Read & Run Me Scan Results

Discussion in 'Malware Help (A Specialist Will Reply)' started by ninjagaiden, Jul 2, 2008.

  1. ninjagaiden

    ninjagaiden Private E-2

    Hi,

    I've gone through the Read & Run Me procedure and I think the scans found and got rid of a bunch of thing. You may have noticed posts from me earlier, but they were for a different machine. I think the Mbam program may not have been able to remove everything it found. There is a screen shot of the MBAM screen just before reboot. I think only the SuperAntiSpyware log came out clean. Also, for some reason, Combofix wouldn't run on my machine as cf.exe so I named it cfe.exe. I posted immediately afterwards because I had more than 3 attachments.
     

    Attached Files:

  2. ninjagaiden

    ninjagaiden Private E-2

    Here is the MBAM screen shot.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean.
    Did you note that the MWB message said the items will be removed when you reboot?

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (substitute for cf whatever you renamed it)
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  4. ninjagaiden

    ninjagaiden Private E-2

    Hi,

    I got stuck on Step 6 of your instructions. Only Read Me file I could find in my Windows folder was in C:\WINDOWS\Help\SBSI\Training\WXPPer, and it doesn't contain a System Restore section.

    Events leading up to me using READ & RUN ME procedure:
    About 3 weeks ago my computer crashed after downloading an alleged Active X update. It would crash about 2 minutes after logging in. In Safe Mode it would last a little longer but I would still et a blue screen. I tried using several system retore points but that didn't work either. I got some advice from techspot that got me up and running again, but Symantec would find trojans or other viruses every few hours and notify me of their deletion so I ran the RUN and READ ME procedure. Also, I noticed that my System Restore didn't seem to work anymore. There is a link to It under Start > All Programs > Accessories > System Tools, but in the screen shot you can see the link has a generic, unrecognized program icon and the link goes no where. How can I fix this?

    Separate topic: Antivirus Question:
    In the "How to protect yourself from Malware" guide at http://forums.majorgeeks.com/showthread.php?t=44525 It says that most of the free Anitvirus software is better because it is not as resource hungry as Norton/Symantec or McAfee. Are these free software packages as effective as Norton or McAfee though?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Step 6 refers to the Read and RUn Instructions regarding how to toggle system restore.

    Restore System restore
    No antivirus is 100% ....but the free ones do just as good a job as the bloated suites.
     
  6. ninjagaiden

    ninjagaiden Private E-2

    Hi,

    Sorry it took me so long to reply, I was out of town. When doing the sr.inf install, the machine asks me to insert my Windows XP Home Edition Service Pack 2 CD, but I only have a Service Pack 1a CD that came with the computer. I think I later downloaded SP 2. Is it possible to get a CD with SP 2 for free or can I just download SP 2 from the Microsoft web site?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can download SP2 from the internet or MS update site.

    The instructions to restore system restore, can be done without the cd...just move to the numbered instructions.
     
  8. ninjagaiden

    ninjagaiden Private E-2

    Sorry,

    I don't understand what you mean or where to go. Here is a screen shot of where I get stuck. XP Service Pack 2 is already installed on my machine, but the computer asks for the service pack 2 CD in order to retrieve the sr.sys files like you mentioned. I down loaded Service pack 2 from the MS website and looked through all the documentation, but I did not find the sr.sys file. I don't see how to install system restore from your numbered steps in your posts on 07-04-08 13:12 or on 07-03-08 10:13. Did you mean a different set of numbered instructions?
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are trying to install sr.sys not sr.inf --->
     
  10. ninjagaiden

    ninjagaiden Private E-2

    I had right-clicked on the sr.inf file and chose install, but I think the problem is that when I try to install sr.inf, it needs the sr.sys file from the XP Home Edition Service Pack 2 CD which I don't have. My machine has SP 2 installed, but the CD that came with my machine is older and only has SP 1a. Can I maybe get the sr.sys file by reinstalling SP 2? Or, I found a file on my SP 1a disk called SR.SY_ (underscore is part of the name). Should I use this? Sorry about the confusion
     
    Last edited: Jul 22, 2008
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds