After Removing Spyware Fix etc. Problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by susieq29, Dec 3, 2011.

  1. susieq29

    susieq29 Private First Class

    After finally removing the spyware fix. Win 7 internet security 2012- antispyware virus that changes names. It took a lot of time almost 3 days. Finally removed it using PC tools and Microsoft security scan.

    Everything is working fine. I was on line with windows support for 2 1/2 hours because I can't seem to turn on my firewall. I have Mcafee firewall and it won't turn on either from software or from windows firewall site. The tech tried everything.

    I am hoping maybe someone out their has the same problem. I ran the virtual tech from McAfee it said all files are Ok except host file (it says) sercvice state incorrect Service MCMPFSVC "Program Files\Common Files\McAfee\McSvc Host\MCSVHost.exe/MCCore Sv. When I go into services I see this in the Mcafee services but it is disabled and will not let me turn it on. I called Mcafee who said it is a windows problem. I am very suspicious and I was just wondering what you might think. My gut feeling is that the virus attacked Mcafee?
    My next step is to uninstall mcafee and see what happens.:confused

    By the way do not buy trojan kill it does not work.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. susieq29

    susieq29 Private First Class

    Thanks. After your response I felt better about removing Mcafee and sure enough removing it and then reinstalling it fixed my problem.:-D
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  5. susieq29

    susieq29 Private First Class

    I thought everything was working. But after I checked my windows firewall. It would not turn on. However Mcafee is working fine. After looking in services and being online with Microsoft I found that several services are missing from my computer. Base Filtering Engine - Security Center-Windows Defender are all missing. The tech wanted me to do a factory reset of windows. I am not happy and will not do that until I ask some other people. Is there any way to restore these services without doing this. I am sure someone has the dll's to these files that I can reinstall them. HELP HELP:confused
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can either post in our Software Forum to check into the problems you are having with various services, or you can run the malware cleaning procedure I gave you earlied if you wish to verify whether your problems are due to malware.

    Not sure if you really meant the services themselves ( like the registry entries and or driver files ) are really missing or whether you just mean the services were not running. Again this would be something to post in the Software Forum unless you want to pursue checking for malware.
     
  7. susieq29

    susieq29 Private First Class

    Ok. Going to software. There is no malware on my computer. It is a software problem now.
     
  8. susieq29

    susieq29 Private First Class

    I got a pop up message, asking if I wanted to use mevo iTunes to access. This message appeared when I had the virus on the computer.So I am doing a complete virus scan as per your links. While doing scan on superantispyware I got a pop up that says "message from web page Stack overflow the line number changed after I pressed OK on the first pop up. This started yesterday after I was on the computer with tech from Microsoft. He installed 1 click cleaner and windows 7 manager 3.1 . Should I just keep pressing OK or just leave message up while doing scan.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If this is a question, I have no idea since you did not run our cleaning procedure.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you SUPERAntiSpyware can finish running, then just let it continue without doing anything. If it cannot continue, just skip it and continue. If it does not run, skip it and continue.
     
  11. susieq29

    susieq29 Private First Class

    I did all the steps to cleaning PC I got a no spyware report from both antispyware and malware. I am attaching combofix and MGtools reports.

    My computer still will not let me turn on firewall. I think those files are gone.
    I keep getting an message stack overflow line 365. This is new and occurred after tech from microsoft played with my computer.

    I think my virus is gone. I have not finished with the clean. I went to the MG tools. I want to use the computer before I toggle system restore. When I ran combofix I had to run it in safe mode I got a message that windows cannot find nirkmd. It worked fine in safe mod. Just finished MG tools and opened file but can't find UAC.reg file?

    Any help is appreciated. I did see in combo fix the 4 files it deleted and one was part of the virus. I did not see anything that said that mevo virus I had.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you did. Here is a list of the most recent ones. You ran them a few times
    Code:
    6,160 2011-12-08 22:51:29  C:\Users\SUE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 12-08-2011 - 14-51-29.log
      588 2011-12-09 01:57:06  C:\Users\SUE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\SUPERAntiSpyware Scan Log - 12-08-2011 - 17-57-06.log
     
     
    1,039 2011-12-08 22:44:03  C:\Users\SUE\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2011-12-08 (14-44-03).txt
      901 2011-12-09 03:06:37  C:\Users\SUE\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2011-12-08 (19-06-37).txt
    What files are you referring to? And which firewall are you referring to? McAfee or Windows. If you are trying to turn on the Windows firewall, you should not be doing this. You already have the McAfee firewall. Only one firewall should be running.

    May be a problem internal to Windows.

    Not completely yet. I have a fix posted further down.

    When you tried to run it in normal mode, did you have ALL of McAfee shutdown?

    Do you know what the below files and folders are? Is the
    Code:
    2011-11-28 23:41 . 2011-11-28 23:42 -------- d-----w- c:\users\SUE\AppData\Roaming\AC169528
    2011-11-23 23:39 . 2011-11-23 23:39 -------- d-----w- c:\users\SUE\AppData\Roaming\Lacerte
    
    Why is Chrome being started like below and why do you need to run it at all every single time you start your PC?
    Code:
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AC30C6C88D8B6DC4F764D2BFBD17F60969E73E56._service_run"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2011-11-15 1036344]


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. susieq29

    susieq29 Private First Class

    I drag cf script file over combo fix but cf file still shows on desktop. Is that right? Also my McAfee file wall will not turn on. Running combo fix just said there is a newer version.
    Answer to other questions. Google chrome is now off at startup. Lacerte is my Document management system. I do not know what AC169528 is. When I Google it I got cartridge info. My combo fix started. Will Send info as soon as it finishes. I stopped overflow messages using error fix. Not sure if they will return after I reboot. Just to be clear I am only using one firewall (that is not working even after uninstalling and reinstall. ) So I tried to turn on windows firewall because I am afraid to be without one. (That would not turn on either)Thank you for all your input. I will make a donation to this site if that is possible. I meant that both spyware scans showed no infections. That is why I did not attach them-
     
    Last edited: Dec 9, 2011
  14. susieq29

    susieq29 Private First Class

    Attached are the two scans I did. Also my firewall from Mcafee still will not turn on. Everything else seems to be working fine. My computer was not shutting down when in hibernate but now it is.

    My printers and hardware are still not appearing after restart until I do it twice. I can live with that.

    My next question is do I need to use Mcafee Firewall? I am willing to get rid of it if you think I can use another firewall which will work with my computer without doing a whole reformat of windows (which I dread).
    Just to let you know the Mcafee Security Center did not install right away. The tech from Mcafee was on my computer running the download for me. A threat notice appeared so he ran a scan and said it was OK then it started to install. When I open it. It shows as the firewall is on yet in settings it shows not on.
    No more overflow errors are popping up.
     

    Attached Files:

    Last edited: Dec 9, 2011
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seems to be a common problem with McAfee of late. We have seen a few threads with this complaint. Apparently cannot even protect itself from the malware that you bought it to protect you from. ;)

    I see the below om your ComboFix log
    that is a driver/service for the McAfee firewall which likely means there is some kind of an issue with it.

    Let's try uninstall one more time but without reinstalling it immediately. I want to look at some logs first to be sure it gets completely removed ( it frequently does not ). So uninstall it right now. Then run the below for good measure:

    McAfee Consumer Product Removal Tool

    Then reboot your PC. Do not skip this reboot.

    After the reboot, download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    I want to review this log before continuing. Minimize your surfing right now while McAfee is uninstalled.
     
    Last edited: Dec 10, 2011
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is amazing. You had McAfee people looking at your PC and they did not find this problem?????????

    You have TDL infection that has added a new partition onto your hard disk and has made it the active partition inplace of your real Windows boot partition. I see the below in one of your logs from MGtools. The RED item is the problem.
    Code:
    Get Partition Info From WMI in K-bytes                          
    ============================================================== 
    Bootable  Name                   Size          Type                     
    FALSE     Disk #0, Partition #0  49319424      Unknown                  
    FALSE     Disk #0, Partition #1  13360955392   Installable File System  
    FALSE     Disk #0, Partition #2  486695501824  Installable File System  
    [COLOR=red][B]TRUE      Disk #0, Partition #3  1064960       Unknown[/B][/COLOR]          
    Do you have your Windows 7 boot DVD?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Additionally, it appears that the Base Filtering Engine (BFE) service has been deleted and the bfe.dll file required for it is also gone.

    The above quote is from http://www.blackviper.com/windows-services/base-filtering-engine/ where you can see more info about this service.
     
  18. susieq29

    susieq29 Private First Class

    I have windows 7 reinstallation DVD. I am uninstalling McAfee and will send you the log. I knew the files were missing. McAfee tech was useless.
     
  19. susieq29

    susieq29 Private First Class

    I am also missing security Center in services and windows defender. I found this when I was checking my services to make sure my configurations were right. My Security Center still opens.
    Waiting for mg tools to finish
     
  20. susieq29

    susieq29 Private First Class

    Attached is my zip file. Thanks again for all your help. I also have another PC in my house if I need to copy any files to replace on this computer.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now what I want you to do is to delete the C:\MGtools.exe file because I don't want you to run this anymore. In previous steps when I asked to run C:\MGtools\GetLogs.bat you instead re-ran MGtools.exe which does not produce the same results. So delete the MGtools.exe file now. We only need this file to initially get each new version of MGtools installed. ;)

    It looks like McAfee did not fully uninstall, did you run the cleanup program from them?

    Also uninstall the below:
    McAfee Virtual Technician
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this a bootable DVD that allows you to boot into the System Recovery Environment from the DVD? Can you try boot from it just to see if you can use it to do this? Then you can just exit and boot back into Windows.

    A good explanation on booting into this environment is in the below link but I don't want you to run any commands at the command prompt. I just want to see if you can boot up from the DVD.

    http://www.bleepingcomputer.com/tutorials/windows-7-recovery-environment-command-prompt/


    I have another boot CD I will be asking you to make that we will use to remove the infected partition I mentioned.
     
  23. susieq29

    susieq29 Private First Class

    Yes I ran the additional McAfee scan. I also removed virtual tech. Do I just delete mg tools.?
     
  24. susieq29

    susieq29 Private First Class

    I did use mcafee tool and I just deleted the virtual tech from the computer. I am going to put the dvd in my computer and see what happens.
     
  25. susieq29

    susieq29 Private First Class

    When I put the CD in I get open files dialogue. I see files
    boot
    efi
    langpacks
    sources
    support
    upgrade
    autorun.inf
    boot manager - file
    bootmanager -ifi file
    setup.exe
    Then there is a
    Files ready to be written to the Disk 1
    Desktop.ini
    I do not want to select anything without knowing what to do.
     
  26. susieq29

    susieq29 Private First Class

    Wait. I see I need to shut down computer and then insert disk and turn it on. Wait I will do that.
     
  27. susieq29

    susieq29 Private First Class

    My CD will not go in until I turn on computer. I turned it on and quickly inserted CD. Windows just opened like normal.
    Is there something I am not doing right?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Leave your CD in the drive and restart.

    Normally it would ask you if you want to boot from the CD if it is already inserted. Perhaps you need to go into your BIOS to set it to boot from CD before it would boot from the hard disk. This is the boot order options.

    If this does not work then it is probably not a bootable DVD. It is probably just some upgrade disk or other junk your PC vendor gave you but it is not a full installation disk if it is not bootable.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to just delete the MGtools.exe file ( has the superman symbol icon ) not the C:\MGtools folder.
     
  30. susieq29

    susieq29 Private First Class

    I think I figured it. I need to go to boot options.
     
  31. susieq29

    susieq29 Private First Class

    I am in boot set up how do I make CD first. It is hard drive first -USB storage next CD next.OK I figured it out. When I started it said select any key to boot.
     
  32. susieq29

    susieq29 Private First Class

    I am ready for next step see below. Also what is still on computer from McAfee? Shouldn't I remove it. Don't want to talk too soon but every time I restarted all my printers and devices were there.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I need to know before continuing is were you actually able to boot up this CD all the way to the command prompt of the System Recovery Environment as shown in the link I gave you. We cannot continue until I know you can do this.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below should remove it.

    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop McMPFSvc
    sc delete McMPFSvc

    The stop request may say it is not running. Just continue.
     
  35. susieq29

    susieq29 Private First Class

    OK first I got message when I tried to delete McAfee failed 5 . Access denied. Then I booted CD and it says windows is loading files-
     
  36. susieq29

    susieq29 Private First Class

    I got to system recovery options. I pressed load drivers because nothing was there. Now I have a screen insert media for the device and click OK?
     
  37. susieq29

    susieq29 Private First Class

    I have another CD that says drivers and utilities. Would that be what it is asking?
     
  38. susieq29

    susieq29 Private First Class

    I pressed OK and it is showing system folders. Libraries, system,computer,control panel, recycle bin. Are any of these what I want to choose.
     
  39. susieq29

    susieq29 Private First Class

    I need to stop for tonight. My computer is still at the add drivers Screen. See below if I press OK. Can I leave it like this or just tell me how to continue?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not sound like you are doing what we want. I don't think you need to click the Load Drivers button that you must have clicked. You should just click Next and then follow the instructions afterwards. We also do not want to perform a System Restore at this time. We just want you to Cancel that as shown as we just want to verify that you can get to the command prompt where we will need to run some commands at a later time.

    We are trying to verify that you can do this first because if we did other repair steps to remove the infected partition, you will not be able to boot your PC until we boot into this command prompt of the System Recovery Environment to run a few fixes.
     
  41. susieq29

    susieq29 Private First Class

    I am doing what instructions say. I pressed repair computer.
    The picture shows the page I am on.But in picture it says windows 7.
    On my computer it is blank. A message is saying if you dont see your system press load. That is where I am. It is asking for media file. I can send a picture of screen tomorrow.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then this may be occurring due to the infected partition which is not a Windows partition.

    You should backup ALL important data before continuing. The below is the only way we have to remove this infected partition and while this normally works quite well without problems, this malware is changing all the time and something could go wrong. Thus to be safe, you need to back up your data to DVD, external/removable drive or to another PC.

    Let's continue by making that CD I mentioned earlier.


    I need you to download the below:
    Now create a bootable CD the above ISO image file. You can use ImgBurn do this.

    And see the below link if you are not sure how to create a CD from an image file:

    Using ImageBurn to Burn an ISO image

    After you create this Gparted CD you will now need to boot up your PC using this Gparted CD. You can follow along with the below which illustrates what you will see at various points.

    http://img829.imageshack.us/img829/5772/gpartedsplash.th.png
    You should be here...
    Press ENTER
    http://img5.imageshack.us/img5/7286/gpartedkeymaps.th.png
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]
    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is the 1.02 MB partition I mentioned earlier. DO NOT delete any of the other three larger partitions.
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png
    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png
    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    Is boot next to your OS drive?
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags
    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png
    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.
    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.

    Now reboot from the Windows 7 DVD so that we can again try to get into your System Recovery Environment.and once you get to the command prompt, enter the following commands:
    • bootrec /FixMbr
    • bootrec /fixboot
    • exit
    When you enter the exit command your PC will reboot, remove the CD and attempt to boot Windows normally.
     
  43. susieq29

    susieq29 Private First Class

    Ok I will follow your instructions. My computer is backed up on carbonite. How do I close the screen I am on. The recovery option screen.
     
  44. susieq29

    susieq29 Private First Class

    I am out of recovery screen. Will work on this tomorrow. Thanks again for all your help. Hope its not snowing where you live.
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. Been a long day for me too. ;) You're welcome.

    No not today anyway. It was a nice clear night with a full moon last time I checked. It's cold enough to do so. About 29 F right now.

    I guess you don't have to worry about snow where you are at. ;)
     
  46. susieq29

    susieq29 Private First Class

    Ok. I got to command prompt. Just to let you know before that I got a message that said windows could not start up do you want to fix. I said no and got to screen that said command prompt. Enter everything said successful. Exit did not exit. It brought me back to restart option. I clicked on restart. I removed CD getting message bootmgr missing. Press Ctrl+alt+del to restart. Tried this got same message. Should I put in windows CD.
     
  47. susieq29

    susieq29 Private First Class

    I tried putting CD in it did not reboot. Got same message. Tried doing repair computer and press sing OK when option said fix and restart. Got same message.
     
  48. susieq29

    susieq29 Private First Class

    OK I fixed it. It opened up. I tried again this time worked. By the way my printers and devices are still not coming up all the time. Also this morning got a overflow stack 365 message.
     
  49. susieq29

    susieq29 Private First Class

    Also tried Cmd to remove McAfee got same message access denied. Open service failed 5. I went into registry and see file ?
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so let me see if I understand where you are at and what you were able to do:
    1. Were you able to run Gparted and find and remove that partition?
    2. Were you able to boot yor Windows DVD and get into the System Recovery Environment command prompt and run the bootrec /FixMbr and bootrec /fixboot commands?
    3. Is your PC booting up into Windows right now without a problem.
    If you are able to boot into Windows, continue with the below.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds