Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Malware Removal Help  (Read 3079 times)

0 Members and 1 Guest are viewing this topic.

klemak

    Topic Starter


    Starter

    Malware Removal Help
    « on: December 10, 2009, 05:48:52 PM »
    I am attaching my three logs: SuperAntispyware, Malwarebytes' Anti-Malware, HijackThis. Please help.

    Thank you for your expediency.

    Mike

    [Saving space, attachment deleted by admin]

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Malware Removal Help
    « Reply #1 on: December 12, 2009, 06:48:26 PM »
    Hello klemak and welcome to Computer Hope Forum. My name is Superdave but you can just call me SD. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the desktop.

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

    (Description: A small program that reminds you to register your Creative Labs product (i.e. sound card, video card). Unnecessary. Removing this will free up a small amount of system resources.)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Java\jre6\bin\jusched.exe\"
    (Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)

    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

    link # 1
    Link # 2

    Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Vista users Right-click combofix.exe and select Run as Administrator and follow the prompts.
    Double-click combofix.exe and follow the prompts.
    When finished, ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
    Windows 8 and Windows 10 dual boot with two SSD's

    klemak

      Topic Starter


      Starter

      Re: Malware Removal Help
      « Reply #2 on: December 13, 2009, 12:32:40 AM »
      Hey SD! You may call me Mike.

      So far, my computer has been running a lot better, even just using the introductory steps. Thank you for taking my case.

      I applied your steps and have attached the two logs: Hijack This and ComboFix. A couple of things I noticed - after running the Disable/Remove Windows Messenger, I ran Hijack This. The two O9 Boxes that you listed were not there. There were other O9s, but not the specific ones, so I checked of the O2 and the O4 only.

      After running Combo Fix, a copy of Internet Explorer was on my desktop and Google Chrome (which I have used as my default browser) was no longer the default.

      Windows is updating again, which is a good sign, as it wasn't for a long time before I took on this plight. However, one update it is trying to do is for Microsoft Office. It wants the CD for it, but I have not had the disc for some time (long story...messy breakup with ex), so that is the only update I'm not able to do.

      Besides that, I hope that this process is quick and painless for us both. Thank you again,

      Mike

      [Saving space, attachment deleted by admin]

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Malware Removal Help
      « Reply #3 on: December 13, 2009, 01:26:39 PM »
      Good news, Mike. The logs look clean. Just to be on the safe side, I would like you to run this scan. As for the MicroSoft Office problem; I have the same thing on my computers and never get asked for a disk. Perhaps you could ask this question on this forum

      ESET Online Scan

      Scan your computer with the ESET FREE Online Virus Scan

      * Click the ESET Online Scanner button.

      * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
      * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
      * Place a check mark next to YES, I accept the Terms of Use.

      * Click the Start button.
      * Accept any security warnings from your browser.
      * Leave the check mark next to Remove found threats and place a check next to Scan archives.
      * Click the Start button.
      * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
      * When the scan completes, click List of found threats.
      * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
      * Click the <<Back button then click Finish.

      In your next reply please include the ESET Online Scan Log
      Windows 8 and Windows 10 dual boot with two SSD's

      klemak

        Topic Starter


        Starter

        Re: Malware Removal Help
        « Reply #4 on: December 13, 2009, 06:27:19 PM »
        Hey SD,

        There were no threats found, so I couldn't click anything to list. The only button remaining, after the scan had completed was "Finish."

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Malware Removal Help
        « Reply #5 on: December 13, 2009, 07:00:48 PM »
        That's even better  news, Mike. If there are no other issues with your computer I guess we can do some clean up.
        You can uninstall HJT but keep the SAS and MBAM programs. Update them and run them about once a week to keep the bugs out.


        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is finished.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

        Looking over your log it seems you don't have any evidence of a third party firewall.

        Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

        Remember only install ONE firewall

        1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
        2) Online Armor
        3) Agnitum Outpost
        4) PC Tools Firewall Plus

        If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

        To turn off Windows XP System Restore:

        NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
        5. Click Apply.
        6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        8. Restart the computer and follow the instructions in the next section to turn on System Restore.

        To turn on Windows XP System Restore:

        1. Click Start.
        2. Right-click My Computer, and then click Properties.
        3. Click the System Restore tab.
        4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
        5. Click Apply, and then click OK.

        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
        Safe surfing  ;D
        Windows 8 and Windows 10 dual boot with two SSD's

        klemak

          Topic Starter


          Starter

          Re: Malware Removal Help
          « Reply #6 on: December 14, 2009, 03:31:36 PM »
          Thanks SD!! You were an awesome help!!!  ;D

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Malware Removal Help
          « Reply #7 on: December 14, 2009, 04:40:07 PM »
          Thanks Mike. My mentor will be glad to hear that.  ;D
          Windows 8 and Windows 10 dual boot with two SSD's