Request help with malware, have done all steps

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by limigator, Oct 16, 2014.

  1. limigator

    limigator Private E-2

    It is apparent to me that my computer is infected. I went through all the steps in the Read This First thread and my logs are attached. Also, a couple of weeks ago, I updated/upgraded my Adaware software and now it pops up all the time telling me to buy the software. I am also unable to close it from the tray at the bottom of the screen whereas I used to be able to disable it. After running TDSS Killer, I noticed my computer is infected. I did as the instructions said and did not attempt to remove at that time, but I definitely have something going on with my computer. I have screens that will pop up with a voice telling me to upgrade or purchase something.
    Thank you for your help!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What makes you think that? Did TDSSKiller report something as being infected? :confused

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Can you see this file to delete it?
    • C:\ProgramData\SPL848.tmp

    I really do think the adaware issues are going to be topic for the software forum.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. limigator

    limigator Private E-2

    Thank you for the quick response. I thought TDSSKiller detected a threat because it gave me the option to remove the items listed (I didn't as per the instructions).
    I put the machine back into normal startup mode as you instructed.
    I also was able to successfully merge the text in bold into the registry and received a success message.
    I was able to find and delete the file C:\ProgramData\SPL848.tmp.
    I ran the C:\MGtools\GetLogs.bat file and have attached the zip file that it created.

    Thank you again for your help, it is greatly appreciated!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    MGlogs.zip did not attach. :(
     
  5. limigator

    limigator Private E-2

    Sorry about that!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Any issues now apart from adaware? :)
     
  7. limigator

    limigator Private E-2

    I cannot use windows update. I keep getting an error code, 80070422, which, according to the link for that code, could be a virus that is not allowing it to update. And I still have the Adaware issue. Do you think my machine is infected?
    Thank you again Kestrel!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would say no to the machine being infected. Are any of the adaware products you are using paid for, or are they all free?

    Let's try this for Windows Update. It takes a long time to run so go off and do something else for a while.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.
     
  9. limigator

    limigator Private E-2

    I have always had the free Adaware products. I am downloading Windows repair now. Should I reverse the initial steps I did before, such as the UAC controls and selective startup?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should be in normal start up. And yes, disable UAC. You could be looking at an uninstall/reinstall of adaware products then...
     
  11. limigator

    limigator Private E-2

    OK, I ran Windows repair and was finally able to uninstall AdAware. How do I check to see if my firewall is running correctly? I am using Microsoft Security Essentials. Also, I am in full startup mode and my computer is super slow because of all the apps that start up now. How do I put it back in selective startup or is is ok to do so at this point?
    Thank you!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should always be in normal mode. Any other mode is primarily for troubleshooting and diagnostic purposes. You should be using a third party software to control what starts up or not.

    Do this for now:

    run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. limigator

    limigator Private E-2

    Is there any way to reduce the programs that open when starting the computer? My computer is very slow because of all the programs starting. I was able to update windows finally. Windows firewall is turned on but I am not able to turn on Windows Defender. Each time I get an error message saying "Windows Defender encountered an error: 0x800106ba. A problem caused this program's service to stop."
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are using Microsoft Security Essentials, then you do not need Windows Defender. But if need be you can ask about this in the software forum.

    Again, not really topic for this forum here, but I will see what I can do about improving your start up. Here is a good start up controller for future use. (Never use MSCONFIG)



    Now, let's do what we can here to speed things up a little hopefully....



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    • O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    • O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    • O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    • O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
    • O4 - HKLM\..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
    • O4 - HKLM\..\Run: [ScanSnap OnlineUpdate Watcher] "C:\Program Files\PFU\ScanSnap\Update\SsUWatcher.exe" -StartOS
    • O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
    • O4 - HKLM\..\Run: [lxeamon.exe] "C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe"
    • O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
    • O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    • O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark S300-S400 Series\ezprint.exe"
    • O4 - HKLM\..\Run: [EmbassySecurityCheck] "C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe"
    • O4 - HKLM\..\Run: [DellControlPoint] "C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe"
    • O4 - HKLM\..\Run: [DellConnectionManager] "C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe"
    • O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    • O4 - HKLM\..\Run: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
    • O4 - HKCU\..\Run: [HP Photosmart 6520 series (NET)] "C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe" -deviceID "TH45U5805205XP:NW" -scfn "HP Photosmart 6520 series (NET)" -AutoStart 1
    • O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
    • O4 - HKCU\..\Run: [SkyDrive] "C:\Users\boswelll\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
    • O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
    • O4 - Startup: Dropbox.lnk = boswelll\AppData\Roaming\Dropbox\bin\Dropbox.exe
    • O4 - Startup: Monitor Ink Alerts - HP Photosmart 6520 series (Network).lnk = ?
    • O4 - Global Startup: CardMinder Viewer.lnk = C:\Program Files\PFU\ScanSnap\CardMinder\CardLauncher.exe
    • O4 - Global Startup: Conversion to PDF with ScanSnap Organizer.lnk = C:\Program Files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe
    • O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    • O4 - Global Startup: ScanSnap Manager.lnk = C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe

    After clicking Fix exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  15. limigator

    limigator Private E-2

    Thank you Kestrel. I did the steps you advised and am posting the MGlogs file. I have not restarted my computer since running the Hijack This fix but already it seems a bit faster. I tried to install the startup control panel but the folder was empty after it installed.
    Thank you again for all your help!
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :)

    Ready for final steps?
     
  17. limigator

    limigator Private E-2

    Great, that is good news, I am ready for my final orders! :)
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds