Ran Read Me But Still Experiencing Problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SAHeadley, Apr 7, 2008.

  1. SAHeadley

    SAHeadley Private E-2

    Hi there

    I am new to this and only know the basics about computers but have been having some problems.

    Recently my anti-virus program (Norton) picked up threats, advundo (or something like that) was one of them. There was also one called w32.sillyIm. My PC has been very slow and I cannot access some pages, esp hotmail - not with Firefox at all and sometimes have problems with Internet Explorer.

    I get alot of strange ads on my web pages sometimes too. Eg, 'This is no joke, Congratulations, u have won, click here to claim'.

    I tried the readme on removing malware but that has not really worked and I was unable to complete all the steps (couldn't run Spybot nor remove Live Messenger). Norton also gives me a whole host of threat that it picks up (eg 'qttask.exe made 24 modifications to your Windows startup settings'). I had pop-ups as well with IE but since using Firefox that was greatly reduced. I will attach the logs from the scan. Any suggestions you can offer will be greatly appreciated. Thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please run the full current version (you are running an out of date version of MGtools) of the below procedure and attach all of the requested logs.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. SAHeadley

    SAHeadley Private E-2

    Hi

    I think that's the new there. Please let me know, thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run ALL of the READ & RUN ME. MGtools is the very last step. Please start at the beginning and run all steps. You did not uninstall Viewpoint Media Player in step 1 as requested. You can skip the SUPERAntispyware scan since you already attach the log; but when you return, you need to attach the below logs which are requested in the READ ME:

    • the log from Malwarebytes Anti-Malware
    • the log from ComboFix
    • a new MGlogs.zip file which you can easily get by double clicking on the C:\MGtools\GetLogs.bat file which will run all the tools and create a new C:\MGlogs.zip file
     
  5. SAHeadley

    SAHeadley Private E-2

    Hi

    For some reason I cannot download the ComboFix. It doesn't give me the 'save file' option just 'cancel'. Should I continue without it?
     
  6. SAHeadley

    SAHeadley Private E-2

    Hi again

    I uninstalled Viewpoint. I got through with SpyBot this time and Immunised as well as scanned. I have noticed an immediate difference. I can no longer see those annoying ads on the page and can now access all pages attempted so far with FireFox. The pages do not take so long to load. As mentioned earlier I was unable to download Combo Fix and I also cannot run MBAM. I think I got it installed but it wouldn't run but I am also sure I did that the very first time. However I cannot find the logs. I have attached the new MGlog.

    I am also concerned that Norton keeps telling me things like, 'qttask.exe has made 30 (everday, literally, that number grows) modifications to your Windows startup settings'. Is that normal??

    Thanks
     

    Attached Files:

  7. SAHeadley

    SAHeadley Private E-2

    Me again

    I forgot to ask...

    I am doing all this under my user ID. I trust that it is not necessary for the other users on the PC.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true. All user accounts should really be cleaned. They each have their own registry entries and have some unique folders of there own in the files system. How many user accounts are there and have any been experiencing problems?

    Is your copy of Spyware Doctor a paid version or free trial that does not fix things? If the later then uninstall it now.

    What is the below folder for?
    Code:
    "C:\"
    GLXYGIRL      Feb  3 2008              "GLXYGIRL"

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\MEDUSSA\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. SAHeadley

    SAHeadley Private E-2

    Hi

    It's just me and my sister who have accounts. There were about 3 others but I took them off a few weeks before posting this log.

    She was having the same problems as me and now that I consider it, I think it is under her account where the trouble began. A message came from one of her Messenger contact which contained a link and was asking 'is that picture really you?' She clicked on it and a page was opened but didn't load anything. Her friend then told her she never sent her a message!

    I paid for Spyware but haven't renewed the subscription. I don't see it in programs or control panel to uninstall.

    Galaxy Girl is a set of games which sis loaded on for her daughter.

    I ran HJT but was unable to download Avenger (didn't give the 'Ok" option when I clicked on your link, just cancel. So a friend sent it through a messenger window but I got the following message:

    Error: Invalid script. A valid script must begin with a command directive. Aborting Execution!

    I copied exactly as shown above, no more no less.

    Please advise. Thanks for your time.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why would you want to pay to get malware? :D:D:D Okay....I know you meant to say you paid for a spyware removal tool not for spyware. ;) But what program are you referring to? Or was this supposed to say Spyware Doctor :) in reference to my question? It looks like it was uninstall but not properly.

    This is a bad/dangerous practice. You should only use our links. There is nothing wrong with our link and I don't know what you mean about the OK option. When you click the link you get the below window. Click the thumbnail to expand to a viewable image.

    aveng-dld.jpg

    And all you have to do is select Save to download it to your Desktop as requested.

    Maybe not. The error message normally mean you left out the first line: Files to delete:
     
  11. SAHeadley

    SAHeadley Private E-2

    I did mean Spyware Doctor! :eek:

    I don't know why it didn't uninstall properly. I always uninstall through the control panel and Add/Remove programs - not sure if I supposed to do something else.

    I got through with Avenger, thanks! :cool

    I have attached the logs as well!

    I am seeing those stupid ads again, still!:cry
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely because you had used MSconfig to control the startup of Spyware Doctor and uninstalled it while using MSconfig. This is just one on many reasons why the READ ME emphasizes not to use MSconfig. We will fix this.

    Which ads exactly and which browser opens with the ad? This sounds like they may be jsut related to the sites you are accessing. Many sites do give popups.

    Let's do a little more cleaning.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Nikki\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)


    After clicking Fix, exit HJT.


    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now please try running Malwarebytes Anti-Malware and ComboFix again using the instructions in the READ ME. It they do not run, please explain exactly what happens and how far you get.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • Malwarebytes log (if it ran)
    • ComboFix log (if it ran)
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. SAHeadley

    SAHeadley Private E-2

    Hey!

    I get ads like, 'This is no joke, Congratulations. You have won! Click here to claim!' I copy links to a friend and he doesn't see that stuff at all. I used to get it on this site but not anymore. I got it on Hi5 recently.

    I have attached all files as requested except MBAM. I have also attached a file to show the problem I get, Hope this doesn't make me look stupid! :confused
     

    Attached Files:

  14. SAHeadley

    SAHeadley Private E-2

    This is what I get why I try to run MBAM; then nothing!

    It's not allowing me to upload that document!

    It asks about language. Then it gives me the setup screen. Then it says ready to install. Click install to continue with installation. Set-up has finished installing, click finish to exit and I do that, then nothing. Can't find it to run it and it doesn't run automatically.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First please run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Yes and these are quite normal on some websites. If you have all browsers closed except one browser session connected here to Major Geeks do you get these popups? If yes answer the below questions:
    1. if no browsers are ever opened after a reboot, do you get popups
    2. if you reboot into safe mode, with no browsers open do you get popups
    3. if you open one browser and only access Major Geeks, do you get popups.
    What attachment are you referring to?

    No wonder you had problems with ComboFix. You did not follow our instructions for renaming and also on how to run it. You have this:

    C:\Documents and Settings\MEDUSSA\Desktop\ComboFix.exe

    It should be

    C:\Documents and Settings\MEDUSSA\Desktop\cf.exe

    And you should have run it from the Start, Run box with the Killall option as requested.

    Please delete the below file (HijackThis does not below here and is not needed) and the New Folder if it is empty
    Code:
     
    2008-04-05 17:20 . 2008-04-05 17:20 1,308,216 --a------ C:\analyse.exe
    2008-03-30 19:08 . 2008-03-30 19:08 <DIR> d-------- C:\New Folder
     
     
  16. SAHeadley

    SAHeadley Private E-2

    Hi!

    I'm back! My PC crashed and I had to take it to get fixed. Thank you for all your help and I guess I will skip straight to "How to protect yourself from malware.

    Thanks again
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds