Virus - won't let me run antivirus programs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SacerHik, Oct 22, 2011.

  1. SacerHik

    SacerHik Private E-2

    Got a virus & it shut down my antivirus program & wouldn't allow me to access any other one via Google. When I pasted the antivirus link directly in the web bar, it let me download & install but it kept shutting down as soon as the scan began.

    I read other threads and followed the basic instructions given. I followed each link that was related to my situation and eventually had to stop at Step 4 of Vista and Win 7 Malware Removal/Cleaning Procedure, link: http://forums.majorgeeks.com/showthread.php?t=139681 because my problem is still occurring. I ran into quite a bit of problems along the way and only were able to obtain logs from Combofix and Mgtools, not the other three. The virus wouldn't even let the scans get past the 1 minute mark before it closed it out.

    Few things to note: (1)Prior to running Combofix I wasn't able to save anything to the C: drive. It kept telling me I didn't have permission though I was running as Admin. so I just ran all programs from the desktop. (2) When I had problems with the installed version of superantispyware, I tried the portable version as instructed. I had to skip steps that I didn't see available on that version but I did all steps that were available (i.e. leaving just 3 noted boxes unchecked). The portable version got further than the first but when the scan started, the virus shut it down. The msg: “Windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the item” appeared when I tried to access it again. (3) Prior to following your instructions, I'd already tried to download malwarebytes without success. I tried it again when I got to that instructed step and I tried renaming it (which I hadn't done before). It updated normally and then shut down soon as the scan began. (4) Combofix was the only one that ran without interference. It even identified the virus, but I was away from my computer and came back just as the message went away requesting that I allow the system to reboot. I think it was named 'rootkits'. (5) I downloaded RootRepeal but wasn't able to run it only because I didn't know how to “Extract the RootRepeal.exe file from the RAR or ZIP”. I tried some things but nothing worked for me. I need further assistance on that, please! (6) MGTools ran and that log is attached. (7) And after doing everything, I don't think anything has changed because Microsoft Essentials is still in a 'at risk' state and it's denying me access when I try to hit the only button available to me which is "Start" to start the scan, I guess. It's telling me the service has stopped and everything is in scary red. (8) Oh and the only thing that I could run after being infected with the virus was Spybot which was already installed. It came back clean, but in reading some of the things that Combofix presented while running, it seemed that the virus had infiltrated that program too, which I didn't think was possible.

    Thanks for all help provided so far!!! The threads are great and broken down well! :)
     

    Attached Files:

    Last edited by a moderator: Oct 24, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. SacerHik

    SacerHik Private E-2

    Both logs attached!
    FYI, Kaspersky TDS found the virus but didn't neutralize/quarantine it.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Double click on the rootrpeal.rar (I saved it to my desktop) then you can gain access to the RootRepeal.exe which you can then slide out of the folder straight onto your desktop and run it. It will produce a log on your desktop. Attach that please. Note there is only a 50-50 chance of rootrepeal running. It does not run for me.

    Yes, you need to uninstall it. We can reinstall afterwards when we are sure all is well again. You also have AVG 2011 installed which you should also uninstall if you intend to re install Microsoft security essentials.
    Uninstall this too then please.


    Download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes). (How to attach items to your post)
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.


    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: [​IMG]
    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the [​IMG] button.
    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message as well as any other requested logs.


    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:4001


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:4001
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)

    After clicking Fix exit HJT.

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\0200~1 
    c:\windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
    Folder::
    c:\windows\$NtUninstallKB31099$
    c:\users\user\AppData\Local\3d73bbf7
    DirLook::
    C:\Windows\Temp1BEB6842-8E93-D8B0-1490-5646F09438E3-Signatures
    C:\Program Files\MBytes
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. SacerHik

    SacerHik Private E-2

    I uninstalled Spybot, got AVG removed fully (I think), and this time RootRepeal opened in notepad. I couldn't get it to actually "run". I felt like I was failing to do something simple. :banghead Never got that one going, though. Maybe I'm a part of the unlucky 50%??

    I downloaded Junction.zip and followed all instructions but the command prompt only flashed on my screen before closing out. The instructions didn’t say to run junction.exe (common sense?? Don’t count on that with me!!) but when command prompt didn't appear, I went to C:\junction.exe and opened it. That’s when I got the license agreement, but as soon as I clicked “ok”, the command prompt only flashed again. It still didn’t open. Could I have done something wrong? Fyi, here’s what I did to: “Unzip it and put junction.exe in the root folder (C:\junction.exe)”. I opened it and ended up just dragging the exe file to the root folder. :/ There was still a copy under junction.zip. I’m thinking error on my part but Idk. I tried the RUN action a few more times, same result.

    The Win32kDiag.txt, otl.txt, extras.txt, and mglogs.zip are all attached!

    After I followed all your instructions, I downloaded Microsoft Essentials again, and it actually was able to complete a scan! It removed a trojan (after a reboot) and as I type this, I'm running it again just to be sure. I also ran Kaspersky TDSSKiller again and no threat was found this time. Any chance the virus could still be hiding somewhere? How did it compromise Spybot? It just disabled my antivirus but took CONTROL of Spybot and gave me a clear scan like all was fine & dandy! That definitely makes me uneasy. And also, by following the READ & RUN instructions, I changed some things that I'm guessing I can change back. I know I need to change UAC back but should I undo the "configuring to view all hidden files"? Thanks for all your help on this so far. You've shown me that I'm even more clueless about this stuff than I thought!
     

    Attached Files:

  6. SacerHik

    SacerHik Private E-2

    Hi! I ran another scan through Microsoft Security Essentials and more viruses were removed. Yesterday, when MSE prompted me with a reboot, TrojanDropper.Win32/Sirefef.B was the virus it was trying to remove. When I ran another scan (Full scan this time. The first ran was Quick scan) TrojanDropper:Win32/Sirefef.B was removed again, so it was still on there. In addition to that, 6 more viruses were removed/disinfected: 2 called Virus:Win32/Patchload.O, Tojan:Win32/Sirefef.J, Backdoor:Win32/Smadow, Trojan:Win32/Sirefef.K, and Backdoor:Win32/Smadow.gen!B. You can probably obtain all that info from the logs, for all I know, but there it is just in case. I'm tempted to run it again to see what else comes up, but I'll just await further instruction from you.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh, I did not want you to reinstall it yet, I should have been more clear about that. Uninstall it again please and leave it uninstalled until I let you know. The thing is this infection you have is known to chew up antivirus, compromise it or otherwise break it.

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    Code:
    :otl
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    
    :files
    C:\Windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
    c:\program files\MBytes
    C:\Users\user\AppData\Local\3d73bbf7
    C:\0200~1
    C:\Windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
    c:\windows\$NtUninstallKB31099$
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now run OTL again like you did in post #4, and attach the log.

    Run Combofix again by double clicking on it (or right click and run as admin if on win7 or vista) attach the log please.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. SacerHik

    SacerHik Private E-2

    Sorry, I got a little ahead of myself! You asked how everything was running, and being unable to run my antivirus was the only indication that I had a problem. :innocent All 4 attachments are here. I uninstalled MSE, Fyi, but it did enable my firewall and I remembered to disable it again just after Combofix started running. Not sure if that messed anything up. Thanks!!!!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Users\user\AppData\Local\3d73bbf7
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Could you please get this: 0200~1 into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip
     
  10. SacerHik

    SacerHik Private E-2

    I wasn't able to put 0200~1 into a zip file. As soon as I pasted %systemdrive%\MGTools\zip "%systemdrive%\collect.zip" C:\0200~1 into "Run" and hit "ok" the window only flashed on my screen, same as last time. Combofix is attached.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please uninstall SUPERantispyware as it has been incorrectly installed. Reboot the machine and reinstall it which is the C:\Program Files folder. Now see if it, and Malware Bytes will run, and attach logs from each.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited by a moderator: Oct 29, 2011
  12. SacerHik

    SacerHik Private E-2

    SuperAntiSpyware won't fully uninstall. The exe file keeps telling me I need permission to perform the removal action and if I try to open the file, it says "Windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the item". I attempted to download it again under a diff name and was told I didn't have permission to save under c drive. Malwarebytes, avenger, and MgLogs all attached!
     

    Attached Files:

  13. SacerHik

    SacerHik Private E-2

    Oh and I am VERY sorry!! I kind of forgot to mention that I was substituting my computer name with "user" and it just dawned on me that when I was copying your text, you were assuming "user" was the name of my computer so I was asking the programs to delete a file that didn't exist. :-o I can't apologize enough for that! Something tells me that's the reason for all the extra downloads...
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    For removing SUPERantispyware:

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    Now reinstall MSSE and perform a full system scan with it and attach a log if possible.

    How are things running?
     
  15. SacerHik

    SacerHik Private E-2

    I installed Revo but SuperAntiSpyware isn't in Programs and Features & that's all it's showing me options for. Exe is showing up in c drive only. I installed MSE once again, ran a full scan, and nothing was found. I don't believe MSE has logs readily available. I've never seen the option to view one & in looking for it, I didn't find a location for them. Everything is running okay. The problem with being able to save things directly to c drive seems to be sporadic. Sometimes I can & sometimes I can't. I tried to save MSE there & was told I couldn't. Is the virus gone?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. SacerHik

    SacerHik Private E-2

    Log attached.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's see if we can manually remove what remains.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\SUPERAntiSpyware.exe
    • O20 - Winlogon Notify: !SASWinLogon - C:\SASWINLO.DLL (file missing)
    • O23 - Service: SAS Core Service (!SASCORE) - Unknown owner - C:\SASCORE.EXE (file missing)
    After clicking Fix exit HJT.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\Users\user\AppData\Roaming\SUPERAntiSpyware.com
    C:\ProgramData\SUPERAntiSpyware.com
    File::
    C:\SUPERAntiSpyware.exe
    C:\SASCTXMN.DLL
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Run CCleaner, not the registry section, just the cleaner itself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    Now reboot the machine. Will Superantispyware install properly now?
     
  19. SacerHik

    SacerHik Private E-2

    I have 2 zip files attached bc I didn't replace "user" in the 1st. Corrected it in the 2nd (01). I followed all instructions again, but instead of copying the entire text for the cfscript, I just copied:
    SuperAntiSpyware is still there after reboot. I tried to download again, it asked if I wanted to replace existing so I clicked yes, and the old version is still there, still inaccessible.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you downloaded and/or installed SUPERAntiSpyware again, please don't do that anymore unless requested. Uninstall it if you have reinstalled it and delete any files from it that you just downloaded. Then do the below.



    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. SacerHik

    SacerHik Private E-2

    That was at the end of the last post, so I did attempt to install it again, but it wasn't completed so I think we're good.

    MGlogs.zip attached and combofix.txt is included in that. As far as I know, everything is working well. Thanks for you guys' continued help on this!!
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Looks fine now.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. SacerHik

    SacerHik Private E-2

    Before I proceed with the uninstallations, I should probably tell you that the superantispyware.exe is still on here. Still not budging. When I read your post and saw you were initiating the "cool down" segment, I figured it was supposed to have been removed and/or working properly so in an effort to avoid having to ask for help again, I tried to find an uninstall tool myself and, and of COURSE it didn't work. I still can't open it or delete it. I understand the helpfulness of this program and you suggested keeping it, along with malwarebytes, but right now I just want to not see it anymore. This exe file is driving me up a wall. :crybaby
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try getting rid of those files from the improper installation into your root folder. Seems there may be some kind of permissions issue stopping the deletes.


    Now download The Avenger by Swandog46, and save it to your Desktop.

    See the download links under this icon [​IMG]
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Did that work?
     
  25. SacerHik

    SacerHik Private E-2

    It's gone! Finally! :celebrate Well, actually it's now in the Avenger folder. I'm assuming once I delete that, it'll delete right along with it. Please say it will! I'd already gotten rid of those other files so they came back Not Found. MGlogs.zip attached (including avenger log).
     

    Attached Files:

  26. SacerHik

    SacerHik Private E-2

    Hey! I started following the steps to remove all programs, and I ran into a few issues. First, in "programs & features" there is now a program: AVG 2011, that can't be accessed. Right clicking & double clicking does nothing. It did not show up in Revo Uninstaller when I tried to remove it using that. Not sure when it appeared but it wasn't there all along. I uninstalled Malwarebytes, with intention of reinstalling. In C:\Program Files, the folder is still there and can't be deleted. Same thing with C:\Program Files\Spybot - Search & Destroy, and C:\Program Files\Security Task Manager. Am I uninstalling these things wrong or something?
     
  27. SacerHik

    SacerHik Private E-2

    UPDATE: Ok, here's what I did. For the issue with AVG 2011 in Programs & Features, I used the Windows Install Clean Up & it worked. I used Avenger for Spybot, Security Task Manager, & Malwarebytes folders. I had to run it 2x since there was an issue with Security Task Manager. I didn't save the 1st log so when I ran it a 2nd time, it automatically replaced the 1st. The avenger log only shows the removal of STM and not the other two but all were removed. I used "Folders to delete:" and entered the path for each through C:\Program Files. I ran mgtools again and attached in case you want to take a look at it. Kind of late to ask, but is Avenger safe to use on my own in the way that I used it?
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably not! You are most likely suffering from residual damage caused by your infection that has changed various permissions on files and folders on your PC. There may be others that you find over a period of time. Instead of immediately resort to a program like Avenger, you should first attempt to fix the permissions/security settings and change the ownership to have full rights for your user account name. Try right clicking on some files and folders and selecting Properties and then the Security tab to see what I mean. ;)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No not really. If you happen to enter something incorrectly, you could make your PC unbootable and unfixable. But it is your PC, if you are willing to take the risk in using it without being an expert.


    You have a little more cleanup to do.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - (no file)
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - (no file)
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (file missing)

    After clicking Fix, exit HJT.


    Then you can repeat my previous final instructions if you are not having anymore problems.
     
  30. SacerHik

    SacerHik Private E-2

    No, definitely don't want that! I have no plans to use it again bc I probably WILL do something irreversible. It didn't work as I hoped anyway. The Spybot folder I deleted is now sitting in the Avenger folder & now I can't get rid of the Avenger folder. And I can't very well use the Avenger program to get rid of its own Avenger folder. I think it's best I stop while I'm ahead. Any add'l help on that would be awesome!

    I ran HJT as instructed.

    I tried changing permissions before letting you know the folders/files I was having problems with. After reading your post, I tried again. I tried changing them to full control directly in the Avenger folder and also in the root drive. It changed in the Avenger folder but still wouldn't allow me to delete it, and C drive gave me access denied. I'm not too concerned with permissions right now as long as the virus is gone. Things aren't really downloaded to this computer hard drive anyway. The permissions were just impeding the virus removal process....and presently, the removal of all these lagging files/folders. But out of curiosity, in case I am unable to restore permissions for whatever reason, is there something I can safely use to get rid of the stubborn files that I come across in the future?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below.


    [​IMG] Please download GrantPerms by Farbar to your desktop.
    • Open GrantPerms.zip and extract GrantPerms.exe to your desktop.
    • Run GrantPerms.exe by double-clicking on it. (Vista and Win7 right-click and select Run as administrator)
    • Copy the text in the below code box and paste it into the text-field available in GrantPerms.
      Code:
      C:\Avenger
    • Now click the Unlock button.
    • Click the OK button when you see Unlock operation completed.
    • Now click the List Permissions button.
      Note: Notepad will open afterwards. DO NOT EDIT THE INFORMATION INSIDE!
    • This Perms.txt log file is on your desktop.
    • Attach Perms.txt to your next message. (How to attach items to your post)
    Now also see if you can delete the C:\Avenger folder. If not, see if you can go down to the deepest entries in the folder/subfolders deleting them one at a time and working your way towards the top.
     
  32. SacerHik

    SacerHik Private E-2

    Hi! I uninstalled MGTools, and after I rebooted, the Avenger folder was gone. I had actually tried that b4, and it didn't work. Go figure. Anyway, a few days ago, I used a restore point for 1 day prior and ended up with Security Task Manager back on here. Once again, it wouldn't delete so, I used GrantPerms for that instead of Avenger. I have it attached.

    Is it ok to download Spybot again?
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if you wish to use it.

    Are you having anymore problems?
     
  34. SacerHik

    SacerHik Private E-2

    I think we're good to go! Thank you guys very much!! :wave
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds