Problems solved? Would like follow up

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Daybreaksky, Feb 23, 2009.

  1. Daybreaksky

    Daybreaksky Private E-2

    I'm done the 'READ & RUN ME FIRST. Malware Removal Guide' and would most appreciate it if someone could tell me if I've gotten rid of everything.

    The problems started about a week ago when I found out the hard way that my AVG wasn't working any more. I don't know when, where or how it was disabled. Something called 'Spyware Protect 2009' popped up in my task bar and put a large flashing irremovable text box on the screen. I was able to work around it with minimal clicking. I tried downloading and using several programs; Mbam, SAS, and Spybot S&D which didn't work. I got Ad-ware to work and it got rid many infections and after several runs I got AVG back. I haven't seen anything titled 'Spyware Protect 2009' since I ran AVG.

    But since then I've had a problem with searches on google and all other search engines, on both IE and Foxfire. That’s when I came across this site (luckily 'cached' under the link in Google’s searches is there :-D )

    The guide seems to have solved my problems.
     

    Attached Files:

  2. Daybreaksky

    Daybreaksky Private E-2

    the last log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome to Majorgeeks

    Am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Your patience during this time is much appreciated. Thanks.

    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    The VMN Toolbar you have appears to be broken. Do you use it and did you knowingly install it? If not, then uninstall it. If you do use it, you may need to reinstall to fix the possibly broken browser objects.


    1) If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    2) I see that you had Symantec installed at some point, but that you are now using AVG as your Anti-Virus. WE need to rid your machine of any remnants of it by using the Norton Removal Tool. Please see the below:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.


    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:



    After clicking Fix exit HJT.

    4) Now we need to use ComboFix to remove a bunch of malware files and also to disable the viewpoint service which was left behind after you uninstalled it.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\Quarantine\C\WINDOWS\system\msvbvm60.dll
    
    Drivers::
    Viewpoint Manager Service
    
    File::
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}]
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5) Run Ccleaner!

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    ---! Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now !---
     
  5. Daybreaksky

    Daybreaksky Private E-2

    Thank you for your help!

    I went ahead and uninstalled VMN Toolbar. I don't remember installing it as I try to uncheck any toolbar options when installing things. This is the only part I had a slight problem with. It uninstalled but a box popped up titled "Setup" and said "cannot unregister VMN toolbar.dll".

    The previous owner of this computer had Norton but let the subsciption lapse. Norton is annoying and I thought I'd gotten rid of it all. Thank you for giving me the tools to complete that!

    Everything seems to be running great. I'd say faster and definitely more consistent.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My syntax was wrong in my previous post, so let's restore the file properly.

    We need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\Quarantine\C\WINDOWS\system\msvbvm60.dll.vir
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • Attach the log in your next reply so we can see the above worked.
     
  7. Daybreaksky

    Daybreaksky Private E-2

    ok here it is.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, I'd like to see one more MGlog.zip from before I give you the final instructions for clean up.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Thanks :)
    kes
     
  9. Daybreaksky

    Daybreaksky Private E-2

    Here's hoping for the best. :)
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, one more time:

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\Quarantine\C\WINDOWS\system\msvbvm60.dll.vir
    QUIT::
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    ---! Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now !---
     
  11. Daybreaksky

    Daybreaksky Private E-2

    Ok I'm not sure if combo fix ran like it has before, I didn't sit and watch it this time, because it did not give me a log. It gave me a notepad file named DeQuarantine.txt containing

    C:\Qoobox\Quarantine\C\WINDOWS\system\msvbvm60.dll.vir -> C:\WINDOWS\system\msvbvm60.dll ( 1384448 bytes )

    I had no problem with the rest of the instructions.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  13. Daybreaksky

    Daybreaksky Private E-2

    Thank you so much!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're ever so welcome :)

    kind regards
    kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds