Malware guide completed, but still an AV8 problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dalym7, Dec 21, 2010.

  1. dalym7

    dalym7 Private E-2

    Hi guys,

    Hopefully you will bear with me - i'll keep it short.

    I've had a problem with an AV8 redirect - usual story, a fake 'scan' of files appears in an IE window, a pop up to download a 'remedy' appears.

    I hope this won't annoy anyone - but i did ALL the readme malware removal instructions two weeks ago. None of the programs found anything (but i found that i did not have privileges to open some of my own folders afterwards? - i thought because of the settings the anti-malware programs tweaked?). Anyway, i found nothing after following the malware removal guide from start to finish. I also restored my system to an earlier time then. And i've been sailing along since, thinking that it must have been something very simple that was deleted by CCleaner (which i use daily) or Spybot (which i use regularly) or one of the programs recommended in the readme (which i then removed, because they didn't find anything anyway and i had similar products). Anyway, as i result i don't have any logs from the recmmened programs (as they didn't find anything, and i removed them shortly afterwards, thinking, as i say, everything was fine...)

    And then last night it happened again so i went back to the malware removal guide, and yes, i did cherry pick it this time - i downloaded superantispyware again - which again found nothing. I also installed Window Essentials, which also found nothing.

    So now i'm in the predicament - do i have to go through the whole malware removal guide process again (as you might want the logs) - or, if possible, can we pick up from this point onwards? I mean, i really, really, did do the guide from start to finish the last time - as i found the guide (it has change since) an immense help a few years ago when i got a virus - but since it didn't find anything when i followed it two week ago, i felt there was no real point (the old adage of doing something again, the exact same way, but expecting a different result!). Anyway, i will be guided by yourselves and whether you think it is necessary - and i very much appreciate any help you could give me.

    Incidentally, this AV8 has only appeared when i visit one website - a very reputable one - www.guardian.co.uk - i think its unlikely in the extreme that it has anything to do with the site itself - but it must be some sort of trigger? Furthermore, it won't happen all the time - just occasionally. I've also googled to see if anyone has had problems with this on that site, and have found nothing.

    Many thanks in advance for any help you could give me.

    PS - I'm running Windows 7 Ultimate 64 bit on a Siemens lap top
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to do the scans all over again. Attach those even if they don't show anything. Be sure you have updated the programs before you use them ( SAS and MBAM ).
     
  3. dalym7

    dalym7 Private E-2

    Hi TimW,

    Finally got round to posting my logs. The AV8 problem hasn't happened again (but as i say, its sporadic - and only (so far) when i visit guardian.co.uk) -so i'm not sure if i still have a problem or not - but i would much appreciate if you could have a look at the logs i corrected.

    1) Super antispyware log attached

    2) Malware bytes log attached

    3) Combofix - couldn't get a log - program kept hanging just as it was getting to the log generating part - see screen shot attached in hangerrors.doc.

    4) Rootrepeal - did not run as i'm 64 bit

    5) MG tools - I did get a 'program stopped working' error during it - but it seemed to produce its logs none the less - they are attached (along with the 'program stopped working' error - in hangerrors.doc)

    Many thanks!

    Martin
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I would suggest you pay particular attention to the How to Protect Yourself link at the bottom of the final clean up:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  5. dalym7

    dalym7 Private E-2

    Thanks - i appreciate your time. I guess the problem must have been rectified by spybot - but i didn't know the specific problem was being resolved at the time. I'll let you kow how i get on - many thanks for your time and help.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome!! Do let me know if it re-occurs. ;)
     
  7. dalym7

    dalym7 Private E-2

    Just one last thing Tim - from my initial post, you know that i did the guide once before - i had to do a system restore after that as there seemed to be access problems with my folders when i went into windows explorer (padlocks on folders (where there was no padlocks before) etc - and i am the only account on this lap top. Its happened again now - I've attached a screenshot of them - how do i get back to normal? Last time, as i say, i did a system restore, and everything was fine.. but this time, i don't have the option as combo fix has set a restore point of today and there is no more available! Any ideas? - screen shot attached. Many thanks!

    Sorry, need to reduce size of attachments to upload
     
    Last edited: Dec 27, 2010
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is an issue for the software forum. I don't know how that happened or what you should do about it. Sorry. Do post in the software forum and maybe someone else has had this issue and knows how to resolve it. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds