MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 04-09-09, 16:41
jaredberaj jaredberaj is offline
Private E-2
 
Join Date: Mar 2009
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Default Need help removing MalWare that won't let me open Ad-aware

Hi, I'm getting random Internet Explorer windows opening and whenever I try opening the newer versions of Ad-Aware nothing happens, I can only open older versions (but I can't update them with the new virus detection databases). There was an error message style pop-up that said click ok to get the latest version of WinWeb. I searched the forums and found someone else that had a similar problem, but the process that helped him out said to end processes through hijackthis that I don't have. Any help would be greatly appreciated, thanks. Here's my hijackthis log:

Last edited by Corporal Punishment; 04-12-09 at 04:26.. Reason: remove inline log
Reply With Quote
Sponsored links
  #2  
Old 04-12-09, 04:26
Corporal Punishment's Avatar
Corporal Punishment Corporal Punishment is offline
 
Join Date: Jan 2002
Posts: 1,985
Thanks: 14
Thanked 91 Times in 56 Posts
Default Re: Need help removing MalWare that won't let me open Ad-aware

Please begin by clicking Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
  • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
  • Then search forTDSSserv.sys
  • Let me know if you find this or not.
  • If you do find it, right click on it, and select Disable. Do not try to uninstall it.
  • Also if TDSSserv.sys is found and you disable it, then reboot.
  • After reboot continue on with the below cleaning instructions.

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.
  • If something does not run, write down the info to explain to us later but keep on going.
  • Do not assume that because one step does not work that they all will not.
Notes:
  1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
  2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
__________________
Beware of Geeks bearing .gif's.
Reply With Quote
  #3  
Old 04-12-09, 22:07
jaredberaj jaredberaj is offline
Private E-2
 
Join Date: Mar 2009
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Need help removing MalWare that won't let me open Ad-aware

Thanks for the reply, I couldn't locate TDSSserv.sys. I've attached some logs that might show something. Thanks again, talk to you soon hopefully.
Attached Files
File Type: txt ComboFix.txt (20.3 KB, 2 views)
File Type: txt mbam-log-2009-04-12 (21-55-33).txt (1.9 KB, 1 views)
File Type: zip MGlogs.zip (91.9 KB, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 04-12-2009 - 21-05-40.log (465 Bytes, 1 views)
Reply With Quote
  #4  
Old 04-16-09, 00:20
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 79,717
Thanks: 61
Thanked 7,420 Times in 3,971 Posts
Default Re: Need help removing MalWare that won't let me open Ad-aware

In my instructions below, we will be deleting log files that you extracted from the MGlogs.zip file into the C:\ root folder. Please do not extract these files here. It is unnecessary. They are already in the C:\Mgtools folder in extracted form if you really feel you need to look at them.

Uninstall the below old versions of software:
J2SE Runtime Environment 5.0 Update 4
Java(TM) 6 Update 11
Spybot - Search & Destroy 1.4

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O20 - Winlogon Notify: b8861cb6573 - C:\WINDOWS\
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

After clicking Fix, exit HJT.


Now we need to use ComboFix to remove a bunch of malware files.
  • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
  • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
  • Open Notepad and copy/paste the text in the below quote box into it:
Quote:
KILLALL::

Driver::
npggsvc

DirLook::
C:\Documents and Settings\Administrator\Local Settings\Application Data\{A9C5E954-DFB4-4F4C-BED9-DFC4164BD6DF}

File::
C:\procdll.txt
C:\hijackthis.log
C:\ffdata.txt
C:\UserInfo.txt
C:\newfiles.txt
C:\runkeys.txt
C:\GetUnKey.txt
C:\WINDOWS\Hbacalanahifu.bin
C:\WINDOWS\Lgorewa.dat
C:\WINDOWS\system32\GbFc4Gn.vbs

Folder::
C:\Program Files\AskSearch
C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
  • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
  • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
  • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
  • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
  • Follow the prompts.
  • When it finishes, a log will be produced named c:\combofix.txt
  • I will ask for this log below
Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.


After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

Now run Ccleaner to clean out only temp files and nothing else!

Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


Now attach the below log:
  • C:\ComboFix.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #5  
Old 04-17-09, 10:48
jaredberaj jaredberaj is offline
Private E-2
 
Join Date: Mar 2009
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Need help removing MalWare that won't let me open Ad-aware

Hey thanks for the reply, when I ran ComboFix.exe with SCscript.txt I just got a blue screen. I continued through the rest of the instructions though. No ComboFix.txt log was created, but I attached MGTools script and a screenshot of what appeared when I tried to run ComboFix.
Attached Images
File Type: jpg Clipboard01.jpg (57.6 KB, 3 views)
Attached Files
File Type: zip MGlogs.zip (100.2 KB, 2 views)
Reply With Quote
Sponsored links
  #6  
Old 04-20-09, 20:43
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 79,717
Thanks: 61
Thanked 7,420 Times in 3,971 Posts
Default Re: Need help removing MalWare that won't let me open Ad-aware

Since ComboFix did not run (possibly due to your protection software still running) we will have to use a different method.



Now download The Avenger by Swandog46, and save it to your Desktop.
  • Extract avenger.exe from the Zip file and save it to your desktop
  • Run avenger.exe by double-clicking on it.
  • Do not change any check box options!!
  • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
Quote:
Driversto delete:
npggsvc

Files to delete:
C:\procdll.txt
C:\hijackthis.log
C:\ffdata.txt
C:\UserInfo.txt
C:\newfiles.txt
C:\runkeys.txt
C:\GetUnKey.txt
C:\WINDOWS\Hbacalanahifu.bin
C:\WINDOWS\Lgorewa.dat
C:\WINDOWS\system32\GbFc4Gn.vbs
C:\WINDOWS\system32\GameMon.des.exe

Folders to delete:
C:\Program Files\AskSearch
C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP

Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}

  • Now click the Execute button.
  • Click Yes to the prompt to confirm you want to execute.
  • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
  • Your PC should reboot, if not, reboot it yourself.
  • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
Now run Ccleaner to clean out only temp files and nothing else!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



Then attach the below logs:
  • C:\avenger.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
STOP 24 after removing malware and malware removal apps. hankyknot Hardware 0 02-19-09 09:21
unable to run any anti-malware tools and also cant open any anit-malware related site kallam238 Malware Removal 6 01-21-09 15:07
Help removing malware hindtm Malware Removal 11 11-29-07 10:04
Need help removing malware PinkStars Malware Removal 15 11-21-07 02:08
Help removing Malware KenB2014 Malware Removal 12 02-04-06 10:52


All times are GMT -5. The time now is 09:41.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger