AntiVirus 2008 XP virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by crm1975, Aug 26, 2008.

  1. crm1975

    crm1975 Private E-2

    I believe I had the Antivirus 2008 XP virus. I read and ran the steps in "Malware Removal" process. Can you please review the attached logs and let me know if there are still any viruses. When I was running the MGTOOLS program, I kept getting a message saying that it did not have permission to write the ZIP file or something like that. The MGtools.ZIP folder was not created so I am going to attach the logs I beleive it should have had in that zip file.

    I used IE for 15 minutes after running MGtools.EXE and haven't had any popups.

    I will post 3 logs here and the remaining logs in a 2nd post.

    NOTE: The Malware log has a date inside it from 2004, this was because my clock was off when the program was run.

    Thanks in advance.
     

    Attached Files:

    Last edited: Aug 26, 2008
  2. crm1975

    crm1975 Private E-2

    Here are the MGtools logs. The ZIP folder could not be created so I am attachine them individually.
     

    Attached Files:

  3. crm1975

    crm1975 Private E-2

    Here is the Hijackthis log too if needed.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you need the below files, I suggest that you move them somewhere else. Otherwise delete them.
    Code:
    2007-02-12 00:14 5,214,192 ----a-w C:\Documents and Settings\Dawn Peterson\RPC2006-FI.exe
    2007-02-11 18:16 39,778,384 ----a-w C:\Documents and Settings\Dawn Peterson\MIS2007-FI.exe
    2007-01-14 23:30 435,112 ----a-w C:\Documents and Settings\Dawn Peterson\switchsetup.exe
     
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to McAfee Protection Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastemcpromgr into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O15 - Trusted Zone: http://www.download.com
    O15 - Trusted Zone: *.download.com
    O15 - Trusted Zone: http://www.mcafee.com

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 27, 2008
  5. crm1975

    crm1975 Private E-2

    I deleted the 3 files you suggested to move or delete. I did get a success message after running FIXME.REG. Was I supposed to re-run Combofix too, it wasn't in the directions so I did not.

    I again ran into errors creating the MGLOGs.ZIP folder so I am going to post the logs in this message and an additional message. The error says "Zip I/O Error: Permission denied" when i ran the Getlogs.Batfile

    Moved around on the internet for about 15 minutes and no pop ups came up. PC seems to be running OK.

    Let me know if you need additional files or for me to run Combofix again. thanks
     

    Attached Files:

  6. crm1975

    crm1975 Private E-2

    Additiona lfiles. Combo fix is from when I ran it yesterday.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. crm1975

    crm1975 Private E-2

    I have finished all of the suggested steps. Everything seems to be working fine. Thanks again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds