antispywarexp2009 Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by jdwood3, Nov 13, 2008.

  1. jdwood3

    jdwood3 Private E-2

    Good afternoon, I thank you in advance for any help you can give me regarding this infection! I am currently posting from another computer - when I try to access this site from mine, it redirects me to ad sites. Can you give me a starting point? I am looking forward to getting rid of this virus but do not know how to proceed since I cannot get here from my home computer. Hope this makes sense! Thanks!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gifWelcome to MajorGeeks.com!http://www.majorgeeks.com/images/grenade.gif

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:
    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. jdwood3

    jdwood3 Private E-2

    Hello, I was able to copy the programs from another computer and begin to run them on mine...although my computer kept freezing during the start up. I went into safe mode and ran superantispyware which found over 200 infections. I then restarted and went into normal mode but found there was no log when I opened the program again. I went ahead and ran the program again in normal mode and continued through the process. I ran spybot and malwarebytes also. Attached are the logs from each process. I do not have the windows CD for combofix and the microsoft support website would not come up for me when I tried. So I stopped there and did not proceed with combofix or MGtools. I am running XP home edition 2002 with service pack 2. Not sure how to proceed from here. Thanks.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You need to download and run ComboFix and MGTools. They are required for us to continue in the cleaning process.

    BTW, ComboFix, you just download and run, no need to do anything else. You can skip the install of the Recovery Console for now.
     
  5. jdwood3

    jdwood3 Private E-2

    Ok, here is the log from combofix. I ran mgtools and it showed a log but I can't find it...? I ran a search for mglogs.zip but it didn't find it either. Suggestions? Thanks.
     

    Attached Files:

    • log.txt
      File size:
      13.4 KB
      Views:
      8
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You have to download MGTools.exe and run it to get the file.
     
  7. jdwood3

    jdwood3 Private E-2

    I appreciate your patience with me....I ran mgtools.exe and it stated at the end that my logs were located at c:\mglogs.zip, just as your guide says. But I guess I don't fully understand how to post the log, because when I go to my computer>c: drive, I don't see a zip file there by that name. There is the mgtools folders and mgtools.exe. Am I way off here?
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the file MGTools.exe, save to the root of your C drive. (C:\) and run it from here. It will create a folder "C:\MGTools" and once it thru running it will create a log "MGLogs.zip" in the root of the C:\ drive.

    Disable all antispy and antivirus programs before running it. It may be blocking parts of it.
     
  9. jdwood3

    jdwood3 Private E-2

    Thanks for the direction. I disabled Avast and ran the program again, but got the same results: yes, the mgtools.exe was in the C: drive and it created the mgtools folder, but there is no zip file. Throughout the process of running the mgtools, it kept saying 'could not create output file' - is that normal?
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No, something is more than likely causing this. For now, look for the following files and attach them if you find them.
     
  11. jdwood3

    jdwood3 Private E-2

    Here are those items...
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Pre-Instructions:
    1. First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.
    2. Print out these instructions or save them to a text file so that you can operate with All Browser Windows CLOSED.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 2:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 3:
    Default Security Settings

    To Default Security Settings:
    For Internet Explorer 6 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up navigate to the Security Tab and click Default Level for the following:
    • Internet
    • Local Intranet
    • Trusted Sites
    • Restricted Sites.
    Click OK to exit.

    For Internet Explorer 7 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up, navigate to the Security Tab and simply click the "Reset all zones to default level" button. Click OK to exit.

    Step 4:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\Avenger.txt
    • C:\MGlogs.zip
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  13. jdwood3

    jdwood3 Private E-2

    Everything seemed to go well, although when I changing security settings to default, the 'default' box wouldn't light up unless I changed the level on each item (only the custom box would light up). Then when I returned to click the 'reset all zones to default level' it didn't light up either. Plus, again, the mglogs.zip could not be created due to some type of error. Here is the avenger log.
     

    Attached Files:

  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Try once again to run the C:\MGtools\GetLogs.bat file by double clicking on it. If successful, attach the new log it creates.
     
  15. jdwood3

    jdwood3 Private E-2

    Looks like I finally got a log to create. My pc is running much better, thank you, although its speed is a little disappointing.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do have some more malware to remove but your speed issues are most likely due to the fact that you only have 512.00 MB of memory and really should have twice that amount. Also it is due to what you are running. BJ gave you a few non-malware things to remove but you did not remove all of them so let's try again.

    Looks like you have been having a problem getting the Zip utility in MGtools to work properly. We will remove the MGtools folder and download a new version to use later.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [InstallProgram] C:\Documents and Settings\Ria Wood\Local Settings\Temporary Internet Files\Content.IE5\VJA783WC\setup_243_3777_[1].exe
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS

    After clicking Fix, exit HJT.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 30, 2008
  17. jdwood3

    jdwood3 Private E-2

    Thanks again for your time....I ran through your directions and got the avenger log. You mentioned that we would download a new mgtools but didn't give a link. Obvioulsy getlogs.bat wasn't there so I didn't run it. I am attaching the avenger.txt and will await your direction on the mgtools. Also, after running analyse.exe, the last three lines to select weren't there, so only the first, O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime, was selected.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. The current link is always the one in the READ & RUN ME but I was just going to post it here. Here it is: MGtools.exe

    Run this new version and attach the new log.

    Are things working any better?
     
  19. jdwood3

    jdwood3 Private E-2

    I downloaded mgtools and ran it and I'm apparently back to the issue I had before because it wouldn't generate an output log. It runs through the program but I see lines like "zip error: could not create output file" and "zip I/O error: permission denied". The only file at c: is the original mgtools.exe. These error messages are the same I was receiving before. I ran the program twice; once without disabling avast and again after I turned it off.

    My pc is running light years better than when I first contacted you guys. Also I did order some additional memory. Thanks again.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why you are having this problem since many many other people coming hear also have Avast and do not have this problem. All I can think of is that there may be another zip.exe program on your PC but I doubt it.

    What do you have still installed from Symantec (if anything). I saw the below in one of your previous logs:
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    Just attach the below files from the C:\MGtools folder so we can make sure you are all clean.
    • hijackthis.log
    • newfiles.txt
    • runkeys.txt
     
  21. jdwood3

    jdwood3 Private E-2

    I found the following in regards to symatec: NIS071030.exe, a symantec shared folder, and an empty live update folder under program files. Can I assume it's safe to delete all of these? I installed the additional memory and there is a huge improvement.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! My question was to find out if you still had software from Symantec that you were actually using. You can delete those items you mentioned but you should also do the below too.

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Also delete the below folder if it still exists:
    Code:
    "C:\Documents and Settings\All Users\"
    SYMANT~1      Jul  5 2007              "Symantec Temporary Files"
    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  23. jdwood3

    jdwood3 Private E-2

    Thanks to all who have helped me over the past month! I am very thankful that I found this website and will continue to use it as a resource in the future. Thanks again!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds