XP Cleanup Logs...

Discussion in 'Malware Help (A Specialist Will Reply)' started by RayM, Dec 28, 2008.

  1. RayM

    RayM Private E-2

    Can I please get your help in analyzing these logs for my laptop after performing all the steps listed in read and run me first and xp cleanup thread(s). See attached and thanks in advance.

    Ray
     

    Attached Files:

  2. RayM

    RayM Private E-2

    Here's mgtools log as well. Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    You are also out of date with the definitions for Malwarebytes, run it and update to the current database and run a new scan with it too. Attach the new log.

    What malware problems ( if any ) are you currently having? You do not have this PC properly protected and it appears to be a corporate PC. Are they allowing PCs on their network with no protection installed?

    You have a broken uninstall of McAfee showing. You need to run the below, reboot and run it one more time:

    McAfee Consumer Product Removal Tool

    Now delete the below folder:
    C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP

    Who put the below file in the root folder? It does not belong here:
    Code:
    2008-10-16 03:45 262,144 ----a-w C:\ntuser.dat
    Do you know what the below file is for?
    Code:
    2008-12-03 20:34 . 2008-12-26 20:09  256  --a-- c:\windows\system32\pool.bin
    Now let's cleanup a few other misc items.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)

    After clicking Fix, exit HJT.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe using the black bold print link in the first sentence.


    Run MGtools.exe then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 31, 2008
  4. RayM

    RayM Private E-2

    Hi Chas. I don't know what happened on the SAS and Malware updates being so out of whack. I followed your instructions word for word below and have attached all the requested logs.

    Here's some answers to other points in your post:


    "What malware problems ( if any ) are you currently having? You do not have this PC properly protected and it appears to be a corporate PC. Are they allowing PCs on their network with no protection installed?

    You have a broken uninstall of McAfee showing. You need to run the below, reboot and run it one more time:

    McAfee Consumer Product Removal Tool"


    The Malware problems I was experiencing were my browsers (IE and Firefox) getting hi-jacked and shutting down regularly. The last straw was a hi-jack that took me to install "Internet Security 2009".

    This is more a personal PC that has the option to work in our business environment. It runs too slow when accessing the server, so I just RPC my Outlook instead. And the synch feature stinks as well (maybe I'll try Good Synch).

    The original McAfee was what came with this laptop. But the definitions got old and one day while connected to the server I decided to install our Sonicwall McAfee Total Protection. Somehow that install never got fully installed. After my malware post, I started reading through the firewall and antivirus suggestions and found the McAfee un-install through the Wiki link. I un-installed it and decided to run Comodo as my AV and FW. So far, I'm happy with it.


    "Now delete the below folder:
    C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP"


    DELETED

    "Who put the below file in the root folder? It does not belong here:
    Code:
    2008-10-16 03:45 262,144 ----a-w C:\ntuser.dat

    Do you know what the below file is for?
    Code:
    2008-12-03 20:34 . 2008-12-26 20:09 256 --a-- c:\windows\system32\pool.bin"


    No idea but I'm pretty sure they are useless. I have deleted them.

    "Now let's cleanup a few other misc items.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)

    After clicking Fix, exit HJT.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe using the black bold print link in the first sentence.


    Run MGtools.exe then attach the below log:
    C:\MGlogs.zip"

    Done as requested!

    "Make sure you tell me how things are working now!"

    So far, things seem to be running pretty smooth. Please let me know what you turn up, if anything, in the logs and how I should finish up the cleanup (system restore toggle, etc...). Thank you for taking the time to help me out. I appreciate it!

    Ray
     
  5. RayM

    RayM Private E-2

    Forgot to attach the logs. Here they are.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As
    Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX
    until you exit all browser sessions including the one you are reading in right now:

    O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - Unknown owner - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (file missing)

    After clicking Fix, exit HJT.

    Now just as a redundant fix, also open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop myAgtSvc
    sc delete myAgtSvc


    Other than that your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. RayM

    RayM Private E-2

    Thanks for your help Chas. Take it easy.;)

    Ray
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds