win 7 antivirus 2012 issue

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mikehurv, Dec 18, 2011.

  1. mikehurv

    mikehurv Private E-2

    Somehow this file got onto my laptop last night. Found a link and fixed it (at least partially) so the annoying fake pop up doesn't pop up anymore. however, ever since my internet browsers have been redirecting me and getting pop ups to various sites.

    I have Eset and Malware Bytes on my computer. Have run them both and they don't find anything. In my Malware Bytes log it shows that a variant of Win 32/sirefef.dn was found and deleted. But every time I restart my computer I have the same redirection issues.


    I am attaching a few logs (not sure if I am supposed to have more than these 2).

    Need some help!! Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. mikehurv

    mikehurv Private E-2

    Here is another log
     

    Attached Files:

    • log.txt
      File size:
      18.7 KB
      Views:
      2
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be following the instructions in the order written. Wait until you have finished them and then attach ALL of the logs.
     
  5. mikehurv

    mikehurv Private E-2

    Here are the other two logs. Have gone through all of the other steps. Thanks for your help
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Not yet. You still need to attach the requested log from MGtools.
     
  7. mikehurv

    mikehurv Private E-2

    My bad. Here it is
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You one of the latest infections going around the stops your BFE and MpsSvc services ( and possibly others ) from running and that also corrupts permissions on files, folders, and registry keys.


    Download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click onresetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.

    Okay now press the Windows key and the R key at the same time to bring up the Run box. Type in regedit and hit OK.
    • Then in the Registry Editor click File, Import.
    • Navigate your way to the C:\MGtools folder and locate the fixW7BFE.reg key and select it.
    • Then click the Open button and allow this to be added into your registry
    Tell me what happend exactly. Like do you get any error messages or do you get a success message?

    If you received a success message then repeat the above import but with below to files from the MGtools folder.
    • fixW7FW.reg
    • FixW7FWdrv.reg
    Wherther the imports work or not, now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  9. mikehurv

    mikehurv Private E-2

    I get an error in the registry editor. It says

    "cannot import c://mgtools/fixw7bfe.reg error accessing the registry"
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the resetperm-x64.cmd as requested? Did you notice it popup a window and take 10 min or so to run? Did you reboot afterwards?

    If yes to all the above questions, just do all 3 registry imports anyway even if you get errors. The get the new MGlogs.zip file
     
  11. mikehurv

    mikehurv Private E-2

    I ran resetperm-x64.cmd using run as administrator. The black command box opened up for less than a second and disappeared. I let the computer sit for about 15 minutes, but it didn't appear that anything was running or anything was happening. I restarted and tried to edit the registry and it says can't import the file, there is an error accessing the registry.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry, that's my fault. I forgot to give you the correct version of resetperm. You are not running a 64bit version of Windows. Please run the below version

    resetperm.cmd

    Then make sure you reboot your PC.

    Then rerun the registry patches and no matter what errors you get, import all three registy patches.

    Then reboot your PC one more time. After this run the C:\MGtools\GetLogs.bat file as requested and attach the new MGlogs.zip file.
     
  13. mikehurv

    mikehurv Private E-2

    I ran resetperm and it went for about 10 minutes. Then the black box closed. I restarted my computer and was able to import

    fixW7BFE.reg and fixW7FW.reg

    but when I try to import FixW7FWdrv.reg I get the error - cannot import c:/mgtools/fixwdrv.reg: not all data was successfully written in the registry. Some keys are open by the system or other processes.
     
  14. mikehurv

    mikehurv Private E-2

    I restarted and here is the Mglogs zip file
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job. That has now fixed the BFE and MpsSvc services that were not running.

    Are you still having any malware type problems?
     
  16. mikehurv

    mikehurv Private E-2

    Everything seems good. Haven't had any redirects since I fixed it. Thanks so much
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds