Anitvirus 2009 Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by crm1975, Aug 21, 2008.

  1. crm1975

    crm1975 Private E-2

    I beleive I was infected with the Antivirus 2009 virus. I ran all 5 of the programs that the forum suggests I run in order. I ran Super Antispyware, then Spybot 1.6, Malwarebytes Anti_malware, Combofix and MGTools. The internet seems to be ok and I don't seem to be getting any popups, although it has only been 10 minutes.

    Can someone please review the attached logs and let me know if I missed anything or still ned to clean anything up, thanks in advance.

    I will attache the MGLOGS.zip in a 2nd post since I can only attach 3 files to this post.
     

    Attached Files:

  2. crm1975

    crm1975 Private E-2

    here is the MGtools.Zip file too
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have some more to remove. Also your Norton 360 program is broken and will need to be removed and reinstalled to fix.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Do not reinstall it yet!!!

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now you can reinstall your Norton 360 program if you still plan on using it.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. crm1975

    crm1975 Private E-2

    I followed all of the directions given blow. It said the Registry entries were successful. I am not going to re-install Norton 360 so I didn't do that. When I ran Combofix, it did say an update was available so I said YES to get the update. While running ComboFix, the PC rebooted but then continued on after it came back up, is that normal? I have attached the logs you requested. Things seem to be working ok, no popups, but I only messed around on the internet for 15 minutes after running all these programs. Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is how it removes the malware files.

    Your clean other than the below new file that was spawn from the infection. See if you can find and delete this file:

    C:\WINDOWS\system32\Kv4tlkG8.exe.a_a

    If you get the above file removed, continue on with the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. crm1975

    crm1975 Private E-2

    I followed all of the remaining steps and all seems well. I also downloaded an anti-virus and firewall from the list you supplied. Thanks for all your help.

    This was for my sisters PC. My other sister has the Windows anti-virus 2008 malware so I will follow the Malware removal guidelines for that one next. Thanks again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you start a new thread for the other PC.
     
  8. crm1975

    crm1975 Private E-2

    I will create a new post for the next PC, how do i close this one?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can't and we don't normally bother closing them as it is unnecessary because only you or one of the helpers here can post in this thread.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds