Malware removal unsuccesful

Discussion in 'Malware Help (A Specialist Will Reply)' started by avz10, Apr 25, 2011.

  1. avz10

    avz10 Private E-2

    I followed the Malware removal guide to the letter, but it did not remove the malware.

    I found out there was a problem when I had an internet connection, but could not connect to the internet with IE and Firefox. Somewhere IE was restored, but Firefox still changes the proxy settings. This stayed the same after using the programmes.

    I removed anything that looked like antispyware and AVG is deleted. Windows firewall is off.

    Two programs did not work- Combifix and Root Repeal (I attach screen shots)

    I trust that you can help me.
     

    Attached Files:

  2. avz10

    avz10 Private E-2

    Re: Malware removal unsuccesful (2)

    Second set of attachments
     

    Attached Files:

  3. avz10

    avz10 Private E-2

    Re: Malware removal unsuccesful (3)

    Third set of attachments
     

    Attached Files:

  4. avz10

    avz10 Private E-2

    Re: Malware removal unsuccesful (4)

    Fourth set of attachments
     

    Attached Files:

  5. avz10

    avz10 Private E-2

    Re: Malware removal unsuccesful (5)

    Fifth set
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please note that as instructed in the READ & RUN ME FIRST, the only log from MGtools that you should be attaching is the C:\MGlogs.zip file. You should not be attaching any individual files from the MGtools folder unless we ask you too.

    Not a malware problem. Per step 1 of the READ & RUN ME, you need to setup to not use a proxy as given in the link of step 1
    Did resetting back to not using a proxy resolve your problems?
    Was that your only problem?


    Also do the below which also will provide a redundant fix to the proxy server when running HijackThis.

    Did you create the below batch file ?
    C:\Users\Albie\AppData\Local\Tempzx45.bat

    Do you know what the below service is for?
    O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:58444
    R3 - URLSearchHook: (no name) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
    R3 - URLSearchHook: (no name) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 25, 2011
  7. avz10

    avz10 Private E-2

    Re: Malware removal unsuccesful (succesful!!)

    All I can say is thank you. Working perfectly.

    No, it did not help. It kept on changing to the new proxy settings. Please see the attached screen shot.

    No

    No

    Well, it is working well now. I'm very happy.

    Just two questions:
    1. I used AVG, MBAM, Super Antispyware and Spyware Search and destroy. What would you recommend?

    2. My computer started runnning slow a while ago. I posted on this site:
    http://www.pctechbytes.net/showthread.php/44498-Desktop-slowing-down(1)?p=125917#post125917

    Do you think this malware could be the cause of this?. I want to get this post off as quickly as possible and will observe today if it slows down.

    Thanks!!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware removal unsuccesful (succesful!!)

    I suggest that you delete the C:\Users\Albie\AppData\Local\Tempzx45.bat file.

    Avira instead of AVG and paid version of MBAM. Keep SUPERAntiSpyware for additional scan only.

    Get a legit copy of Windows 7 . The KMService you said you know nothing about is for illegal activation of Windows 7. And it connects to a remote server to do this and it is always running.





    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds