"Read & Run Me First" but still have problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by talking777, Jun 14, 2010.

  1. talking777

    talking777 Private E-2

    Cleaning Computer of Viruses via Malware Removal Guide

    My Computer is: Dell Dimension 4600i Desktop 32 bit Windows XP SP3 (Home Edition)
    2.5 GB Ram 70 GB HD drive 3.00 Ghz Pentium

    Prior to 4/1/2009: I noticed there were times I could move the cursor with the mouse, but I could not click on anything. Then the screen would go black for a second or 2, and then the cursor would function again. At this time, I had an outdated Norton Anti-virus software and was trying to find something better. Your site helped with this!

    4/1/2009: My computer was hit by the April fool’s virus, and it was excruciatingly slow for approximately 4+ weeks. After trying to use it a number of times, I just stopped using it. At some point later in time with no help from me, I powered up the computer, and it just started working.

    During this time I researched how to clean my computer of viruses on the internet via public computers (the library) and attempted to clean my computer while it was slow. It didn’t seem to do much good. I found multiple sites/procedures for cleaning computers of malware. I attempted some of these procedures but they weren’t well explained. I finally found your site (MajorGeeks.com). The procedures seemed more understandable because it was stated in a more step-by-step manor. What I didn’t know how to do I could look it up on the net (e.g. how to get in and out of “Safe” and “Normal” modes.).

    I printed out all your guides/ procedures that related to malware/cleaning my computer since I couldn’t refer to them on line because the computer was so slow. I did part or all items in the procedures ( 6/2009 – I don’t remember now) but was not able to send off the malware logs due to extenuating circumstances. There were problems when I ran Combofix. The then malware guide did help me delete (via add/delete) a lot of malware.

    I did add the following anti-malware sw (all freeware) to my computer: (AVG AntiVirus, CCleaner, Spybot (with Teatimer turned off), Super Anti-Spyware, PC Tools Firewall) I did use Malwarebyte Anti-Malware (freeware). I don’t know if it continued to run after I used it once. I don’t know if AVG Anti-Virus also installed AVG Anti-Spyware as well.

    While running the anti-malware sw, I noticed some files scrolling by with the name Virtumonde ( possibly Spybot) though the results from some of the anti-malware sw came back “No infections”.

    6/2010: Recently, my email had been hacked – with everyone in the address book sent a blank email. I have since started the malware cleaning process again and have reprinted all your malware guides from MajorGeeks.

    I cannot uninstall McAfee Security Scan—even when logged in as Administrator.

    First and foremost, I very much appreciate that you have these guides available for all to use. They are a life saver!

    What follows are my notes/ some of my mistakes while trying to follow this/these procedures. Printing out all these procedures resulted in well over 100 pages to read/ keep track of. I felt more secure having it all on paper due to past computer problems.

    In the Windows XP Cleaning Procedure in the section (1) for downloading the Anti-Malware SW (Super-AntiSpyware, MalwareBytes Anti-Malware, and the rest— I only used the freeware versions of this software ), I downloaded the software someplace I could find them easily for installation. In Step 2 ( Installing and Running) even though I consider myself good at following directions, it appeared that I needed to reinstall/ move some files to the correct locations. So I moved/re-downloaded them at that time. MGTools download was deleted. I had to download that software again.

    AVG AntiVirus and PC Tools firewall were disabled prior to running Combofix. Teatimer on Spybot was already disabled. I did not disable SuperAntiSpyware (freeware) or any other sw. It appeared that AVG was doing a scan during the run of one of the AntiMalware SW even though it had been disabled. Is that supposed to happen??? Is that good to happen when running AntiMalware SW??? I don’t think I have AVG AntiSpyware. I think I’ve become the poster child of how to do this anti-malware procedure wrong.

    I have an external 250 GB hard drive (F-drive) that has been used to backup my current hard drive in the past and to backup a hard drive for an old computer. It has Norton AntiVirus files/ sw from a bygone time.

    Power was turned OFF on the F-drive while the Anti-Malware programs ran on my computer.

    RootRepeal was going on 10hrs+ when I stppped it. If appeared as if every file on the F-drive had an error status. The computer screen sometimes goes black after long periods of use which is why I stopped RootRepeal. I didn’t know where the log file would be stored and didn’t want it to be lost/non-existent. The scan on the F-drive appeared (to me) not useful since it appeared to list every file with a comment/error possibly due to the fact that the F-drive had the power OFF. I thought the <Save Report> function would be available for use once RootRepeal was stopped. Since it did not become available, I did a PrintScreen of what I thought was most important from the RootRepeal log file into a .doc file to send to you. It included all the C-drive comments/errors and a sample of the F-drive comments.

    I’m guessing the power probably should have been ON for the F-drive for the anti-malware sw??

    I continued on with the anti-malware sw with the power OFF on the F-drive for consistency.

    If I need to redo all the anti-malware scans with the F-drive powered on, please let me know.

    Through out the use to the anti-malware sw, the computer has been connected to the internet unless the sw itself disconnected the computer from the internet.

    I assume at the end of Step 3 of the Windows XP Cleaning Procedure, I should Enable the AntiVirus sw, the SW Firewall, the AntiSpyware SW, CD Emulation programs and hide unhidden files or should I leave it unprotected until I hear further notice from you??? I did Enable the disabled sw since I wanted use the computer before you got back to me.

    Can you tell me if any of the Anti-malware sw (software) (i.e. Spybot, Super-AntiSpyware, or others) resident on my computer ever get updated when the SW Firewall (PC Tools) is ON??? At this point, I only have freeware Anti-malware sw on my system.

    I know AVG AntiVirus will ask to be updated, and I’m guessing the SW Firewall (PC Tools) will update itself.

    After I stopped RootRepeal, I had to leave, and I shut the computer down.

    When I powered the computer back up,CHKDSK ran on F-drive. It looked like it was in SAFE mode, but later when I looked at it again, it looked like it was in NORMAL mode.

    I ran MGTool.exe. Messages flew across the screen. At one point, a statement came up that stated that if any key was pressed it would end the program ( I believe). The next statement stated “Press any key to continue “. I waited awhile expecting the program to continue. It did not. So I pressed a key, and the window closed. It appeared that MGTool had ended. The statements seemed contradictory, and I didn’t know what to do.

    I have several problems/ concerns:
    1. Is the April Fool’s virus gone or just laying dormant?
    2. How to fix the cursor problem ( it can move but does not always select until the screen goes black for a second or 2)? This is still a problem.
    3. How to remove the McAfee Security Scan? It probably came with Adobe Flash update which did not install at all. I have tried to remove it via Control Panel and the Start menu while in the Administrator account.
    4. Based on your guide How to Protect Yourself from Malware
    I will make the following changes hopefully soon:

    AVG AntiVirus to AntiVir Personal Edition (Is this a good to do?)
    PC Tools Firewall to Comodo Personal Firewall (without the antivirus)(Is this good todo?)
    Have CCleaner already
    Upgrade to the Paid SUPERAntiSpyware
    Have Spybot with TeaTimer disabled
    ADD SpyWare Blaster with all protection enabled

    5. How to remove Virtumonde if I have it? I do have popup blocker that shows itself at the top of a web page when a popup occurs.
    6. Should I rerun Windows XP Cleaning with F-drive Power ON?
    7. How to get rid of a 2 inch x 5 inch (approximate) popup(?) that appears in the lower right hand corner and has celebrity news on it? I’m sorry I did not note a name for it, and it has not appeared since the malware cleaning. So it may be gone.
    8. Yes, powering up is slow. I do not know which programs NOT to load at Startup.


    Sorry for being so verbose—just trying to be thorough – mistakes and all! Thank you for any and all help.
     
  2. talking777

    talking777 Private E-2

    The logs - the purpose for this post in the first place.

    There is a problem. For the Rootrepeal log, I couldn't cut and paste it to a .doc file. I had to do a print screen to a .doc file. The file is 374 KB which is larger than the 97 kb max for an attachment to this forum.

    I've tried copying it to a wordpad or notepad. It either did not work or the file size became even larger.

    Any suggestions?
     

    Attached Files:

  3. talking777

    talking777 Private E-2

    Rootrepeal log - I typed to a .txt the unique and the repetitive info from the .doc file. I'm sure the F-drive needs to be cleaned among other things.

    Thanking you in advance
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Now run the new C:\MGTools.exe and this time agree to the hijackthis license that you did not do last time. Attach the new C:\Mglogs.zip into your next reply as well as the log from running SUPERantispyware's newest version.
     
  5. talking777

    talking777 Private E-2

    Here are the 2 logs. Last time, I don't recall NOT agreeing to the license, and this time, I don't recall Agreeing to the license. So, I hope the MGTools ran correctly this time.

    At some point in the future, will I have to run these test with the F-drive powered ON?

    Thank you for all your help.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You do not boot from drive F so there is nothing to worry about. Only if a MBR infection shows up on the drive you boot from in a rootrepeal log does action need to be taken. So if one had been reported on the C drive then we would have to do something about it. Although worth bearing in mind you can always scan using malware bytes and superantispyware with the external connected.
    Not seeing any signs of it!

    avg 8.5 <--- Yes you will have to either upgrade or opt for something else to use for protection.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Try Revo to remove mcafee Security Scan.

    Then if remnants still exist:

    Reboot into safe mode to delete these from mcafee security scan.

    There is always the mcafee removal tool to consider but we will see if this has done the trick.

    Then reboot into normal mode again:

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Any other issues you have must be resolved in the software forum. We only have chance to deal with malware removal here and I am not seeing any malware in your logs.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. talking777

    talking777 Private E-2

    Thank you for all your help!

    Looks like Revo removed McAfee Security Scan.

    I still have the cursor problem/ the screen going black.

    I have some questions. I'm not trying to give anyone a hard time. I know how to use a computer, but not how to fix one. When I see contradictions I'm not sure what to do.

    [*]We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.

    1. The How to Protect Yourself from Malware guide says to use only one real time blocker. Is it ok to run both Superantispyware and malware bytes anti-malware (the paid versions of both ) long term?

    2. Do I have Virtumonde?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The free versions do not offer real time protection so you could have both installed, but with the paid for versions they DO provide RTP, so you would be better off just choosing one if you're going to purchase.

    No.
     
  9. talking777

    talking777 Private E-2

    Thank you for all your answers and help.

    I was guessing that there are no McAfee Security Scan remnants since the files and/or folders that would needed to be deleted in Safe mode were not there.

    I still have a problem...

    How do I fix the cursor problem ( it can move but does not always select until the screen goes black for a second or 2)?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have no idea sadly. This is something that will have to be discussed further in the software forum or hardware, wherever appropriate. :)
     
  11. talking777

    talking777 Private E-2

    Thank you for ALL your help. I also had an email virus(?) in my yahoo account which instigated this round of malware removal. Blank emails were sent out to everyone in my Contact list. Would that be something that is resident in my computer? Did this round of malware removal remove the email virus?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would say the best thing you could do would be to inport all your contacts addresses, create a new free yahoo email account and abandon the other.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds