Antivirus 2010 and ReleaseToday.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by tomkat2006, Oct 13, 2010.

  1. tomkat2006

    tomkat2006 Private E-2

    Help guys, after vising some sites yesterday the known virus Antivirus 2010 was installed and run on my PC by itself, leaving the "your computer is inflected" wallpaper. I uninstalled it via add/remove and followed up by scanning my system with all tools at hand (recommended in the sticky), the tools would run, then crash, the .exe would then crash anytime after that loading it up (even after using rkill).

    Combofix wont run because of spyware doctor et all in the backround - even though they were fully uninstalled. Tonight after trying to download newer versions of the scanners all fail (crash during scan), combofix says "access denied" when doing its scan then hangs.

    The webpage of "ReleaseToday.com" automatically comes up as a default page all the time, and at startup, I just cant get rid of it.

    Please recommend some suggestions, Ive wrote this thread as the stickied programs will now no longer run (at least long enough to finish a scan).
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    For this part use safe mode with networking if normal mode is posing problematic for you.

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: (in normal mode if possible, otherwise use safe mode) Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. tomkat2006

    tomkat2006 Private E-2

    Thanks for the reply, I was unable to scan the PC with Malware Bytresm the same issue happens again.

    I tried exehelper and got the first log (exehelper1.log) then installled mallware bytes but as soon as you click scan the program closes, not crashes - just vanishes.

    I rebooted in safemode scanned again with exehelper and got log number 2 (attached) you can see in safemode some items were removed yet in normal mode there arent any.

    Tried installing Mallware BYtes again, same issue happened, the .exe also become unusable after it crashes.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about MGTools? I need logs from that at least :( Did you try that in safe mode?
     
  5. tomkat2006

    tomkat2006 Private E-2

    as requested
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    Navigate to: C:\MGtools\analyse.exe (if using vosta/win 7 right click and run as admin) do a system scan only and save a log file. Or if that fails then please download Trend Micro HijackThis run a system scan only and save a log file to attach for my reviewal.

    Java(TM) 6 Update 15 <--- Uninstall this.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Run ComboFix in safe mode if you are not able to in normal mode (try normal first)!

    You need to install some anti virus when we are finished here.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running and don't forget to attach that HJT log.
     
  7. tomkat2006

    tomkat2006 Private E-2

    Thanks for the reply, cant get past the first step though, running analyse gives this error:

    "windows cannot access the specified path or file" (this is the same error msg that comes up whenever ANY virus remover etc is accessed

    I install Hihack this, run the scan, and it too vanishes, I try again - it wont open. I try and reinstall and a error msg says

    "the installer has insufficient privilages to modify this file"

    I thought I'd await your reply before trying avenger.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then try running HJT in safe mode. (If it fails, move onto the other steps but in normal mode)
     
  9. tomkat2006

    tomkat2006 Private E-2

    I took the hdd out of the pc and installed on another and scanned it there, it detected and removed all the bogus files so its all ok now.

    HJT wouldnt work in safe mode either btw, that was an annoying virus!!
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sometimes the preliminary scanners don't always nail it all in one go, often malware can remain, hence our use of other tools. If you are sure you're alright then you can follow final steps, otherwise, follow my previous fix and attach logs.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. tomkat2006

    tomkat2006 Private E-2

    thanks for the support
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds