we were done with the stuff you need done.


    Thanks you for all your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We still have a little more to do.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKUS\S-1-5-21-3861678527-2731200870-2866809866-1007\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe (User '?')

    After clicking Fix, exit HJT.

    Now we need to use ComboFix again. When you run this, you may get a message about ComboFix being expired or out of date. Make sure you say yes to installing the new version.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. justpk

    justpk Private E-2

    I could not locate this file in the MGtools analyse.exe I read each one that was listed and did not find that particular one.

    Everything seems to be ok. What would you suggest doing to test certain things that would trigger problems still there?
     

    Attached Files:

    Last edited by a moderator: Apr 9, 2009
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run your PC however your normally run it. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. justpk

    justpk Private E-2

    Thank you so much for your help.
     
  10. justpk

    justpk Private E-2

    I'm so sorry, but, after completing the final steps, I ran a scan with Malware bytes, it found 11 infections, log below. I also ran it in safe mode, but only under adm and it still found 11 infections. Thanx
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is new:

    C:\ProgramData\RD Platinum v5.0

    Have you installed or downloaded anything new?

    Download the current version of combofix.exe and save it to your Desktop but DO NOT run it yet.

    Now run this Resetting Registry and File Permissions and make sure you reboot where requested.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!


    Now run another scan with Malwarebytes but make sure you update it before scanning. If it tells you it needs to reboot, make sure you immediately reboo.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the new Malwarebytes log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. justpk

    justpk Private E-2

    I have not installed any new programs.

    Here are the new logs. Thank you again.

    I think things are working ok. I will check around and let you know.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other problems, repeat my final instructions from msg # 8.
     
  14. justpk

    justpk Private E-2

    Thank you soooo much for all your help. You're an angel.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds