Still not sure of Malware removal with XP Pro

Discussion in 'Malware Help (A Specialist Will Reply)' started by S14, Feb 12, 2014.

  1. S14

    S14 Private E-2

    Hi Geeks!

    I have been trying to resolve several issues which began with slow downloading and Google redirect issues in Firefox; Office 10.(XP Pro) Excel which returns "Microsoft Visual C++ Runtime Library runtime Error" C:\Program Files\Microsoft Office\Office 10\Excel.exe Among others.

    I followed your extensive pages on Malware running all on the "Read and Run" page and logging as directed. I did follow the pages on Google Redirection removal, and i surmise that has solved that problem.

    I am not sure that I have removed all the malware, as in some places you recommend that I NOT clean the malware, just send the logs....but figure I cannot repair the Excel or other problems without first being sure that I have removed the threats.

    Will you please review the log files and / or direct me to the next steps?

    I have used the Belarc advisor should you need that detail too.

    Kind Regards


    XP Pro w/MS updates
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun MBAM and have it fix what it found.

    Then rerun Hitman and have it remove all the:
    Potential Unwanted Programs

    Finally, rerun RogueKiller and have it remove:
    Code:
    [RUN][SUSP PATH] HKLM\[...]\Run : shicoxp (C:\WINDOWS\shicoxp.exe [-]) -> FOUND
    Reboot and rerun both RogueKiller and Hitman and attach both those logs.

    Let me know how things are runnning.
     
  3. S14

    S14 Private E-2

    Hi;

    I followed your proceedures and have the logs attached.

    From the reading I, I believe that I must now toggle system restore; and delete any backups on my NAS, then create a new backup before continuing to solve my other problems?

    Thank you!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your RogueKiller log is clean but you did not remove the PUP's in Hitman.
     
  5. S14

    S14 Private E-2

    Thanks for your prompt reply.

    I believe I got the PuPs, but have no idea what the "Conduit" and "Rocketfuel" programs are.

    Rocketfuel seems to be a part of "conduit" having to do with Facebook.

    I don't do Facebook.

    Conduit shows up in Program files as C:\program files\conduit\community alerts\alert.dll and also as shown in the log.

    Rocketfuel? Not in Program files

    I don't recall installing them.

    I would prefer to delete them if they are not needed, but they do not show up in "add and remove programs".

    Recommendations?

    Thanks!

    Kind Regards
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now reboot and rescan with Hitman and attach the new log.
     
  7. S14

    S14 Private E-2

    Done!

    Thank you and Kind Regards,

    S14
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can remove that one last PUP in Hitman.
     
  9. S14

    S14 Private E-2

    I think I got it.

    -Best

    S14
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. S14

    S14 Private E-2

    Hi Geeks;

    I had to be away for a while, but finished the recommendations from your last post. When I went to copy some files to the CD (Sony CRX-145E)and DVD (Plextor PX-755SA)drives, I received the message / Error:

    D:\ is not accessible. Incorrect function

    The drives will read a disc with files on it, but not able to drop files into the open empty window nor write to a blank disc.

    I remembered using Defogger and re-enabled via that program again to no avail.

    I checked the device manager, both "working properly" in the General tab.
    Plextor:
    Driver date 7/1/2001. Ver: 5.1.2535.0 (Microsoft)

    Sony:
    Driver date 7/1/2001. Ver: 5.1.2535.0 (Microsoft)

    But didn't venture beyond that as I didn't want to mess up anything that Defogger may have done.

    Suggestions?

    Kind Regards,

    S14
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The issues you are having are not malware, so I suggest you post in the software forum for further assistance.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds