virus removal, problem with some of the steps

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by barkingmad, Dec 3, 2009.

  1. barkingmad

    barkingmad Private E-2

    I have been working on this for 7 hours, trying to get everything exactly as the read me file suggests and the other links in that thread. I am not that computer literate, plus dont fuss me if I didnt do something right :-o I'm trying. Thank You for any help :) Here is my only 2 logs I could get (1 incompleted)
    super antispyware log
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/03/2009 at 06:45 PM

    Application Version : 4.31.1000

    Core Rules Database Version : 4332
    Trace Rules Database Version: 2186

    Scan type : Complete Scan
    Total Scan Time : 00:55:41

    Memory items scanned : 389
    Memory threats detected : 0
    Registry items scanned : 5130
    Registry threats detected : 2
    File items scanned : 13934
    File threats detected : 4

    Adware.Gamevance
    HKU\S-1-5-21-507921405-813497703-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3}
    HKU\S-1-5-21-507921405-813497703-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}

    Trojan.Agent/Gen
    E:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\1E.TMP

    Trojan.Dropper/Sys-NV
    E:\WINDOWS\SYSTEM32\1D.TMP
    E:\WINDOWS\SYSTEM32\FDE32.DLL

    Trojan.Agent/Gen-FraudLoad
    E:\WINDOWS\SYSTEM32\FDE32(2).DLL

    MGtools log (not complete) attached
     

    Attached Files:

  2. barkingmad

    barkingmad Private E-2

    I FORGOT TO ADD MY NOTES AS REQUESTED IN READ ME AND OTHER STEPS ON THREAD.......
    unable to download ccleaner says error 500
    try to download defragmenter from maintenance page and it doesnt start
    the download. i have 2 antivirus programs ...my antivirus that came
    with my computer, symantec corporate edition has been disabled, and i
    cant enable it. i cant run a scan, it says files are missing or moved.
    i tried to remove the second antivirus (avg pro trial edition) rebooted
    and its not in add/remove programs anymore. but still in system tray
    functioning.
    tried to download malewarebytes anti male ware. I click on the link
    to start the malewarebytes program and the download doesnt start.
    (i didnt download the programs that didnt except the 64 bit bc i didnt
    know what i had)
    i downloaded root repeal to my desktop. i double click on it and it says
    windows cannot open the file, choose from a list to open it for you.
    i didnt continue since i wasnt sure of what i was doing.
    i downloaded mgtools. double clicked it and it started a prompt screen
    during the scan for mgtools (i have a "windows -no disk"
    error message that reads....
    EXCEPTION PROCESSING MESSAGE C0000013 PARAMETERS 75B6BF9C 4 75B6BF9C
    75B6BF9C)...im not sure if thats any useful information just thought i'd
    include it. (it just came up again) (i clicked continue) (and the scan
    has stalled out) not continuing the scan.... i had to close the window after about 30
    minutes. i tried to rerun the scan. i double clicked on mgtools and it
    just opens a bunch of other files inside of the mgtools folder. (im not
    that computer literate, sorry im trying)
     
  3. barkingmad

    barkingmad Private E-2

    i have tried 3 times to come back here and show my other logs, and my IE8 keeps getting 'hung up' so i'll try yet again.........i will try and attach them ALL
     

    Attached Files:

  4. barkingmad

    barkingmad Private E-2

    here is super antispyware log
     

    Attached Files:

  5. barkingmad

    barkingmad Private E-2

    I UNDERSTAND THAT YOU GUYS ARE VOLUNTEERING TO HELP US MISFORTUNATE FOLKS. HOWEVER NOBODY HAS TAKEN THE TIME TO LOOK OVER MY LOGS :(.........LIKE I SAID I UNDERSTAND THAT YOUR BUSY. IF NEEDED I CAN GO TO SOME OTHER GEEK FORUM FOR HELP WITH MY LOGS. I HAVENT RECEIVED ANY TYPE OF HELP SINCE I CAME HERE!!!!!! (other than the read me first thread)
    I DONT UNDERSTAND IT!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    We understand you are frustrated but impatience and shouting is not going to help you. Reading the stickies and the instructions you were already given, would have helped. Bumping your thread by adding additional posts is what cost you additional delay. Had you read your signup email and followed the instructions, your first post would have included all the required logs and you would have just waited to get an answer. That answer would have been at least two days ago. But since you bumped your 12/3 message 2 days later, you now are getting an answer on 12/7. Such is the cost of bumping. See: Don't Bump! It Only Hurts You!!! which you were given in the READ & RUN ME FIRST and in your email.

    You are free to go to another forum if you wish. There you will just have to start all over again and will be waiting at least as long if not longer to get another answer. Any good forum is just as busy as we are and quite a few forums do not answer or finish all threads, which we do. We just do them in queue order so everyone shares the same queue waiting time. Are we supposed to answer your thread before we answer everyone else who posted before you?????? Do you think that would be fair?

    You mentioned having a problem getting one of your two AVs uninstall. Reinstall AVG9, and then reboot. After reboot, uninstall it. Then I would suggest seeing if you can uninstall Symantec since it may be broken. Then after another reboot, reinstall only one antivirus program.


    Also I see Spyware Doctor 7 installed. Is this a paid version? If not, I suggest that you uninstall it now.

    What remaining malware problems are you actually having after running the READ & RUN ME? Other than what has already been removed and the issue with multiple antivirus programs, your logs are clean.
     
    Last edited: Dec 7, 2009
  7. barkingmad

    barkingmad Private E-2

    I guess this should teach me a lesson to start checking my emails daily.
    i didnt know uppercase letters meant i was shouting, im sorry i do not mean to shout at nobody ....sometimes uppercase is easiar for me to read, again sorry :(.....ummm well my avg9 expires today so i suppose i can download the free version after removing the trial version. spyware doctor , i seen that i believe in the maintenance thread, which is the only reason i downloaded it. i will remove it promptly as well. yes, after having done these logs my computer is still very slow. IE8 keeps saying that runtime had to i think shut down in an unusual way. IE8 runs much more slowly still, is this normal after having had a virus?
    ......the day or two after i posted my logs i still noticed on some web pages certain words would be double underlined and highlighted in green, if i hover over that word "vibrance" or "vibrant" window pops up (small window) with some type of advertisement. (i wasnt able to fully disable my antivirus while running the logs, will that affect the outcome? should i run any logs again? if not, should i remove all the programs READ ME suggest I download to obtain the logs? Thanks Chaslang for taking time out of your personal life to help folks like me and many others. how might i make a donation to your website after this is all over and done with? I'm greatful, i really am!!! I look forward to hearing back from you :)
     
  8. barkingmad

    barkingmad Private E-2

    i wasnt successful at download the avg trial edition for a second time, however i was able to download a free one. i remmoved spyware doctor. i havent seen any more advertising. i think i realized what was making my computer slow. i always have a speicific page opened that requires flash player, and i believe that may have been causing my computer to be slow. i noticed when i do not have a page with flash player on it, pages run smoothly. so i think my problems are cured, with the exception that i still need to figure out how to remove avg trial edition, im sure with some researching on google i should find an answer. thank you so much!
     
  9. barkingmad

    barkingmad Private E-2

    well when i came back here to search on how to do a clean system restore open up ........
    the advertisement appears on the READ AND RUN ME FORUM....... but hasnt showed up on any other sites. of course i only visit a handful of different sites. the name in the header of this small window (that doesnt detach from my main viewing window) is Vibrant.......it has all types of advertisement. bing advertisement, microsoft advertisement, depending on the word on the page like, virus, spyware etc specific words triggers the advertisement.....i do not know how to fully get rid of this. i will not post again so my thread doesnt have to start all the way over again.. thank you so much :)
     
  10. barkingmad

    barkingmad Private E-2

    well i said i wasnt going to post but um... superantispyware popped up and said it needed to block my avg. i did not unblock yet without doing a scan, so i do quick scan and almost immediately it says trojan something on the list to the left of scanning window...so i thought i'd scan and not fix yet, and post log......it just kinda sucks i have to post again and this thread gets bumped to the top :(:(:( ...ok tried to attach the log but it says its to big that its 279 kb in size. sas said that i had over 3000 detections. is this possible? should i try to upload the log in 2 different attachments?thanks, :cry
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are not malware. The are normal advertisement ads that show on many websites. Some websites will stop showing them once you log in and the recognize you are a member. Major Geek's does this when you login to the forums. The main website always shows the ads. Websites cannot be run for free which is why the sell advertising space.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just try running their removal tool show on the below page:

    http://www.avg.com/us-en/download-tools
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The free version of SUPERAntiSpyware does not provide any protection. It is just an after the fact scanner. The only thing it may do, is inform you of a possible change to your home page if you chose that option when you installed it. Thus if AVG was trying to reset your home page back to a different default then what you had when you installed SUPERAntiSpyware then you would get a notification about the change.

    Without a log, we cannot advise you any further.

    Just stop posting and this will not happen. Thus far you are not posting about any valid malware issues. Just inability to uninstall AVG and Vibrant ads which are quite normal on the internet and they only appear when you move your mouse over the keywords. By continously posting, you made it take more than 4 days to get a response to message # 7 that you posted on 12/08/2009.

    Is this the SUPERAntiSpyware log? Did you disable reports about cookies like we suggested in our instructions? We said to set the below options
    Either split the log or put it into a ZIP file and attach it.


    Oh and one comment about your remarks about your PC or IE8 being slow. The problem is your PC! Your logs show the below specs
    Code:
    Processor x86 Family 6 Model 7 Stepping 3 GenuineIntel ~547 Mhz 
    Total Physical Memory 512.00 MB 
    Available Physical Memory 131.75 MB
    Your processor is too slow and you have only half of the minimum amount of memory we recommend for XP. You need at least 1 GB but even with that, your very slow processor is still going to be a problem.
     
    Last edited: Dec 12, 2009
  14. barkingmad

    barkingmad Private E-2

    im not talking about that advertisement!!!! and those options are unchecked under the scanner options but thats ok, im going to get another pc....good luck helping out everyone else, i hope you dont make them feel as dumb as you made me feel......please do not reply, you'll only be wwasteing your time!!!! AGAIN IM GREATFUL YOU HELPED RID ME OF VIRUS BUT YOU MADE ME FEEL LIKE A FOOL IN THE PROCESS, GOOD JOB:wave peace out
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but Vibrant Ads are advertisements. They are double underline keywords appearing on many websites. The keywords trigger various ads to be shown. This is not malware. You stated yourself that you were talking about Vibrant Ads and all I was doing was explaining to you that they are not malware and that they are quite normal and used by many websites. In message # 7 you said
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds