Antivirus 2010 Taken Out But Still Have Problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by edflo, Nov 3, 2010.

  1. edflo

    edflo Private E-2

    A friend's Computer stared with Antivirus 2010. SuperAntispyware and Malwarebytes started scans, but vanished from screen! After that they would not start! Will not run in safe mode either. In safe mode I was able to find and uninstall Antivirus 2010, and that got rid of the pop up windows. Still can not run either of the above programs. SuperAntispyware Portable runs, but gets knocked off screen after scanning about 4500 files. But since it runs again, I ran it till it found 10 trojans, paused, and dealt with those 10 trojans. Next Combofix and RootRepeal only run a short time and they dissappear. No logs can I find for any of the above.

    Mgtools runs without errors, though! Attached are all the logs I have. Also when booting into safe mode there is an additional account called Administrator which I did not think was ever on this computer before.

    This is my first time posting, but I have greatly appreciated MajorGeeks. I have successfully disinfected about five other computers using your forums.
     

    Attached Files:

  2. edflo

    edflo Private E-2

    Finished online scan by eset.com. Here is log. Also RootRepeal log I found on her crowded desktop. I wonder if I can remove this infected ndis.sys file that eset could not deal with by using my Bitdefender linux boot disk. I will try tomorrow if I do not get other instructions from MajorGeeks before I can get back to this. I will report back.

    Thanks so much, Ed
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this:
     
  4. edflo

    edflo Private E-2

    Thanks Tim. I was able to get mbam.exe to run again using the cacls command that you gave. The mbam scan only lasted 6 seconds, and the mbam screen dissappeared again. After that mbam would not start. Then I booted with the BitDefender Linux boot cd and deleted the ndiswan.sys file in Win\Sys32\drivers that the above eset scan identified as infected but could not get rid of. Then I rebooted into Windows, used cacls, tried mbam another time, and it still dissappeared after only 6 seconds of scan.

    Wondering what to try next. Thanks, Ed
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. edflo

    edflo Private E-2

    Thanks, Tim.

    Did BitDefender online scan. Log is attached. Could not updated virus signatures, though. Tried twice. When it got to 33% it started over. 2nd time it made it to 40%. I am trying updating again, but I thought I would do the scan and get the log to you. It found lots of bad stuff.

    Thanks again, Ed
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All that found was a false positive for MGTools and infections in your system restore folders. Uncheck system restore and reboot. Do not re-enable system restore quite yet.

    Tell me what issues you are still having.

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
    Last edited: Nov 7, 2010
  8. edflo

    edflo Private E-2

    Hi Tim,

    Issues still can not run mbam.exe nor superantispyware. I can run cacl and then they will run one time, but only scan a few seconds. I tried uninstalling each and then reinstalling not in Program Files but in their own directory in C:\, but same symptom -- each runs one time and only scans a few seconds.

    Also, in Safe Mode there is this Admin account I have no password for and mbam and Superantispyware will not run in the user account.

    Ran TDSSKiller.exe without having to change its name. It found only one suspicissous service -- vbma55c9 in Sys32\drivers. Log attached.

    Thanks Ed
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now! We may need to do a clean install if we can't fix this.
     
    Last edited by a moderator: Nov 7, 2010
  10. edflo

    edflo Private E-2

    Hi Tim,

    I ran Avenger and MGTools\Getlogs without problem. Avenger log and MGTools logs attached. I could find no Combofix.txt in C:\ or anywhere else, evn though I ran ComboFix again.

    Still can not scan with mbam nor SAS. I uninstalled both from where I had last installed in C:\ and reinstall both in their normal place in Program Files. MBAM installed and ran one time scanning for 11 seconds this time. SAS will not install right. SAS portable scans to about 4500 files and dissappears again.

    I think the user does not want me to spend a lot more time on this, and I do not want to take up much more of your time.....She may get a new computer, and I think I can salvage her personal files off this. Unless you now see something in these latest log that appears promining, I will go that route. Please give me a response to this.

    I appreciate what I have learned. Thank you so much -- Ed
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are still unable to remove this item which is hooked deep into the system:
    svchost (\\.\globalroot\Device\svchost.exe\svchost.exe)

    So to avoid further delay, I would suggest you back up her personal info and data files and do a reformat and clean install.

    I am sorry we were unable to clean this for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds