Thank you major geeks

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ChrisInMN, Jun 20, 2008.

  1. ChrisInMN

    ChrisInMN Private E-2

    I have used majorgeeks.com in the past for downloads of spyware cleaning utilities and so (of course) I turned to major geeks when my computer got a wicked case of the vundo crap. Well, just following the stickies I was able to work out a process that cleaned my machine up right away.
    Thank you to all you great people out there helping us all keep our computers running to the best of their abilities. Without these instructions I would have probably ended up reformatting and that's such a pain in the behind.

    Thanks again everyone

    ChrisInMN
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You're welcome. We are happy to hear it helped you; however if you had a real Vundo infection, it would be in your best interest to attach the logs requested in the READ & RUN ME. Vundo almost always requires additional manual removal steps to totally remove it.
     
  3. ChrisInMN

    ChrisInMN Private E-2


    Here is the zip file of the logs created on the last step of the "read me first" thread.

    Thank you.

    ChrisInMN
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do have a little more to do, but I'm sorry to say I need all of the logs. The below 3 other logs were requested:

    • SUPERAntiSpyware
    • Malwarebytes Anti-Malware <--- looks like you did not even run this
    • ComboFix
    Also you have more than one antivirus installed. The first few paragraphs of the READ & RUN ME indicated that you must not do this. You have Authentium AntiVirus and iolo AntiVirus installed. One of them must be uninstalled immediately.
     
  5. ChrisInMN

    ChrisInMN Private E-2


    I use Iolo (bundled with system mechanic). I've never even heard of Authentium antivirus, and it doesn't show up on the add/delete programs. Any ideas what to do to get rid of that? I'll get those other logs posted as soon as I can.

    Thanks again for the help

    ChrisInMN
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You probably installed it when you used junk from an ISP that you used at some point. Many offer free security suites and Authentium is often included. When the ISPs software was uninstalled, this should have been removed, but apparently it was not. We will remove it manually when I get the rest of the logs.
     
  7. ChrisInMN

    ChrisInMN Private E-2


    Here we go.. sorry about that.

    ChrisInMN
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old version of Java:
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {47e398a4-baa8-bdfb-40b4-1bc8f8e9b458} - {854b9e8f-8cb1-4b04-bfdb-8aab4a893e74} - C:\WINDOWS\system32\vvbrsdjl.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. ChrisInMN

    ChrisInMN Private E-2

    Ok.. Great! The registry update worked good. It was successful. The only thing I noticed was that after we got rid of the other antivirus program, it caused iolo to not be able to function. When the pc rebooted it said iolo antivirus could not initialize because it can not load "dvpapi.exe"

    Attached are the two files requested.

    I really do appreciate all your help with this issue. It will be nice to have a clean machine without spending 2 hours reloading XP.

    ChrisInMN
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we just learned something. And that is that iolo does not have their own antivirus even though they list a separate startup for one. They are actually using Authentium's antivirus program. Too bad they don't show it that way in Add/Remove programs. Can you please just reinstall this now? It will be easier to do that then to try and restore things from ComboFix's backups. Let me know your status.

    Your logs are clean now!
     
  11. ChrisInMN

    ChrisInMN Private E-2


    Chaslang,

    You're brilliant when it comes to malware. You really should set up a paypal "chip-in" site so that people you help can toss a few dollars your way. I have reinstalled my anti-virus software and everything is working great.
    It's a double edged sword though.. now I know where to go when things get tough so I might beg for help again! ;)
    Thank you and god bless.

    ChrisInMN
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds