The straw that broke the camels back

Discussion in 'Malware Help (A Specialist Will Reply)' started by stevejouanny, Aug 18, 2009.

  1. stevejouanny

    stevejouanny Private E-2

    Some months ago I wrote to you all and discovered my friends computer had flec006. Through your assistance I managed to completely rid his computer of it!

    He has procured another piece of malware which has been doing the following to his computer:

    - Coming up with Google Installer 'error' messages saying that it has encountered a problem needs to shutdown
    - General slow performance on PC
    - Redirects in Mozilla Firefox to bogus search websites
    - Freezing at Welcome screen in XP

    I would not help but they insist they have done nothing untoward and have some got the malware in spite of good net practice. I checked this out and it seems they have took onbaord what I said and have been unfortunate. In any case, I've reluctantly agreed to help them...they are perhaps 'more sinned against than sinning' for you Shakespeare fans.

    Having trawled through all of the malware removal guide step by step (I found Ask Toolbar on my travels) I got to the XP removal guide and have done the following things:

    *I ran Superantispyware and MGTools - these ran successfully and I have logs for them both.
    ** I also tried to initialize Malware Bytes, Spybot, Combofix and Root Repeal. Malware Bytes, despite clever renamings and such like, will not run, nor will Spybot or Combofix. RootRepeal has locked up my computer everytime I've tried it - despite disabling all features on my computer which would inhibit it.

    The friends computer is still having much the same problems as before, hence why I posted here. My gratitude for any one who can help.
     

    Attached Files:

  2. stevejouanny

    stevejouanny Private E-2

    Hi again, not trying to bump my thread - just updating yourselves as I have managed to get Malware Bytes to do a scan. I have adhibited the said log to this post.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sure you were told the last time to disable TeaTimer...and probably also told to clean out everything you can in this folder:
    C:\Documents and Settings\Steve\Local Settings\Temp\

    After you have done both of those tasks, and disabled all of you protection software and your firewall, try running Combo and the other scans. At the moment, it looks like the SAS and MBAM scans may have removed the malware, but I would like to see the results of the other scans to be sure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds