Malware Removal Assistance Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by paulibsl, Sep 5, 2010.

  1. paulibsl

    paulibsl Private E-2

    Hi, new member. Need help. Have read and followed the Guide, but only after thinking I had removed the problems. History before following the Guide :
    I noted that my router was showing too much traffic when it should be quiet. Installed Colasoft Capsa 7 and found hundreds of emails pouring out of my machine. On 27 Aug I used Avira, TSS Killer, HijackThis and other tools to clean up. They noted a TR/Agent.78248.4 & NUIGG.SYS problem. Quarantined NUIGG.SYS but returns in C:\Windows\system32\drivers every restart. My XP Professional won't boot into safe mode (Blue Screen), so moved hard drive with C: to another PC as a seconardy drive and attempted clean up from there. NUIGG.SYS removed on other PC and various other finds. On returning drive to original PC all appears OK, no unexpected emails, no NUIGG.SYS and machine seems to behave OK.
    Decided time to virtualise PC using VMWare (recommended by a friend) and re-install machine, dipping back into VM when I need to use a particular application. I noted that the VMware executable fails to run unless I rename the executable first (later fails in installation though). This raised my suspicion that the problems I had had, may not be fully resolved. Hence, I have read and followed the Guide. All went well except ComboFix.
    ComboFix failed - Error: "Installation Failed" dialog and hidec.exe "Not enough quota is available to process this cmd".

    I would be grateful for any guidance to sort my PC out.

    Regards

    Paul
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing that niugg.sys existing in your logs. It looks like TDSSkiller resolved that issue. You do need to run CCleaner and make sure your temp files are cleaned out. What issues are you still having?
     
  3. paulibsl

    paulibsl Private E-2

    Tim

    I have run CCleaner as per Step 3 of the Guide against all user accounts.
    Issue remaining is that I can't run the VMWare executable without renaming it, and then when I rename it fails part way through installation. I suspect that something is parsing my executable name at launch and blocking it.

    Regards

    Paul
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, first off, it is a very bad idea to allow all users to have Admin. privileges!! You will need to run both SAS and MBAM on each user account. Then attach any logs that show infections with the name of the user account. The VMware issue may be something that needs posting in the software forum.
     
  5. paulibsl

    paulibsl Private E-2

    Thanks for spotting the admin rights (I wish I had noticed that :-o). Running SAS and MBAM. Will attach findings as recommended.
    Paul
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. I will be here.
     
  7. paulibsl

    paulibsl Private E-2

    Tim

    Ran SAS and MBAM from first of several other user accounts. 5 tracking cookies only. While MBAM running was away from machine for some hours. returned to see no errors but found PC running really slow. I found FixCamera.exe to be hogging CPU in both of two logged in accounts. Using Task Manager I ended both to enable use of PC. Used AntiVir and MBAM to directly scan the c:\Windows\FixCamera.exe file - each reported it OK. Tried Prevx but can't get it to load from start menu.
    While this was going on AntiVir popped up warning that c:\MGTools.exe had the TR/DropAgent cyeu Trojan, so I quarantined it.
    Any suggestions on what to do next?
    Paul
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are many reports on the internet ( including even ones from major AV companies ) saying this file is bad. However I suspect that it is related to WebCam software. Do you have a WebCam? It looks like it from your logs.

    False detection but it does not matter since you don't need the installer anymore.
     
  9. paulibsl

    paulibsl Private E-2

    Thanks for help so far. I completed running MBAM and SAS for all users on the machine. No new findings other than a few tracking cookies.

    I have run the machine over the past days and all seems well. I have taken a full XP Backup to a removable HD.

    Today I noticed in the Start->Programs menu an application highlighted (as in a new installation). I have not willingly installed anything today. The program is called 'GBalpha NDSMovie Converter V1.00'. Very suspicious.
    What do you recommend I do?
    Paul
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you didn't download it, uninstall it.
     
  11. paulibsl

    paulibsl Private E-2

    Tim

    I'm wary. If I haven't downloaded it, what did? Is it related to the virus problems I had? It doesn't have its own uninstall (and if it had would I trust it), should I use Add or Remove Programs or some other tool to uninstall?

    Paul
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it doesn't have an uninstaller it won't be in add/remove programs. Is it listed in CCLeaner? Is is only showing in your programs list? Can you not right click and delete it?
     
  13. paulibsl

    paulibsl Private E-2

    It appears in Add or Remove Programs. The Start->Programs entry is only the program, no uninstaller is listed there. CCleaner - Tools lists it and offers Run Uninstaller, Rename Entry and Delete Entry. Does Right click in Start-Programs on this new highlighted entry uninstall it or just remove the link to it?
    I think I'd like to remove it, but wouldn't want to use any code associated with it to uninstall it; rather use a method that doesn't involve using its code. I can imagine that if it is malicious then its author might set up uninstall code to cause more mischief.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and let CCLeaner run the uninstaller. Then run the registry part of CCLeaner ( making the backup when prompted) to clean out any leftovers.
     
  15. paulibsl

    paulibsl Private E-2

    Tim
    All complete as per recommendation.
    I'll look out for any recurrence.
    Thanks
    Paul
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds