SuperAntiSpyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bishar, Dec 16, 2008.

  1. Bishar

    Bishar Private E-2

    When I try to run the SuperAntiSpyware application in the Malware removal procedure it gives me a error message as follows

    SuperAntiSpyware Application has encountered a problem and needs to close We are sorry for the inconvenience.

    Can somebody help me resolve this before I continue with the Malware removal process.

    Thank you
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MAjor Geeks!

    Just skip it for now and continue. Try it again, after running Spybot, Malwarebytes and ComboFix. Then no matter what, move on to MGtools and then attach whichever logs you were able to obtain.
     
  3. Bishar

    Bishar Private E-2

    When I run spybot this is the error
    setup is now downloading additional files
    fileupdallocater.php (1 of 1)
    status connecting to 127.0.0.1

    Then a popup saying A connection to the server could not be established

    Cannot run Malwarebytes or combofix

    The only file i got is when I ran MGtools and it is attached.

    I cannot connect to this site from my infected computer

    Pleas help
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple AV programs installed. First instruction in the READ ME ask you to uninstall all but one . You must do this now!!

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search for TDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to do the below which was also requested in step 1 of the READ & RUN ME.

    Uninstall the below software:
    Java 2 Runtime Environment Standard Edition v1.3.1_06
    Viewpoint Media Player (Remove Only)

    Then reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  6. Bishar

    Bishar Private E-2

    I apologize but I thought I deid everything in step one. I disabled TDSSserv.sys as you said and currently Super antispyware is running. After that I will do the Java steps and then run the other, Spybot, etc. Thank you
     
  7. Bishar

    Bishar Private E-2

    When I rebooted after disabling TDSSserv.sys the avast antivirus gave me two warnings which I moved to chest, 1) TDSSXFUM.dll and 2) TDSSMHCT.SYS.

    Super Antispyware said no harmful elements detected.

    Spybot gives me the same error message as below
    setup is now downloading additional files
    fileupdallocater.php (1 of 1)
    status connecting to 127.0.0.1

    Then a popup saying A connection to the server could not be established

    I have attached the Malware log file

    When running combofix I get this message
    Following files are attempting to attach to combofix
    C;|Programfiles\commonfiles\Logitech\LVMVFM\LVPrcInj.dll
    I have attached combofix.txt
     

    Attached Files:

  8. Bishar

    Bishar Private E-2

    Chas

    Also attached is the MGtools Log file after running all the programs, combofix, malware.

    Thanks for all your help

    Bishar
     

    Attached Files:

  9. Bishar

    Bishar Private E-2

    Can someone tell me what the logs I have attached in my earlire threads reveal and also why spybot won't run.
     
  10. Bishar

    Bishar Private E-2

    I have had no replies from any of the helpers after I attached my logs in my earlier e-mails. Can someone please look at the logs and tell me how to proceed so I can get rid of the computer problems I was having.

    Thank you.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes be because you constanly keep bumping your posts. Have you read the below sticky thread?

    Don't Bump! It Only Hurts You!!!

    You Malwarebytes log shows that you took no action. Please run it again (make sure you update before scanning) and this time make sure you fix anything found before saving the log. Then attach the new log. We need to be sure everything was fixed.

    Also please attach the SUPERAntiSpyware log. As requested in the READ & RUN ME, we want to see them even if nothing was found to verify correct versions are being run.

    What is the below link on you Desktop? Delete it if unknown. If known, I suggest giving it a useful non-malware looking name.
    "C:\Documents and Settings\All Users\Desktop\"
    2hjjfb~1.lnk Dec 2 2006 1644 "2hjjfbnfggdkjgk.lnk"

    Need to delete the below files if found. Let me know what you find.
    C:\WINDOWS\system32\av.exe
    C:\WINDOWS\system32\getwn32.dll
    C:\WINDOWS\system32\av.dat

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • first log from SUPERAntiSpyware
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 18, 2008
  12. Bishar

    Bishar Private E-2

    I apologize, this is my first time using this service and I did not know about bumping.

    The 2h... was an icon for my webcam, I didnot find any of the winows\system files you mentioned.

    I ran malware and anitspy both logfiles are attached

    When running combofix I get this message
    Following files are attempting to attach to combofix
    C;|Programfiles\commonfiles\Logitech\LVMVFM\LVPrcInj.dll

    I have attached all the files you
     

    Attached Files:

  13. Bishar

    Bishar Private E-2

    Attached is the mglog.zip
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not update SUPERAntiSpyware and Malwarebytes as I requested. You need to update them first and then run new scans. Then attach the new logs.
     
  15. Bishar

    Bishar Private E-2

    Please bare with me I will get it right. Attached is the antispyware and malware logs after the update. I am in the process of getting the other logs. Thank you
     

    Attached Files:

  16. Bishar

    Bishar Private E-2

    Combo fix gives me the same message

    When running combofix I get this message
    Following files are attempting to attach to combofix
    C;|Programfiles\commonfiles\Logitech\LVMVFM\LVPrcInj.dll

    Mgtools gave me this message

    application failed to initialize properly (0x0000135).

    Both logs are attached
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is just due to an improperly designed program from Logitech. They should not be trying to hook into every program that runs.

    This error message was explained in the Using MGtools link in the READ & RUN ME. You do not have the Microsoft .NET Framework software installed.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  18. Bishar

    Bishar Private E-2

    Currently I am not able to complete the final steps as I am away. It is good to know that all my logs were clean. You had asked me to disable tdsserv.dll in your very first reply do I go back and re-enable it? Also do I do I still run my system on normal mode?

    Lastly, I want to thank you for your help and patience. You have a Merry Christmas and Happy New Year.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is malware and should not even be there. Does it still show now?

    Yes. See step 1 of the READ & RUN ME and the link given.


    You're welcome. Surf safely and enjoy your holiday season malware free. ;)
     
  20. Bishar

    Bishar Private E-2

    I'm back at my computer and am trying to do the final steps as mentioned. One problem I have is trying to delete combofix. It is located in my root directory and not on my desktop. How should I proceed. Thank you.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Put it on your Desktop as the instructions originally requested.
     
  22. Bishar

    Bishar Private E-2

    Put it on my desktop and uninstalled it. I am still confused about "normal mode". When I started the malaware removal process you told me to run my pc in normal mode. Do I still leave it like that. Thanks
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is what normal mode is for. It is the mode you should "normally" be running in. ;) You should not be using MSconfig for anything other then temporary debugging as stated in the info given in step 1 of the READ & RUN ME.
     
  24. Bishar

    Bishar Private E-2

    I do not know if I did the lats step about the restore system points correctly. I think I followed the steps listed in the read me file. Is there someway to check if I did this right.

    I have a Wireless G router and on checking it tells me that my firewall settings are low. Is this okay? Inot how do I make necessary changes.

    I have down loaded the armor protection software firewall. Will it automatically disable the firewall in windows and how do I check.

    Thank you for your patience and help.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only you would know. If you followed the instructions as written then everything would be correct.

    Every piece of hardware is different. Thus I have no idea what your router means by this. If it has other choices like medium or high, medium may be more correct.


    Yes it should automatically disable the Windows firewall. You can check by running Control Panel and selecting Windows Firewall. If it is not disabled then disable it.
     
  26. Bishar

    Bishar Private E-2

    I think I finished with the Malaware removal process. Now my DVD drive does not work properly. When I put in a DVD or CD it does not automatically open. Also, when I try ejecting the cd my computer locks up and then an error pops up saying Kernel_data_input_error. starting memory dump.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Autorun may have been disabled along the way but this is a good idea anyway since many new infections make use of autorun to infect thousands of PCs each week. The last step in the How to protect yourself from malware even mentions disabling autorun. You should read that and the Microsoft link given.

    I suggest that you post the exact word for word message in the Hardware Forum as this in not a malware problem.
     
  28. Bishar

    Bishar Private E-2

    I installed online armor but whenever I try to access any web site it does not allow me to do so. The online armor icon (sheild) at the bottom right of the tool bar pops up with c:\Metamail Inc\Metamail Reader\MMviewer.exe is blocked. I then diable online armor and it allows me to connect to web sites. What should I do?

    Thank you.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Whenever you install any firewall, you have to approve whichever applications and websites you want to allow to have access. If you have blocked them, then you will not be allowed access. You need to read the instructions for the firewall and be more careful. This is not a malware problem. You should ask questions about software in the Software Forum.
     
  30. Bishar

    Bishar Private E-2

    I recentlyscanned my computer using Malwarebyte and Superantispyware. I have attached the logs. Please let me know if I am Malware free.

    Also, I have MSN messenger and Yahoo messenger which load up whenever I start my computer. How can I disable them from loading on startup.

    Thank you.
     

    Attached Files:

    Last edited: Mar 7, 2009
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We cannot tell you anything other than they did not find anything and that you are our of date with Malwarebytes. If you want to know if your PC is clean, standard procedures must be followed and that is to run all of the READ & RUN ME.

    Post this in the Software Forum. Also step 1 of the READ & RUN ME gives you this Dealing with Startup Processes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds