I have a problem.....

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lollyde, Jul 24, 2008.

  1. Lollyde

    Lollyde Private E-2

    I was starting to run your malware removal guide and screwed up by not renaming MalwareBytes program before downloading, so now my computer detects it as a virus or spyware. I tried to delete it, rename it etc, nothing works and it keeps shutting down my F-Secure anti-virus.

    I have now run your Malware Removal Guide in it's entirity and have some logs for you when you are ready. I downloaded a fresh MalwareBytes program, and renamed it, for this procedure. However the original MalwareBytes file, mbam.setup.exe is still causing a problem so I really need to figure out how to get rid of it. When I try to delete it, it says access is denied. I am using my main administrator account.

    Then when I ran Combo-Fix it let me know that THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! What??? How do I fix that??

    My brain is fried after running all of these programs so I'm not sure which end is up or what to do next. Please advise. :(
    Lauren
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't recall the guide telling you to rename MalwareBytes ...and certainly not before downloading. We do ask you to rename ComboFix after downloading to your desktop before running it.

    However, I need to see the logs from
    SAS
    ComboFix ----this you should disable your F-secure program before running.
    MWB's ---if you got it to run.
    MGLOgs.zip --> after running the MGTools.exe
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does Tim (in two locations ;) ). Changed on 7/16/2008 to have the installer renamed to mb.exe because new malware was recognizing the real installer and blocking it from being run. I will be doing the same for SUPERAntiSpyware soon since we have been seeing similar issues with malware stopping it from installing. We may need to also rename the executables that are used for running the actual scans too since malware often stops those too (just like ComboFix).
     
  4. Lollyde

    Lollyde Private E-2

    Ok, SAS and Spybot S & D found no problems.
    Here are the logs for the other three programs.

    By the way, this is my secondary computer. My main computer is fine.

    Thanks so much,
    Lauren
     

    Attached Files:

    Last edited: Jul 25, 2008
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to re-run MWB's and have it fix anything it finds. Please attach a new log from that as well as a new MGLogs.zip from running the C:\MGtools\GetLogs.bat file by double clicking on it.
     
  6. Lollyde

    Lollyde Private E-2

    I ran MWB and had it use FileAssassin on the original mbam.setup.exe file that was causing me the problem. It worked - yeah!!!!!!!!!!!

    The MWB does however have three files in quarantine from the very first time I ran it. Two of the files are in the registry, so I didn't know what to do with these.

    Here are the files you asked for:
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What malware problems are you currently having?
     
  8. Lollyde

    Lollyde Private E-2

    All of the malware problems have been fixed by running the programs in your Malware Removal Program. Thanks.

    The only remaining questions are:

    1. What do I do with the three items in quarantine in the MWB program. Do I delete them or what?

    2. Then when I ran Combo-Fix it let me know that THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! What??? How do I fix that??
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you can delete the quarantined items.

    You can get instructions on installing the recovery console HERE.

    If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.

    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:

    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  10. Lollyde

    Lollyde Private E-2

    Thank you so much Tim. I really appreciate all your time and help!!!
    Lauren:)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds