Can't Remove All Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by moyer24, Aug 10, 2010.

  1. moyer24

    moyer24 Private E-2

    I ran through the Read me, but was unable to run: Malware, or ComboFix.

    My computer will not load into safe mode, it just continues to restart itself when I hit the F8 key. Likewise, if I manually shut down and get the black screen with options, I can not run Malware or Combofix in safemode. That's one of my known problems, I am also forwarded to unknown websites when using google search enginge. I can't update any virus scans, like Trendmicro, it says there's no internet (but there is).

    I'm including my log from running Avira as well, as I was able to get that to run and it found quite a landmine.

    Thank you for taking the time to look these over, I really appreciate it.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We don't want them to be run in safe mode anyway, so try running them in normal boot mode which is what we want.

    The DNS infection you had is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.

    Do you have any disk emulation software running like Daemon Tools? We did request that this be disabled in step 6 of the READ & RUN ME. Your logs are showing signs of a possible Master Boot Record infection. If you did not disable disk emulation, it could be just a false detection but we will not know until you do this. If you did disable it then it may be a real infection or it could be that Daemon Tools did not disable it and we may need to forcefully delete it since it seems to never be able to be uninstalled properly ( poorly designed ).

    Uninstall the below old versions of software:
    Java(TM) 6 Update 20

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5643
    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)

    After clicking Fix, exit HJT.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. moyer24

    moyer24 Private E-2

    I reset my router. I did receive a success message after running fixme.reg Everything also seemed to go well with the Avenger.

    I did run the defrogger, but it is possible that one of the times I forgot to run it again after a reboot. Is there something that I should rerun specifically?

    I had the daemon tools uninstalled about a year ago, but I did notice there was a registry key for that in the MGTools file. I don't see any folders or program files for it, so how can I fully remove this software?

    I still am unable to load Malware or Combofix in regular mode.

    Likewise, when I boot my computer now, it flashes to black then the screen will have "Auto Detect (analog -) pop up each time, then the screen goes black, repeat 3-4 times. After that, it will eventually go to the windows sign, then the log in page.

    Google is no longer forwarding me to malware websites.

    Thank you for taking the time to help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will see if I can provide a fix.

    You need to be much more specific and describe exactly what happens when you try to run them. Also you need to make sure you shutdown both Avira and Zonealarm before trying to run them. I'm not sure why you say you cannot run Malwarebytes when your logs from MGtools show that you have run it multiple times:
    Code:
    "C:\Users\Deeds\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Jul 31 2010   920  "mbam-log-2010-07-31 (16-03-33).txt"
    Jul 31 2010   893  "mbam-log-2010-07-31 (20-05-11).txt"
    Jul 24 2010  3069  "mbam-log-2010-07-24 (12-22-03).txt"
    Jul 29 2010  1140  "mbam-log-2010-07-29 (13-33-51).txt"
    Jul 30 2010  1179  "mbam-log-2010-07-30 (22-14-33).txt"
    Jul 31 2010   895  "mbam-log-2010-07-31 (12-46-14).txt"
    This is due to some program you are loading at startup not malware. Possibly the below:

    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe



    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. moyer24

    moyer24 Private E-2

    I spoke too soon on the google forwarding, I am still being forwarded.

    At the end of July I thought I had a virus (same issues as now) and I had been able to run the Malware, I thought I had gotten rid of it, but then had a program "Ape" asked for internet permission through ZoneAlarm. I denied that, and then started going through the steps in the "Read Me First" post again, that's when I found that the malware and combo fix were no longer able to run.

    Now when I click on combofix a screen pops up asking me if I want to run it, I hit "Run" the mouse icon does a thinking rotation, then goes back to normal, and nothing loads. When I try malware bytes, same instance, it thinks like it will load, but never does.

    I have firealarm, and virus protection turned off when I try to run these programs.

    I'm still unable to boot into safemode, which I just checked to see if it was solved, not to run the malware programs with.



    Running the fixme.reg I received this error message:
    "Cannot import C:\Users\Deeds\Desktop\fixme.reg: Not all data was successfully written to the registry. Some keys are open by the system or other processes. "

    I had all windows closed, zone alarm/virus protection turned off when I tried running the fixme.



    I ran avenger, and the got an error while trying to reboot. Vista started in repair mode, and then the computer did boot.

    So all the same problems still, google forwarding, no safe mode, not able to run malware/combo fix.



    For the Auto-Detect analog, is this something to be concerned over? I removed the Digital Line as I didn't have a use for it, and it didn't stop the flickering.

    Thank you for your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you said you reset the router, what exactly do you mean. If you just meant a power cycle/reboot, that is not what I was suggesting.

    What browsers get redirected? Test more than one.

    Please attach the logs I listed so I can see what was found in those scans.

    See if SUPERAntispyware can repair it. Run it and click Preferences and then the Repairs tab. Then scroll down to Repair broken SafeBoot key and select it then click Perform Repair ...

    If that does not work you will have to post about this in the Software Forum as you may need to run a repair on Windows itself.


    Okay I misunderstood your message since you did not post everything that is in the popup. You left off some key info especially the fact that it is Auto Detect (analog input) which means you have a hardware issue between your PC and your monitor.
    The analog input is the VGA input. If the signal cannot be found by your monitor you will see this message. Since it does work later, it seems to just be taken some length of time before the signal is being found. You will need to post about this in the Hardware Forum or just live with it. If you do a google search on that message, you will see that lots of Dell PC owners have seen this message.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds