sys. restore to get rid of virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by texasharper, Mar 21, 2008.

  1. texasharper

    texasharper Corporal

    Can I use system restore to get rid of virus?
     
  2. Lev

    Lev MajorGeek

  3. texasharper

    texasharper Corporal

    Thank you, Lev for your reply. I have started the process. Currently downloading the most recent version of Java.

    There was a link under a message from Chaslang stating that all messenger plus should be deleted. I went there and it was a scan that said I had like 78 infections. 2 with cookies, 1 trojan, Keyloggers, zango, and wildtangent.

    MSConfig, confuses me, I thought my system should always start in normal mode. Is this correct?

    How do I know if MSConfig is being used to control system start-ups?
     
  4. texasharper

    texasharper Corporal

    How do I delete all my quarantined files in my anti-virus? I have Avast.

    Also, there is a decompression bomb in my quarantined files!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask you to install anything from that link. It was for informational purposed. It you installed things from them, just uninstall them now as you don' need them.


    Yes, just select Normal Startup and remain in that mode.

    If you run it and it is not showing you to be in Normal Startup mode, then you are using MSconfig.

    Don't worry about this. Just complete the READ ME. But there should be an option in the program, otherwise you can just manually delete any files in the quarantine.
     
  6. texasharper

    texasharper Corporal

    Status now installing spybot, however I get an error message saying "error sending request". The server name or address could not be resolved. Retry or cancel. In the setup wizard in select destination location, I installed it to c:\new folder\spybot search and destroy. I unchecked teatimer.

    My question is:

    1) How do I resolve the error
    2) Does my internet need to be disconnected through all four scans
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then uninstall it it and delete that folder. You should always install programs to their suggested default folder which is normally under C:\Program Files. For Spybot it would beC:\Program Files\Spybot - Search & Destroy



    Not sure! Is this during the installation or while trying to get updates. If you continue to have issues with Spybot then skip Spybot.

    No! If we don't ask you to do it, don't do it. Just follow our instructions as written.
     
  8. texasharper

    texasharper Corporal

    I already had spybot installed on my computer, I uninstalled it because I didn't know if it was from the Mayor Geeks link. So, therefore, I downloaded again, saved it to program files and upon installation directed it to the c:\program files and got the error this sending request "The server name or address could not be resolved".

    I'm going to skip spybot. I ran spybot just before I started my thread.

    Started the instructions on combo Six. I printed all the instructions. That's what I'm working off of. I downloaded combo Six.exe to program files and there was no desktop icon. I selected combo Six in program files, right clicked to rename to cf.exe. Then I went to run and typed in the path exactly as written per instructions and got this error. Windows cannot find "C:\Documents and Settings\userprofile\desktop\cf.exe"/killall.

    The rest of the error said make sure you typed the name correctly and try again.
     
  9. texasharper

    texasharper Corporal

    Sorry, I meant ComboFix not Six, Duh!! Here are my logs.

    I am grateful to all of MajorGeek's Geeks!!!! Saying I would be lost without you guys is NOT an understatement!! ....ok, am I starting to sound sycophantic? = )
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix.exe which is renamed as cf.exe must be saved to your Desktop not to the C:\ root folder. You will not be able to run our procedures until you put the cf.exe file where the READ ME asked you to put it which is on your Desktop.

    Also based on your previous messages, if you are Downloading files to your C:\Program Files folder, you need to stop downloading them there. The C:\Program Files folder should not be use like that. This folder should only contain installed programs.

    However after saying all of the above, I continued on to look thru all of your logs. While I do see a few things that should be addressed, they have nothing to do with malware. What malware problems are you having as I do not see any?


    Here are the non-malare fixes I suggest that you do.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 23, 2008
  11. texasharper

    texasharper Corporal

    Life has been coming at me fast the last couple of days!!! Thank you for your assistance. I'll get on that right away!!
     
  12. texasharper

    texasharper Corporal

    Chaslang, how do I remove all the stuff I put in the program files folder?
     
  13. texasharper

    texasharper Corporal

    Ran MGtools, however, I did not see any of the things you mentioned, such as a system scan only option or a fix button I could click. I see the program was written by you and it is a black background with white letters. Is that where I am supposed to be? Combofix and MGTools I right clicked on, and sent them to the desktop. Is that the correct way to do it?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not say run MGtools! I said run C:\MGtools\analyse.exe

    analyse.exe is an executable program file inside of the MGtools folder on your C drive.


    By deleting them using Windows Explorer. Make sure that you don't delete the installation folders for programs. Only delete what ever files you mistakenly downloaded into the C:\Program Files which I assume was the ComboFix.exe file.
     
  15. texasharper

    texasharper Corporal

    Do you need a new Combofix log?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No we don't need one. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter cmd and click OK to open a command prompt
      • Type cd Desktop at the command prompt and hit enter.
      • The prompt should change to show you are on at your Desktop folder now.
      • Now type cf /u and hit the enter key which should run ComboFix's uninstaller.
        • Note: The space between the cf and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds