Damn antispyware-reviews.biz please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Cnn, Apr 1, 2008.

  1. Cnn

    Cnn Private E-2

    Hello!

    The other day when I was surfing this annoying antispyware-reviews.biz thing started poping up. Have tried several ways to fix it but nothing seems to work. Also tried the"Malware removal guide" didn't work.
    Apperantly I'm not the only one having this problem, and it seems like you guys have the means to fix things. Thanks in advance for helping :)

    Btw the MGlog didn't work :s so hope it's ok to attach HJTlog instead..? When running the getlogs.bat it says my OS is unsupported. Running Vista home pro i think.

    Cnn
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi Cnn,
    Welcome to Major Geeks!


    Are you running a 64 bit operating system? Did you disable UAC? Why is HijackThis installed on your desktop? Did you follow the instructions in the READ & RUN ME FIRST thread which is one of the stickies at the beginning of the Malware Forum? If so, you will have come to the cleaning procedures for Vista operating systems.

    Please reinstall HijackThis directly under C. Make a folder called HJT and install it into this folder. Rename the file hijackthis.exe to analyse.exe. Then double click on analyse.exe to run it again and attach the fresh log.

    abri
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Abri,

    Did you notice that the HJT log shows evidence of THREE antivirus programs? It appears that a very important starting step of the READ ME was skipped.
     
  4. abri

    abri MajorGeek

    Hi Chaslang,
    I don't think the READ ME was ever followed. Cnn will notice these things like the Vista instructions and getting rid of all but one antivirus program when running through the READ ME.
    abri
     
  5. Cnn

    Cnn Private E-2

    I did follow the "read & run" and the "Vista cleanup" first, obviously missed the antivirus-part. :) Believe I've removed Symantec now, but Panda Antivirus won't uninstall. I't says "An error has occured while running the setup."
    Error Code: -5006 : 0x80070002
    Error Information:
    >SetupDLL\SetupDLL.cpp (1194)
    pAPP:panda Antivirus 2008
    PVENDOR:panda Security
    PGUID:D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A
    $11.0.0.28844
    @Windows (6000) IE 7.0.6000.16609

    So now I don't know how to remove it.
    Have reinstalled HJT under C and attaching a fresh log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer the below questions.
    1. Did you follow the instructions for using MGtools?
    2. Did you disable UAC and then reboot?
    3. Did you save MGtools.exe to c:\MGtools.exe
    4. And then did you run MGtools.exe as administrator as requested?
    5. What problems are you having with MGtools?
    6. Do you see the C:\MGtools folder?
    7. Do you see the C:\MGlogs.zip file?
    Please try using the below to uninstall Panda:

    Your Uninstaller! 2008

    Did that work?



    Run C:\HJT\analyse.exe by double clicking on it. (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [ynqafbjl] C:\Windows\system32\wtqroxyn.exe
    O4 - HKLM\..\Policies\Explorer\Run: [M5mNzfepmi] C:\ProgramData\yjyxejod\ghwtchsb.exe
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. Cnn

    Cnn Private E-2

    1-4 Yes
    5- It says "Your OS Version is unsupported by Getlogs"
    System specs: MS Windows Vista AMD Athlon 64X2 Dual-Core Processor TK-53,
    1,9gb RAM, NVIDIA MCP67M
    Is this maybe why Mgtools won't work?
    7- There is a MGlogs.zip file in C, but it only containes getunkey.txt.

    Looks like Uruninstaller did the trick and removed Panda.

    No pop-ups the last hour, and it used to pop every 10-15 minutes, so looks like it's gone. Hope so :)

    Thank you so much, you guys rock!!
     

    Attached Files:

    Last edited by a moderator: Apr 2, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is the problem and that is why Abri ask you if you were running x64 back in message # 2. The tools are not compatible with your version of Windows.

    Please download GRK64.zip to your C:\MGtools folder and extract the GRK64.bat file into the same folder. GRK64.bat should run on x64. Then double click on the GRK64.bat file. It should create a runkeys.txt log and it probably will even ZIP it into the MGlogs.zip file in your root folder of the Windows boot drive. Attach the new MGlogs.zip file now.

    I still see Panda in the HijackThis log you attached. Did you get this HijackThis log before or after running Your Uninstaller.

    You need to uninstall your old Sun Java versions and install the current version as requested in step 1 of the READ ME.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds