Malware Removal Issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JustinR123, May 13, 2011.

  1. JustinR123

    JustinR123 Private E-2

    Hello

    So I am infected with some kind of malware and I cannot seem to get rid of it.Basically I was searching some reference images through google image search and I clicked on an image which took me to a page that just popped up all this stuff and it installed a bunch of things like Facemood Tools, Anti-Malware Doctor.

    I have run every program I can think of but it just doesn't go away.Basically what it is doing is popping up another tab that leads to some kind of ad page.I have done certain things like uninstall Facemood tools from firefox and all that.Also I have run CCleaner and all that

    Other issues this is presenting is on startup it loads up but sits on a blank screen and will not load explorer unless I go into the task manager and shut down the explorer.exe and then run it even then it takes ages to start.It also starts disabling Services.It always starts with the audio then eventually things on the desktop won't load when clicked and eventually it gets to the point where I can't even shut down the PC unless i reset or manually turn it off.I get pop ups saying Generic Host Process for Win32Seriveces has encountered an error.If I go into Services.msc and turn the audio back on it just removes it again.


    Here are my logs and info

    Operating system: Windows XP
    Browser: Mozilla Firefox
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Did you not run Malwarebytes' and MGTools.exe per the R & R ME FIRST guide's instructions? I need those logs.

    Also, run the below:

    TDSSkiller - How to run
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is attached. You meant SUPERAntiSpyware. ;)

    However do note that Malwarebytes is extremely out of date!!!!!!!
     
  4. JustinR123

    JustinR123 Private E-2

    Thanks for the help.The Malwarebytes log is posted below ive run it again and attached it again to this post as well as the MG tools zip and TDSS and I have also added the Superspyware log as well i apologize.EDIT* ok all attached it should be up to date
     

    Attached Files:

    Last edited: May 13, 2011
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Thanks, chas!

    @ JustinR123 -

    EDIT: Requested logs have been attached

    Please allow me time to review your logs.

    dr.m
     
    Last edited: May 13, 2011
  6. JustinR123

    JustinR123 Private E-2

    I ran the programs again within safe mode after doing the last steps you had given me and the problem seems to be gone now.My computer is running properly, the little shield icon that was coming up is gone, the internet pages aren't loading any ads anymore and its been booting fine.I have been using it for more than 2 hours and I have had no issues where as before it was happening within 20 minutes.

    I think the problem has been removed and all the scanners aren't picking up anything anymore which is a good sign.So for now I will say it is fixed and I appreciate all the help I am sure there is others as well who have issues and for now I don't think my issue is an issue anymore.

    Again I appreciate the help and will give thanks

    Justin
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, JustinR123

    This is why forums like this request additional logs - there is more work to do besides what the scanners removed! ;)

    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\Administrator\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    * You need to read this stickie thread:
    Warning about Porn, Keygens, Cracks, and other Illegal Software

    Before we begin, please use MSconfig to reset your system into "Normal Startup Mode" and no longer use it to control your Startups.

    Please disable Spybot's TeaTimer as instructed in the R & R ME FIRST guide.
    How to disable Spybot's TeaTimer

    This is not where you were instructed to save MGtools.exe.
    Please move it directly onto your desktop - not in a folder.

    Step 1:
    You MUST perform Step 6: of the R & R ME FIRST guide and " Disable Any Disk Emulation Software (like Daemon Tools..etc)" before proceeding with the rest of my instructions which follow.

    Step 2:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 3:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4 :
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Now install the latest Sun Java Runtime Environment

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited: May 15, 2011

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds