antivirus 2010 stops removal tools

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by franktaplin, Dec 1, 2010.

  1. franktaplin

    franktaplin Private E-2

    A customer brought in a computer running Windows XP Home SP3 that has Antivirus 2010 on it. I started following the malware removal guide. I removed viewpoint media player and removed old versions of Java. I was able to install and run Ccleaner. I installed Superantispyware. The computer already had Malwarebytes antimalware pro on it. I also copied combofix to desktop. Tried to run SAS but it would terminate after about 3 minutes of running. MBAM terminated after about 20 seconds. Combofix doesn't finish starting before it's terminated. Windows then said it could not access the specified device, path, or file. You may not have the appropriate permissions to acces the item. HAd to use cacls from command line to gain access again. Tried to do a manual removal as outlined in:
    http://www.bleepingcomputer.com/virus-removal/remove-antivirus-2010
    The files removed and registry settings removed were under the Current Antivirus 2010 listing.
    After that the Antivirus 2010 splash screen does not come up but I still cannot get removal tools to finish. I then downloaded TDSSKiller and ran it but it terminated before I could see any results. It apparently finished since MGTools found it and included the log but I never had the chance to do anything.
    I don't have any removal tool logs but I was able to get MGTools and Rootrepeal to run so I'm attaching those logs.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please be aware that we will give you limited support as we do not perform this help to businesses that are using our resources to make a profit.

    We need to start with this and then you can see if the other scans will run.

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    Code:
    File::
    C:\WINDOWS\Abonowubucudirot.bin
    C:\WINDOWS\Sjuqexuyodegexin.dat
    C:\\WINDOWS\\itofideluj.dll
    C:\WINDOWS\system32\drivers\vbma8a74.sys
    C:\WINDOWS\mpswsd32.dll
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run CCLeaner and make sure afterward that all the .dat files are removed from this folder:
    C:\WINDOWS\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  3. franktaplin

    franktaplin Private E-2

    Got the registry edit to work but when I copy the second part into the Avenger and try to execute it I get a message that says
    "Error: Invalid script. A valid script must begin with a command directive. Aborting execution!"
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Crap, I knew I had done something wrong, but couldn't recall which thread>

    Do this:

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Then finish the rest of the instructions.'
     
  5. franktaplin

    franktaplin Private E-2

    Ok I figured that something like that occurred. Here's the logs.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK, you got it to run in Combo. Sorry for the confusion. I want to check one more thing. Please go to C:\MGTools\analyse.exe ( HJT ) and run it. You can attach the log or the new MGLogs.zip, but I only want to see the HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds