Malware Protector 2008 - Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Raiders, Jun 18, 2008.

  1. Raiders

    Raiders Private E-2

    Need help. This is what happened and what I have done so far.
    Sunday, 15th I clicked on a Youtube movie. It wouldn't start. Then my SPyware warning popped up showing something was trying to change one of my files, selected no and got out. When the window closed my background was all blue with popup saying my computer was infected and ......
    Now I had Malware Protector 2008.

    What I have done to delete so far.
    I first tryed Norton with no luck. Then I tried Spyhunter, no luck.
    I then tried Malwarebytes' with a little luck. Malwarebytes' did delete any files that had the name Malware Protector 2008 but, nothing with the file name. I noticed that Spyhunter was looking for files with a different name and so was Malwarebytes'.

    If I am not mistaking, the files that Malwarebytes' shows it is looking for is "shclkr0etfg". The files I have are "shcv2fj0ev9s."
    I manually went into my registry and sytem32 and deleted those files out except one. It is a setting folder under that file and it says I can't delete while it searching.
    How can I get rid of that file?
    Also, I still have Norton popups, from stopping e-mails from being sent from the Malware Protector 2008?

    Any help or ideas?

    Thanks.
     
  2. abri

    abri MajorGeek

    Hi Raiders,
    Welcome to Major Geeks!


    Some forms of malware bring a whole lot of files with them, so it would be useful for you to go through the instructions in the READ & RUN ME FIRST. This is a collection of different scans including MalwareBytes which compliment each other and give us more information to work with when you get done. The logs that you get from the scans will allow us to find files which need to be deleted manually. If you decide to do this, you do not have to run MalwareBytes again. We prefer seeing the first-run scan results.

    abri
     
  3. Raiders

    Raiders Private E-2

    will do. I have my log I will post.
     
  4. Raiders

    Raiders Private E-2

    Question is CCleaner "Registry Booster"? That is all I see when I click on CCleaner link.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!! When you click this: CCleaner You see the title of the program is CCleaner Slim (No Toolbar) 2.08.588

    You need to click on one of the dowload links which look like the below
    Code:
    [IMG]http://majorgeeks.com/images/dl-arrow3.gif[/IMG] [B]Free Downloads From[/B] 
    [URL="http://majorgeeks.com/downloadget.php?id=4191&file=15&evp=a12d758b021af1a4f0a6bfe45b0c7a82"][IMG]http://majorgeeks.com/images/american_flag.gif[/IMG] MajorGeeks FL[/URL] - |USA|
    [URL="http://majorgeeks.com/downloadget.php?id=4191&file=10&evp=a12d758b021af1a4f0a6bfe45b0c7a82"][IMG]http://majorgeeks.com/images/american_flag.gif[/IMG] MajorGeeks TX[/URL] - |USA|
    [URL="http://majorgeeks.com/downloadget.php?id=4191&file=11&evp=a12d758b021af1a4f0a6bfe45b0c7a82"][IMG]http://majorgeeks.com/images/american_flag.gif[/IMG] MajorGeeks TX[/URL] - |USA|
    [URL="http://majorgeeks.com/downloadget.php?id=4191&file=15&evp=a12d758b021af1a4f0a6bfe45b0c7a82"][IMG]http://majorgeeks.com/images/american_flag.gif[/IMG] MajorGeeks FL[/URL] - |USA|
    [URL="http://majorgeeks.com/downloadget.php?id=4191&file=9&evp=a12d758b021af1a4f0a6bfe45b0c7a82"][IMG]http://majorgeeks.com/images/american_flag.gif[/IMG] MajorGeeks FL[/URL] - |USA|
    [URL="http://majorgeeks.com/downloadget.php?id=4191&file=14&evp=a12d758b021af1a4f0a6bfe45b0c7a82"][IMG]http://majorgeeks.com/images/australian_flag2.gif[/IMG] Internode[/URL] - |Australia|
    
    You have been looking at other advertisement links on the page. You do not want and do not need Registry Booster.
     
  6. Raiders

    Raiders Private E-2

    Sorry for taking so long. It is due to my job.
    I ran the programs as you suggested attached are my logs.
    It appears everything is running ok.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the last log that was requested. The log from running MGtools which will be the C:\MGlogs.zip file as stated in the instructions.

    What problems did you have trying to run ComboFix. Your log is very incomplete. It did not run properly. Try again in safe boot mode if necessary.
     
  8. Raiders

    Raiders Private E-2

    Here is my MGlogs.zip file. Only problem I had with ComboFix is that I was not able to copy and paste "%userprofile%\desktop\cf.exe" /killall into the run box.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean? Are you saying you don't know how to copy and paste?

    Please just run ComboFix by double clicking on the icon on your Desktop. Then attach the log here after it completes.

    Are you still having malware problems?

    You have no protection software installed! Why not?
     
  10. Raiders

    Raiders Private E-2

    Sorry it has taking so long to reply, it is do to my work.
    I thought I had protection software. Venus Spy Trap by Trend, SUPERAnitspyware, Avira AntiVir Personal, along with my Windows firewall?

    Here is the attached file. I hope it is better.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not show Avira to be installed and while TrendMicro's Antispyware shows as installed and it does show loading in your startup but it is not running. Thus that make me believe you only have a trial version which is only a scanner and it provides no protection. SUPERAntipsyware was only from running the READ & RUN ME and it does not provide any protection unless you purchase it. The free program is a scanner only. The Windows firewall is totally inadequate as it provides only one way protection and it is very poor at even doing that.

    You have some left overs form Norton hanging around. Please run this Norton Removal Tool (SymNRT) and then reboot your PC.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of Sun Java:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 13, 2008
  12. Raiders

    Raiders Private E-2

    Sorry so long to reply, job again.

    Protection software.
    I have Trend Micro Anti-Spyware 3.0, it is due for renewal.
    Super Anti-Spyware (Free version)
    Avira Antivir Personal (Free version)
    On my laptop I have Penicillion.
    Like I said my Trend Micro Anti-Spyware is due to for renewal, I don't have any problems letting it expire. Per the Major Geeks which in their opion would be the best to use?
    Same as with the Firewall, which would be the best to use.

    I did all as you instructed, ran the Norton Removal tool, Disable/Removed Windows Messenger, Uninstalled old versions of Sun Java, ran MGtools analyse selected and fixed the (8) items, did the Combo Fix, did fix me registry and received a message "...has been successfully entered into the registry"., ran CCleaner and MGtools Getlogs.

    I have attached the requested logs.

    Things appear to be working better but, I haven't use my computer after performing this session.

    I also want to thank you for your patience and expertise in your help.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It you like and are happy with TrendMicro AS then keep it. You always get more features and support if you purchase software then you do with free software.

    My final instructions below contain a link which gives you many things to do to protect yourself. You will find info in there on firewalls too.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. Raiders

    Raiders Private E-2

    Trend Micro is a Anti-Spyware. Wouldn't I also need an anti-virus?
    When I read them they all seem to say the same thing and I am just wanting to make sure I have a good software to protect this happening again.

    Thanks.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already said you have Avira Antivir Personal. It is your antivirus program.
     
  16. Raiders

    Raiders Private E-2

    I went to update my Trend Micro AntiSpyware it deleted my Avira Antivir Personal and wants me to delete Spybot. This isn't good is it?
    Should I purchase the Avira Antivir?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I'm not sure why it would do this. In fact if this is truly happening and they are not saying that AntiVir and Spybot were infected, then you should uninstall TrendMicro and ask for a refund since this would be an absurd requirement on their part. Are you sure that you only have TrendMicro AntiSpyware???? Or did you also purchase an the antivirus or worse....the security suite.

    That's up to you if you wish to support the company and also get support from them but this has nothing to do with what you said about TrendMicro telling you that you need to uninstall it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds