System Restore problem after trojan.metajuan removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bowser05, Aug 20, 2009.

  1. Bowser05

    Bowser05 Private E-2

    Hello,

    I want to thank you all for such useful forums. So I have tried running through all the steps that in the Read and Run me thread and there were a couple problems I ran into.

    First off, when I tried to remove all of my quarantine files from my Norton folder, there was a specific one I couldn't remove. It's called backdoor.tidserv. It says reboot is required but everytime I reboot it manages to quarantine that file but then another copy of the backdoor.tidserv pops up with the same problem.

    Also, when set to normal mode, I had to start up my computer 3 times before it would actually stop freezing at the login screen (after the 3rd time I was going to go safe mode, but it worked on the 3rd time). Don't know if that is relevant.

    When I went to Add or Remove Programs, I found a few things I could uninstall that were on your list, but My Way Search Assistant, which is there, will not allow me to uninstall it (as in the option to remove it isn't there, it only says 'used rarely' but the option that should be below it doesn't exist.

    I was also asked to turn off TeaTimer, which I can't do because ever since I got the trojan I have not been able to open Spybot. I've tried running it straight from it's folder as well but it just won't open. It acts like it will but doesn't.

    Also, as background information as to what I have tried so far. I ran a full-system scan with Norton and it detected a Downloader, which it removed just fine, it detected backdoor.tidserv, which I mentioned above, and it detected trojan.metajuan, which it said 'Remove failed.' It then takes me to the symantec site which tells me to turn off system restore, do a full update of norton, do a full system scan, then remove added entries to the registry. I couldn't turn my system restore off because the option is grayed out in it's appropriate tab, so I got some help and figured out to turn it off manually from services.msc. After that I booted normally, did my update, did a full system scan (with the same problems still), then rebooted my computer as per symantec instructions. Finally I went to check out the registry and none of those values (for the trojan or backdoor) were existent for me to remove. I then tried a full system scan again and the two problems still persisted (backdoor for reboot and trojan removal failure). That is when I then came over here, started from scratch and am following your guys' instructions. Hope that information helps as well.
     

    Attached Files:

  2. Bowser05

    Bowser05 Private E-2

    Upon completion of the WHOLE process in the Read and Run me section, it seems my machine is clean and working fine. I then attempted to do the final step of System Restore reset and I ran into a little problem. Luckily, the system restore options are not grayed out anymore (it must have been the trojan like I said before). So I checked the box to turn it off and clicked apply. An error message then popped up that said "System Restore encountered an error trying to enable/disable one or more drives. Please restart your machine and try again."

    I restarted and tried again and it did the same thing. I've already done a full virus scan with Norton, SAS, Malwarebyte and Spybot with nothing popping up to make sure there wasn't anything left over (I could be completely wrong of course). I then tried again and same thing. So then I restarted in safe mode and tried once in my user name and once in the default admin and both times the problem persisted. All the logs are attached.

    I patiently await a reply. Thanks a ton.
     

    Attached Files:

  3. Bowser05

    Bowser05 Private E-2

    As an update, my computer is having trouble starting up. Whenever it gets to the login screen I put in my password and then it freezes. I usually have to restart the machine a couple times before it starts up right. Thought that might be useful for you guys to know. Thanks again.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Lets do this.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\uacmal.db

    See is you can run RootRepeal now. Attach the log if you can.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds