Malware please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gingerwarrior69, Jun 13, 2011.

  1. gingerwarrior69

    gingerwarrior69 Private E-2

    I have been trying to remove some malware from my friends laptop. It has made her prgrams list appear empty and her C drive appear empty too. One I selected to display hidden files/folders they display again but they are ghosted as though the are hidden files. I have ran through the whol read me first section and none of it helped.

    I have attached my logs. I could not do the combo fix one as it said i still had AVG installed, but i have uninstalled avg and ran the avg removal tool. It still says it is installed :(
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    This is not from Ramnit. If these are still missing then please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your Programs?
     
  3. gingerwarrior69

    gingerwarrior69 Private E-2

    Hi, thank you for your help I really appreciate it. I'm sorry I took so long to respond. I am on nights at the moment so findin a decent time to do anything is a nightmare. I have her programs list and files back now, thank you very much for that :)

    I decided to do one last full system scan using malware bytes but I get a PUP.Zwangi virus found in her registry. I removed the virus and restarted the machine (with system restore switched off) and ran another scan but the same virus is there. Do you know how I can remove this?

    The report showed the infected registry key as:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BROSERQUEST_SERVICE (PUP.Zwangi) -> quarantined and deleted successfully
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run ComboFix and attach a log. Ignore it if it tells you AVG is installed ( that is as long as you still have it uninstalled, if not, then uninstall it again first ).

    Also attach a FULL log from Malwarebytes, make sure that you have updated it to current definitions.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot... also do the below.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Conduit Engine
    Java(TM) 6 Update 13

    Now install the current version of Sun Java from: Sun Java Runtime Environment
     
  6. gingerwarrior69

    gingerwarrior69 Private E-2

    Hi, thanks again for the reply. I have tried to run combofix but again it says that combo fix cannot run when AVG is installed and closes itself down, I have no option to ignore it.

    I have attached the full mbam logs now. I hadn't updated the definitions at the time of this scan because I had no internet access at work. I have updated them now and am running another scan. I have also ran the messenger removal tool and the conduit tool and the old version of sunjava and updated it.

    I will attach the updated scan results when I have them if you think you need them?
     

    Attached Files:

  7. gingerwarrior69

    gingerwarrior69 Private E-2

    Hi there, here are the new logs. It didn't find anything this time but now everytime I try to go to a link on google it takes me to some random advert so there is definitly a virus still there.

    I have attached the new file to this post. Thanks again for your help.
     

    Attached Files:

  8. gingerwarrior69

    gingerwarrior69 Private E-2

    Hi, I have ran through the steps in the browser hijacking removal guide and so far this seems to have resolved my issue. I am running a new scan in safe mode just in case. Hopefully this has sorted the problem. If it hasn't I will post again. Thank you very much for your help it is well appreciated!!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then if things are still okay, move on to the below final instructions.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds