MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Closed Thread
 
Thread Tools Display Modes
  #1  
Old 01-07-13, 16:18
MBG MBG is offline
Private E-2
 
Join Date: Jan 2013
Posts: 3
Thanks: 1
Thanked 0 Times in 0 Posts
Default Infected with System Progressive Protection

I was infected with System Progressive Protection the afternoon of January 2, 2013. I found some guidance on the web (using a different computer) and executed all their steps (similar to yours, but a smidge different), and was uncertain that I really cleaned all infection from computer. A friend who had communicated with you all before suggested that I work with you. I've gone through all your steps and am attaching logs to this post. Please confirm whether my computer is clean or if there is still work to be done. And thanks very much in advance. I cannot adequately express my gratitude!

My computer is 32-bit, Dell Vostro 230, running Windows 7 Professional, with 4.00 GB RAM (2.96 usable). Not sure what else is useful here other than I've been running in safemode with networking since I was infected.

Apologies in advance if the correct files are not attached.

Thanks again and best regards,
Melanie
Attached Files
File Type: log HitmanPro_20130107_1315.log (3.7 KB, 2 views)
File Type: txt mbam-log-2013-01-07 (12-15-54).txt (1.8 KB, 1 views)
File Type: zip MGlogs.zip (238.1 KB, 1 views)
File Type: txt RKreport[1]_S_01072013_02d1203.txt (1.8 KB, 2 views)
File Type: zip TDSSKiller.2.8.15.0_07.01.2013_12.37.54_log.zip (26.7 KB, 0 views)
Sponsored links
  #2  
Old 01-07-13, 18:38
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,328
Thanks: 1,044
Thanked 3,821 Times in 3,718 Posts
Default Re: Infected with System Progressive Protection

Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

Coupon Companion Plugin <--- Uninstall this.

Fix items using RogueKiller.

Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
When it opens, press the Scan button
Now click the Registry tab and locate this 1 detection.
  • [RUN][SUSP PATH] HKLM\[...]\Run : SearchProtection (C:\ProgramData\Search Protection\_run.bat) -> FOUND

Place a checkmark next to this item, leave the others unchecked.
Now press the Delete button.
When it is finished, there will be a log on your desktop called: RKreport[2].txt
Attach RKreport[2].txt to your next message. (How to attach)
Reboot the machine.


Delete these folders if they exist. Let me know if you have any problems.
  • C:\Users\MBG\AppData\Roaming\Catalina Marketing Corp
  • C:\Users\MBG\AppData\Roaming\DefaultTab
  • C:\Users\MBG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina Marketing Corp
  • C:\Program Files\Coupon Companion Plugin
  • C:\Program Files\Enigma Software Group

Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

Quote:
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"SearchProtection"=-
Make sure that you tell me if you receive a success message about adding the above
to the registry. If you do not get a success message, it definitely did not work.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
  #3  
Old 01-07-13, 19:55
MBG MBG is offline
Private E-2
 
Join Date: Jan 2013
Posts: 3
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Infected with System Progressive Protection

Thanks so much for your quick response!

I followed all steps you outlined.

One of the files listed wasn't there when I went to delete the files. (I'm sure it is insignificant to mention it, but want to be thorough!)

Received following success message when adding the new info to the registry: "The keys and values contained in C:\Users\MBG\Desktop\fixME.reg have been successfully added to the registry."

Two new logs attached.

Everything seemed to go OK; however, I think when I ran RogueKiller again there was a new entry different from when I ran it the first time--I'm assuming you'll be able to tell by the log.

Thank you again (really, cannot thank you enough for your time and expertise!)!

Best regards,
Melanie
Attached Files
File Type: zip MGlogs.zip (258.4 KB, 2 views)
File Type: txt RKreport[2]_D_01072013_02d1819.txt (2.4 KB, 2 views)
  #4  
Old 01-08-13, 13:41
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,328
Thanks: 1,044
Thanked 3,821 Times in 3,718 Posts
Default Re: Infected with System Progressive Protection

If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
  2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Press and hold the Windows key and then press the letter R on your keyboard. This opens the Run dialog box.
    • Copy and paste the below into the Run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
      • Notes: The space between the combofix" and the /uninstall, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
  3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
  4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
  5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
  7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
  8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning procedures pointed to by step 6 of the READ ME
      for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.
  10. After doing the above, you should work thru the below link:
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
The Following User Says Thank You to Kestrel13! For This Useful Post:
MBG (01-09-13)
  #5  
Old 01-09-13, 11:52
MBG MBG is offline
Private E-2
 
Join Date: Jan 2013
Posts: 3
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Infected with System Progressive Protection

Thank you so much for your assistance. It appears as though it's all good now. Really, cannot thank you enough!
Best regards,
Melanie
Sponsored links
  #6  
Old 01-09-13, 17:34
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,328
Thanks: 1,044
Thanked 3,821 Times in 3,718 Posts
Default Re: Infected with System Progressive Protection

Most welcome. Safe surfing!
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
System Progressive Protection gersh Malware Removal 1 12-31-12 07:55
google redirect ie sys progressive protection vingle Malware Removal 15 10-17-12 17:05
Infected WinXP 64-bit with "System Fix Virus" & "Privacy Protection Virus" (Malware) Chad Syphrett Malware Removal 1 12-16-11 10:31
Not infected! Just have a question about malware protection Pete22 Software 5 01-25-10 18:47
Infected Website protection...know of any? LauraR Software 24 07-12-09 08:37


All times are GMT -5. The time now is 16:19.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger