Need Help removing Virus, Spyware and Malware from my laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thandaka, Jan 2, 2008.

  1. thandaka

    thandaka Private E-2

    Hi,
    My laptop has become quite slow since past few days and get annoying IE Pop-up windows recently. Even my Symantec Antivirus Protecion has got disabled.


    Please let me know what logs I need to provide to resolve these issues.

    Thanks,
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. thandaka

    thandaka Private E-2

    Hi Tim,
    Thanks for your help and I have ran some of the Softwares that you have suggested as per the Guide and my system looks bit stable now.

    But my Symantec Antivirus Protection is still disabled.

    Please advise what needs to be done to get this enabled.

    Thanks,
    Sid
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the logs that were requested in the instructions. :)
     
  5. thandaka

    thandaka Private E-2

    Currently my laptop is in deep mess.I can the view internet connected icon but I cannot browse/view any internet pages viz., www.google.com or www.yahoo.com.

    Have been getting lot of pop-up windows, Email popups. Ran HJT and removed some of the files, thinking that my laptop can be restored.

    Remember removing the below entries and few more.

    O4-HKLM\..\Run: [jkdfj94kgdftdf] C:WINDOWS\TEMP\winlogan.exe
    07-HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    Attached the HJT LOG of yesterday(5-Feb) and of today.

    Please help
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off ..HJT is a tool, not a malware cure. It needs to be properly installed and renamed which is how it will be installed when you run the instructions in the Read and Run First guide.

    The requested logs after doing that are:
    AVG-antispyware log
    ComboFix log
    MGLogs.zip ---> from running the MGTools.exe
     
  7. thandaka

    thandaka Private E-2

    Attaching the log files.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't let ComboFix run to completion. You also didn't fix anything that AVG found.
    You must rerun AVG Antispyware and this time do not Ignore all the problems it finds like you did last time. You must either Quarantine or Delete allt he problems. Save a new log and attach it at the end of the below instructions.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Microsoft PS Service
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    * Click OK until you get back to Windows.

    Run C:\MGtools\analyse.exe by double clicking on it, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste Microsoft PS Service into the box that opens, and press OK
    * If you receive any error messages just ignore them and continue.
    * Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:

    * new AVG Antispyware log
    * c:\avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  9. thandaka

    thandaka Private E-2

    Uploaded the new logs.

    System Status: I still cannot access/browse any internet sites.

    Thanks,
    Sid
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are making some progress.

    Please find and delete:
    C:\Combofix

    Now:
    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Now download ComboFix to your desktop!! Then double click it and do nothing until it produces a log.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:
    * ComboFix
    * c:\avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  11. thandaka

    thandaka Private E-2

    Uploaded the new log files.

    System Status:
    ****************
    Still cannot access/browse any internet pages.
     
  12. thandaka

    thandaka Private E-2

    Uploaded the log files.

    Could not upload the total Combofix folder, so just added the ComboFix.txt.
     

    Attached Files:

  13. thandaka

    thandaka Private E-2

    Tim,
    Can you please check the logs and advise the Action Plan.

    Sid
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The action plan would be to disable ALL anti-virus and anti-spyware software so that the fix I give you can work.

    D:\Documents and Settings\326003212\Desktop\Anti-Virus --> what is this?

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Find and delete:
    :\Documents and Settings\326003212\Desktop\ieupdr2.exe

    Have you tried using FIreFox as a browser?

    Remember...some of your problems are due to not having SP2 installed.
     
  15. thandaka

    thandaka Private E-2

    'Anti-Virus' - This is the folder, where I kept some of Ant-Spyware and Anti-Virus Softwares.

    I have done the steps as suggested by you, but still cannot access the internet.

    Most of the times, I use Mozilla Firefox as browser and rarely IE.

    Do you want me to install the SP2. If yes, where can I download(get it) to install ?


    I have the below Anti-Spyware and Anti-Virus softwares installed.

    Super AntiSpyware
    Ad-Aware-2007
    Spybot
    AVG-Anti-Spyware
    CCleaner


    This laptop has Symantec AntiVirus, which has been currently disabled and has to be enabled.



    Please let me know what should be kept and which needs to be removed.


    Thanks,
    Sid
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Whenever you finish the fixes that I give you, re-enable your security software.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Are you still just having problems with IE?
     
  17. thandaka

    thandaka Private E-2

    Just want to let you know that I am unable to connect to internet from any of the browsers, Firefox or Internet Explorer.

    I am downloading all the softwares that you wanted me to install into my good laptop and installing & generating the logs in infected laptop.

    Will perform your latest Action Plan and update the results shortly.
     
  18. thandaka

    thandaka Private E-2

    Completed the Action Plan as suggested by you, but still cannot acces the internet using Mozilla or Internet Explorer.

    :confused

    Please advise.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are you trying to connect ....thru a router or directly thru a modem ( is it dial-up or cable or dsl?) ....have you spoken with your ISP about the problem?
     
  20. thandaka

    thandaka Private E-2

    I will check with my Internet Provider regarding this.

    What do you think of the current status of my laptop. Is it OK now
     
  21. thandaka

    thandaka Private E-2

    I am able to connect/browse all internet sites after changing the IP Address to detect automatically.

    No pops now and my laptop looks OK now.
    Still my Symantec Antivirus program is disabled.

    Please help in restoring this.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what you have tried to re-enable it. The malware may have corrupted it so you may need to uninstall and then re-install.
     
  23. thandaka

    thandaka Private E-2

    I think in Firefox, I have changed the Connection Settings that were set to Manual Proxy Configuration with some url. After changing the setting to 'Auto-detect proxy settings for this network', I am able to connect to Internet.

    My Symantec Anti-virus was disabled before this as well.

    Please advise.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The symnatec was disabled before what ....? Was it a paid for version that is still active?
    If not...uninstall it and choose a different anti-virus from HERE
     
  25. thandaka

    thandaka Private E-2

    I guess it was disabled by some virus or malware, not sure which one.

    This is my official laptop and Symantec Antivirus is a paid version.

    So I cannot unistall this and install any other software.

    Please advise is there are any way we can re-enable Symantec Antivirus.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds