Want to make sure...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Equilibrium44, Feb 20, 2009.

  1. Equilibrium44

    Equilibrium44 Private E-2

    Hello MajorGeeks Forum Experts!

    Thank you so very much for your assistance up through this point. I went through the Read Me and spent time doing each of the tasks outlined, and they seem to have helped very much.

    As far as I can tell, things seem to be back to normal, but I wondered if at your convenience, someone could check my logs just to make sure?

    It seemed like it had been deleted before as well but as you know this stuff is nasty and I just want to make sure it's gone for good.

    Attached are two of the logs, I'll attach the other two in the next post.

    Thank you all again so much! This thread is wonderful, and I'm going to recommend the steps outlined to my parents for maintenance of their machines.
     

    Attached Files:

  2. Equilibrium44

    Equilibrium44 Private E-2

    Here are the other two logs.

    Thank you again for any assistance you can provide!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are in pretty good shape. We just have a few things to do before final instructions.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O11 - Options group: [JAVA_IBM] Java (IBM)

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old version of Java:
    IBM 32-bit Runtime Environment for Java 2, v1.4.2

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  4. Equilibrium44

    Equilibrium44 Private E-2

    Thank you very much for all the help!

    I followed all the steps, and they all worked (including the confirmation that the registry edit was successful).

    You are a very kind person to devote your time to helping others like this, and it is so much appreciated. Thank you!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  6. Equilibrium44

    Equilibrium44 Private E-2

    One thing I've noticed since completing this process is that my Microsoft Office Applications take forever to open. Like, when I click on a Word Document or a Spreadsheet, it will lock up and take a good minute to come up. This was not the case before, is there something I changed that would have caused this?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not based on the logs. There is possibility that your Windows\Prefetch folder may have been cleaned up and it could take a few days for things to reestablish themselves in prefetch. If they have not returned to normal now, you can post in the Software Forum to discuss this but my best guess right now is the fact that your free Disk Space on drive C is gettin rather log. The below showed in your logs.

    Size 51.09 GB (54,855,811,072 bytes)
    Free Space 1.10 GB (1,178,238,976 bytes)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds