Hy Geeks

Discussion in 'Malware Help (A Specialist Will Reply)' started by montan, Apr 14, 2011.

  1. montan

    montan Private E-2

    Hey

    THANK YOU for the most detailed Malware Removal Guide.

    It helped me to find few trojans and a couple of malware but i don`t know what to do now.

    I`ve posted these logs:
    # SASlog.txt log from SuperAntiSpyware.
    # ComboFix.txt (normally C:\ComboFix.txt)
    # RRlog.txt (from RootRepeal)
    # MGlogs.zip - normally it is C:\MGlogs.zip

    i will make another post to post the "Malwarebytes Anti-Malware log" .
     

    Attached Files:

  2. montan

    montan Private E-2

    Malwarebytes Anti-Malware log
     

    Attached Files:

  3. Caliban

    Caliban I don't need no steenkin' title!

    Greetings, montan.

    The MG moderators will most likely move this thread to the Malware Forum, where the gurus will check out your logs. You might want to post any symptoms you're experiencing to help the process.

    Good luck, and welcome aboard! :major
     
  4. montan

    montan Private E-2

    I`m experiencing some sudden system restarts, very very rare, but this i believe is because i have to many processes running. Last one it was because i had a game opened and a browser and the processor was at 100%.

    The main reason i decided to try and follow the guide 100% is because of a website that i use for many years without a problem and in the last days it doesn`t load scripts properly anymore. The website is soccerway.com

    Every time i access a link or a page of the website it says that a script cant load and always is a different script that doesnt load. When i disable the java the website works properly. I also contact the website about this problem but unfortunately i got no response. I need the java to be enabled.

    I`ve uninstalled the java and reinstalled again, also done the same whit my browser - firefox. Same result.

    I figured there is something wrong with my system.

    Also i like to point out that my brother uses a program to play an online game, a bot. Game name is silkroad online and the bot name is mbot.

    I also use Avast AV home edition, the free one, and when he installed the mbot , avast detected it as a malware. My brother saiz all bots related to this game are detected as a malware all over the world . I find this awkward , however i added the bot`s .exe to trusted processes in avast. This way I can keep the antivirus running.

    This is pretty much everything that i can think of ...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Other than a couple minor items that were already removed, your logs are clean. Thus it does not appear that your problems are due to malware and you should investigate them in the Software Forum if you wish.

    I do however recommend that you uninstall Ask Toolbar


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  6. montan

    montan Private E-2

    Thank you.

    I don`t have Ask Toolbar installed.

    1. done
    2. done
    3. i`ve uninstalled the emulator , i didn`t disable it.
    4. done - what is Qoobox folder?
    5. i didn`t download any registry patches like fixme.reg or fixWLK.reg
    6. i din`t use vista i have xp sp 2 -btw which windows is better . most of the time i use sp2 or sp3
    7. i didn`t install hijackthis.
    8. done but i can`t get wrid of the QooBox folder.
    9. exceptional advice , some of the programs there i`ve used in the past and wore good.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you do. You can see in the newfiles.txt log in MGlogs.zip that Ask Toolbar appears in your installed programs list towards the end of the log.

    And the below folders exist too:
    C:\Documents and Settings\NEC\Local Settings\Application Data\AskToolbar
    C:\Program Files\Ask.com

    Also the below is seen in your HijackThis log:
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Foxit PDF Creator Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    Quarantine from ComboFix. MGclean.bat will normally remove it if found unless you have permissions problems on your folders. Goto the lowest level files and folders inside of QooBox and delete from the bottom up. This will sometimes work when you have permissions issues. Also safe boot mode is an option.

    Yes you did. It is run as part of MGtools which is why the instructions stated to uninstall it now.
     
  8. montan

    montan Private E-2

    Done.I remember now that it was installed with Foxit PDF reader. That is why i didn`t saw it in the add & remove programs section. It had a different name: Foxit pdf toolbar ..something like that.


    MGclean didn`t remove it and the weird thing is that QooBox it has one subfolder BackEnv and it doesn`t allow me to do anything, delete or access it. It gives me an error: c:\QooBox\BackEnv is not accesable. Access is denied.

    Since i used MGclean.bat file i don`t have anything of those programs except that QooBox folder so if i want to uninstall the hijackthis program, where is it?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Resetting Registry and File Permissions and after reboot see if you can remove it.

    If HijackThis no longer appears in Add/Remove Programs, it was likely already removed.
     
  10. montan

    montan Private E-2

    I`ve dwld & installed SubInACL , i created the Reset.cmd file and then run it. After finish i reboot but the QooBox folder it is still give me "access denied" error.
    I saw that Reset.cmd found 8 irregularities in system32 and after that it said fixing registry in 0% out of (34/4041)..or something like that.

    What else can I do?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on the c:\QooBox\BackEnv folder and select Properties
    • Then select the Security tab
    • Now find your user account name in the Group or user names: list
    • The in the Permissions list at the bottom make sure that the Full Control checkbox is checked so that the all permissions for your account are enable ( that is all the check boxes below Full Control should then be checked ).
    • Then click Apply and OK to close the Window.
    Repeat the above on the QooBox folder.

    Now see if you can first delete the BackEnv folder and if it deletes then delete the QooBox folder.
     
  12. montan

    montan Private E-2

  13. montan

    montan Private E-2

    just perfect now each time i start the Pc i get 2 error over and over and my desktop freezed. windows explorer has encouterd a problem and DrWatson has incoutered a problem . I dont even know what DrWatson is.

    And i even used system restore and still nothing. I cant do anything. I i close firefox , there is no way i can opened again, i cant acces Mu Computer.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What changed? You did not do anything with the last fix because you had no Security tab. Thus you have not changed anything from my part. And in addition, even if you had found the Security tab, just changing permissions on these two folders would have no impact on the ability to boot your PC properly. What else was being done on the PC? Any programs installed, updated, modified, download.....etc.

    Also I don't understand what you are saying, if you cannot boot your PC up to Windows properly then how did you run System Restore.

    DrWatson is part of Windows. It is a debugging tool that runs automatically during Windows crashes. See >> http://support.microsoft.com/kb/308538
     
  15. montan

    montan Private E-2

    I was typing very fast, because my desktop freezed. The problem was because of an .avi file that I was just downloaded.

    I tested it. Every time i run the .avi file , the movie started normally in bsplayer but also the error with "Windows Explorer has encountered a problem and need to be closed" [Send error report] [Don`t send], fast after that my desktop disappears and appear few seconds later. Also I couldn`t access any icon.
    Anyway I`ve deleted the file and run CCleaner.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So then are you saying that everything back to normal now?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click Start and select Explore. This will open up Windows Explorer.
    • Now on the top menu, click on Tools and select Folder Options
    • On the Folder Options form, select the View tab
    • Scroll towards the bottom of the Advance settings area
    • Look for the Use simple file sharing (Recommended) option and tell me if the check box is checked or unchecked.
     
  18. montan

    montan Private E-2

    It is cheked.


    No. Now I can`t delete some of the folders. It tells me that it is used by another program but everything is closed. After restart I can delete the folder but i don`t want to restart each time.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then uncheck it and apply the settings. Then see if the Security tab I asked about earlier will show up.


    This is a Windows problem with permissions. It is a frequently complained about issue on the internet and I have never seen any real cure other than reinstall. Some people run into this problem, and some do not. Yes it is possibly that malware could be a triggering point ( but you did not really have any malware ), but the problem still results from Windows being problematic. If you get the Security tab to come back, you may be able to set permissions properly to allow you to remove the folders without rebooting.

    The above problem, along witht he problem of freezing and also with Dr.Watson running are all signs of problems with Windows that may require a repair install or a full reinstall to fix.
     
  20. montan

    montan Private E-2

    Done. I removed both, folder and subfolder. Should i check back the file sharing option?

    I figured i have to reinstall the windows. Maybe this is an unproper question but do you know from where can i find a god windows sp3? I don`t want an original one because at this time i can`t afford one. I want to dwld a good sp3 and make bootable cd.
    Can you help me?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We cannot and will not help you to do anything considered illegal. You can download and install Win XP SP3 direct from Microsoft Windows Update if you have a legitimate Windows XP license. Making a slipstreamed CD still requires having an original Windows XP CD. Any help you require in doing this ( legitimately only ) can be found in the Software Forum.
     
  22. montan

    montan Private E-2

    Ok . I understand. Thank you very much for your help. This forum is great.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds