Virus on a Vista PC. Am I clean now?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ragexzero, Dec 13, 2008.

  1. ragexzero

    ragexzero Private E-2

    Hello. Its me again, this time attempting to clean the family computer.

    I ran the "Read & Run Me First" with no problems and it seems Im clean but I cant be sure so I thought Id confirm with you guys.

    AVG was going crazy every time I did an antispyware scan, saying theres an infection in the process started by the antispyware programs. It also gave a result with an infection of:

    Generic_C.ABUI

    located in:

    C:/Windows/System32/drivers/ndisprot.sys

    So here are my logs and thanks for the help.
     

    Attached Files:

  2. ragexzero

    ragexzero Private E-2

    Last one of my logs. Thanks again.
     

    Attached Files:

  3. ragexzero

    ragexzero Private E-2

    Apparently Im far from clean. AVG has still been giving me virus alerts, this time for other viruses.

    One of the viruses this time is: Win32/Heur

    Located in: C:\Users\pcromero\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PX7XCXQK\InstallAVv_880167[1].exe

    And another one is a trojan: Downloader.Agent.AQEE

    Located here: C:\Users\pcromero\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DPH07JS7\InstallAVg_880167[1].exe

    I hope you can all help me clean this stuff out. Thanks for everything. If I need to post more logs or do anything else, just let me know.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your previous logs were clean. Note you should read the below sticky:

    Don't Bump! It Only Hurts You!!!

    The last post cost you about a total of 6 days. We were probably about ready to answer your msg # 2 from Dec 13th when you posted msg # 3 causing more delay. We are so busy right now that it is taking 2 to 3 days to answer new posts.

    These are just temp file in your Temporary Internet Files (aka TIF) folder and can be removed by emptying your browser cache. It also seems rather strange that AVG cannot remove them since they are nothing and infact they actually appear to be temporary files that AVG itself uses which is therefore stupid of them and not strange.




    Flusing the Internet Explorer Cache
    1. Run Internet Explorer
    2. Click Tools and select Internet Options
    3. Now on the General tab, click Delete Files and select Delete all Offline content too on the next window, Click OK. When it finishes Click OK.
     
  5. ragexzero

    ragexzero Private E-2

    Thank you for your response and help. I didnt realize posting again on the thread would constitute a "bump". I was under the impression that a bump would be just a post with the word "bump" on it. But I stand corrected and Im sorry I broke the rules. Ill know better next time.

    I ran CCleaner the other day and also ran ComboFix and MGtools once more, and it all went away. I hope there wont be more trouble but that computer is used by my dad who is not too knowledgeable about safe browsing so Im sure Ill be cleaning it again eventually.
     
    Last edited: Dec 19, 2008
  6. ragexzero

    ragexzero Private E-2

    Im really sorry to bother you all again but I just realized the computer in question has a broken internet connection for some reason. I remember running ComboFix and MGtools a previous time made the connection die, but then I restarted the computer and it came back. Now it wont connect at all. What can I do? Any help would be appreciated.
     
  7. ragexzero

    ragexzero Private E-2

    Nevermind. It was an ISP problem. Its all fixed. Thanks again for everything. I didnt mean to bump this again but I thought I would save you the trouble of answering to it, since the issue is resolved.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are happy to hear you got your problem resolved.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds