Windows XP Cleaning question

Discussion in 'Malware Help (A Specialist Will Reply)' started by gillobc, Dec 18, 2008.

  1. gillobc

    gillobc Private E-2

    Hi,

    I was instructed by your welcoming forum to perform the read and run me first and the XP cleaning procedures.

    I had Spybot S&D installed previously a few days ago before I posted to this forum. The program did not find anything, but in the instructions in the XP cleaning it says not to have Tea Timer. Well, I do. SAS does not indicate how to unstall or deactivate it- so since I just installed it yesterday, do you want me to uninstall and then download without the tea timer?

    Next, I also installed Malwarebytes AntiMalware a few days ago as well. Not knowing I would be on this forum, I did not rename the the setup file as you instruct. This program did find 2 issues which were quarantined - again do you want me to uninstall and download and change the name. Or can I rename the file. The exe file is mbam.exe, but you indicated it would say mbam-setup.exe - so I wasn't sure if it was the same file.

    Thanks so much for your help and patience - I am new to this
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We ask that you disable teatimer while you run the scans:
    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    MBAM just needs to be checked for updates.

    Same with running SAS
    Then ComboFIx
    Then C:\MGTools.exe --> C:\MGLogs.zip

    attach those logs.
     
  3. gillobc

    gillobc Private E-2

    I have followed the instructions and attached are my logs. Hopefully I do this right with the the 4th log attachment.

    My issues started about 2 weeks ago when another user was on my laptop (a different computer) on my network -and she had a pop-up come up that she needed to install Antivir - her screen went black then two icons came up on that computer Best BDSM Pron and Gayfetish. I quickly ran Spybot and got rid of them on the laptop and various other spyware, and antivirus - it is running fine now- however on this computer, my desktop, during the time I was cleaning the laptop, it started making a grinding sound so I quickly shut it down. When I turned it back on it made the same grinding sound, but booted up very slow - I ran several different antispyware, malware, spybot, etc.. but found nothing, so I found this website and thought I would see what you have to say. However, to this day, the computer still seems to have problems booting up, sometimes takes about 15 minutes, and initially getting onto my email and IE. Once I'm there it seems to run fine, albeit quite a bit slower. I also seem to be losing a lot of hard drive space, I ran defraggler and got back a couple gigs. Still running slow though
     

    Attached Files:

  4. gillobc

    gillobc Private E-2

    Here is the forth log from MGtools - Thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....there are a few thing we can do, but you are limited because of the amount of RAM you have installed
    Code:
    Total Physical Memory    512.00 MB    
    Available Physical Memory    121.80 MB
    
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Your other issues would best be addressed in the software section.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. gillobc

    gillobc Private E-2

    Thank you for everything. I went ahead and did the instructions you gave me- but have 2 questions.

    (1) I don't think I have MSJVM becuase I have Sun Java most recent version- and I did try your removal instructions - when I typed into run it said the file could not be found - however in my windows prefetch there is a file UNMSJVM(1)exe-32070a90.pf -- Does that mean it was unininstalled at some point? Just want to be sure I have it completely off. I also went to the download to remove but got scared when it wanted me to assingn a place to put the extracted files so I clicked off and didn't run anything.

    (2) You indicate to empty the Sun Java cache file periodically - how do I do that?

    Thanks for your help.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it is no longer in your Add/remove programs.....and you have run CCleaner ( both cleaner and issues --> making sure to do the backup when prompted)...the you are fine.

    To clean the java cache....go to the control panel / click on Java / settings / delete files.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds