video codec

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jrs40jas3, Sep 20, 2007.

  1. jrs40jas3

    jrs40jas3 Private E-2

    Recently got home from class to find "Windows Defender" up saying it detected a virus (W32 looksky) and also "W32/UltimateDefender" on my computer. I clicked remove and my computer decided to freeze up. I restarted it and ran McAfee and it came up with nothing?! I have also noticed in my remove programs list, the program "Video Access Codec v1.4" is there and i get an error message when i try to remove it (see below). I am running Windows Vista Home Premium. Any help would be greatly appreciated!!

    Error Message while trying to uninstall "Video Access Codec v1.4":

    "The installer you are trying to use is corrupted or incomplete.
    This could be the result of a damaged disk, a failed download or a virus.

    You may want to contact the author of this installer to obtain a new copy.

    It may be possible to skip this check using the /NCRC command line switch
    (NOT RECOMMENDED)."


    Also, here is a HijackThis log (see attached).



    Thanks!!
    Josh
     
    Last edited: Oct 11, 2007
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not rename HJT as per the instructions in the Read and Run First! Please do that.

    Counterspy will also work under Vista --- please use it!

    Turn off UAC and you can run ShowNew and GetRunKeys.

    you need to right click the Hijackthis/Analyze exe and Choose "Run as Administrator" if you haven't already.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please attach new logs for:
    ShowNew
    GetRun
    HJT
    Counterspy or AVG Anti-spyware
     
  3. jrs40jas3

    jrs40jas3 Private E-2

    Sorry bout that... kinda new to this forum. :)

    Here are the log files you requested.

    Thanks!!
    Josh
     
    Last edited: Oct 11, 2007
  4. jrs40jas3

    jrs40jas3 Private E-2

    Hjt Log...
     
    Last edited: Oct 11, 2007
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Clean out the temps....CCleaner:
    CCleaner ~ works, but its best to set the Privilege level on this app to Run as Adminstrator.

    You need to re-run counterspy and have it quarantine MyWebSearch!

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger

    Tell me if you had any problems running the above.
     
  6. jrs40jas3

    jrs40jas3 Private E-2

    TimW,

    Everything has worked so far... except for the avenger program. When I go to run it it brings up an error message that states...

    "Fatal error: unsupported version of Windows! This program will only run on Windows 2000 or XP." (see attached)

    Any Suggestions?

    -Josh
     
    Last edited: Oct 11, 2007
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry ...Vista compatibility is creating havoc for us with the malware removal.
    Let's try:
    Pocket KillBox
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    If this doesn't work in Vista ...(have you turned off UAC?) (and be sure to run it as Administrator - right click the exe and Choose "Run as Administrator)
    Then you may have to use explorer to find and delete them.
    Let me know.
     
  8. jrs40jas3

    jrs40jas3 Private E-2

    Did not recieve that message... here are the log files you requested eariler (minus avenger)

    -Josh
     
    Last edited: Oct 11, 2007
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are more than likely files for the Brother printer software that is installed. You should restore these from the C:\!Killbox folder.
     
  10. jrs40jas3

    jrs40jas3 Private E-2

    Ok... I have put those files back into the "C:/Windows" folder. Is there anything else that I need to run to get rid of any stray files or is this removal complete?

    Thanks!
    Josh
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have ViewPoint in your add/remove items.
    The fixes aren't working, so you need to turn off all your security software and try them again.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Quote:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    After clicking Fix, exit HJT.
     
  12. jrs40jas3

    jrs40jas3 Private E-2

    Ok the Viewpoint is out of the programs list. Here are the log files again. Let me know if you need anything else.

    Josh
     
    Last edited: Oct 11, 2007
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you still have windows defender installed - if so, I would uninstall it.
    You may uninstall Counterspy now.

    The two items in your HJT log are not critical (left overs) that may be fixed once both of the above are uninstalled. But again, they are not critical nor malware.

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  14. jrs40jas3

    jrs40jas3 Private E-2

    I have yet to figure out how to uninstall windows defender? I figured out how to disable it but not uninstall it.

    Also my laptop seems like it back to normal. I appreciate all of your help!! Keep up the great work!

    Thanks again!!

    Josh
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you usually have to stop it / disable it before you can uninstall it ...but it is not in your uninstall list. Is it in the uninstall list in CCleaner?

    We can kill it with this:
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

     
  16. jrs40jas3

    jrs40jas3 Private E-2

    I checked the CCleaner uninstall list and did not see it in there. I then added the registry key you provided. But if I go to the start menu and type in the search box "Windows Defender" It still shows up? Any suggestions?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Give the exact location.
     
  18. jrs40jas3

    jrs40jas3 Private E-2

    "%ProgramFiles%\Windows Defender\MsAsCui.exe"
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you right click and delete?

    HJT item to delete:
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
     
  20. jrs40jas3

    jrs40jas3 Private E-2

    Do i need to just delete that app file, or delete the whole "Windows Defender" folder out of the "Program Files" folder?
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First try deleting what is in the folder ...then the folder. If this doesn't work and you have already disabled it ..then you may have to reinstall and then try uninstalling.
     
  22. jrs40jas3

    jrs40jas3 Private E-2

    Ok I tried and it said I needed permission to? Also this came with vista... I did not install this myself. I really didnt know I had the program until it came up the other day... :D
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try right clicking the folder and choose "Run as Administrator" then try to delete it.
     
  24. jrs40jas3

    jrs40jas3 Private E-2

    Dont have that option...
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I keep forgetting that this is Vista ...forgive me ...it is probably okay under this new OS ...and like all Vista stuff, you could probably only uninstall after turning off UAC ...but again, it is really not that big an issue and may provide some protection for you.
     
  26. jrs40jas3

    jrs40jas3 Private E-2

    I appreciate it VERY much!! Thanks for all the help and keep up the good work!
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome....safe surfing!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds