trying to remove viruses

Discussion in 'Malware Help (A Specialist Will Reply)' started by dobieman, Jan 20, 2010.

  1. dobieman

    dobieman Private E-2

    Hi, I did everything it said to do and wanted to see if I still have viruses on this pc, it was a friends pc that let his teenagers use it , and and help would be appreciated.
     

    Attached Files:

  2. dobieman

    dobieman Private E-2

    heres the mg log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This PC was/is a mess. The kids need to be set to Restricted User Accounts. They must not be allowed to have administrator priviledges especially if this PC is used by other people and especially if it is used for any financial related transactions.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 5

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. dobieman

    dobieman Private E-2

    Hi, thank you for helping me out, I know the pc's a mess, I did install Kasperky internet security on it and will set the parental controlls on it before I give it back to them, I hope I did what you said right. here are the logs you wanted. Thank you.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you working on multiple forums to solve your problems? Who asked you to run C:\ISeeYouXP

    Also who asked you to install a-squared Anti-Malware
    Also who asked you to install Spyware Doctor

    You are not following our instructions!!!! See the first section of the READ & RUN ME

    Help here will now be terminated.
     
    Last edited: Jan 23, 2010
  6. dobieman

    dobieman Private E-2

    I got those other scans from your list that says try other scans if this things dont work, and I didn't hear anything for a while so I was trying other things
     
  7. dobieman

    dobieman Private E-2

    i got them from your Alternative Scans list
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to be on step 6!!!! You are still working on step 4 of the cleaning procedure and we are manully fixing things.,

    No you did not get Spyware Doctor or ISeeYouXP from our Alternative Scans. Yes A-Squared is there (soon to be removed) but the other two are not part of our procedures.

    Uninstall A-Squared, Spyware Doctor and delete the ISeeYouXP.exe file and folder it created. Then attach a new log from MGtools ( i.e, run the GetLogs.bat file again first ).

    Also tell me what problems if any still remain.
     
  9. dobieman

    dobieman Private E-2

    Thanks chaslang for all your help, I apologize for being impatient and trying other things before waiting for your reply, I realize you can only help if I take it one step at a time, for now now I wont do anything until I hear from you, I trust your help more then any one elses, thank you.
    Everything seems to be running good now and heres the log you wanted, I did get rid of all the other thing I had on here and ran. Thanks again.
     

    Attached Files:

    Last edited: Jan 25, 2010
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Obviously not. You ignore what the READ & RUN ME said, and then I instructed you again a few messages back that you are not supposed to be doing anything on your own. And what do you do, you continue to install things on your own! WebRoot on Jan 23, Advanced System Care on Jan 25, Revo Uninstaller on Jan 25th. You are now on your own to cleanup all the junk left over on your PC from Spyware Doctor, A-Squared and anything else.




    Since your logs were clean and all you have are issues due to installing things that were not requested, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds