Antivirus Live virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ashj1, Jan 5, 2010.

  1. Ashj1

    Ashj1 Private E-2

    Hi folks, daughter inlaws computer infected with the Antivirus Live virus. Complied with "read and run me first", got a little confused due to lack of knowledge and moving from safe mode to normal mode trying to see what programs would work when.

    When in normal windows mode the virus would hijack any attempts to connect to normal sites on the internet and would reroute to porn sites with various virus attack alerts. Problem started in June 09 and laptop was stashed in a closet since.

    Norton system is out of date and will be removed and replaced with other protection software when you give the ok.

    Most of the cleaning procedures were accomplished in the safe mode except the SUPERAntiSpyware as it wouldn't run in safe mode. Also couldn't load updated Sun Java in safe mode so I have no Java.

    Somehow, I tricked the virus program and was able to get combo fix on the desktop and run it in normal windows mode, and now all seems to work ok. This is the only cleaning procedure I was able to run in normal windows mode. Won't run any other until you give the ok.

    Thanks for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your problem with SAS is probably due to this:
    C:\sas.exe.exe <--- one too many .exe. Remove one, and move it to program files.

    Let's reset your IE defaults:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let me know if you get a success message. Then tell me how things are running and if you can run SAS now.
     
  3. Ashj1

    Ashj1 Private E-2

    Tim,

    Successful with IE defaults reset, thanks for your help, exe.exe, yeah that would probably slow progress a little (hehe).

    Attached is the SAS log, that's a great program, it picked up 45 more infections.

    The only thing that may be a problem is this, the first boot of the day is vvveerrryy slow, I haven't just let it alone to see how long it actually takes however I have left it for 5 minutes and it only gets past the option page for selecting between the normal start up or the "Windows Recovery console" and then seems to stall, if I intervene, shut it down and reboot (many times) it still takes approx 15 or so minutes to get a normal operating computer, after that first boot though any subsequent boots are speedy, probably less that 2 minutes.

    That being said, it's not my computer so I don't know the history, maybe this was happening before the infection??

    I admire you and the team of Malware warriors at MajorGeeks, looking at logs and figuring out what it all means and how to fix someone else's computer......yikes, and with the various skill levels of operators is bound to be frustrating at times.

    Keep up the good work.

    Joe.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Slowness could be a factor of too little RAM:
    Total Physical Memory 512.00 MB
    Available Physical Memory 199.16 MB

    Though I don't understand the difference between initial start up and subsequent start ups.

    You may wish to use one of these:

    Startup Manager

    Startup_CPL

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. Ashj1

    Ashj1 Private E-2

    Tim,

    The laptop seems to be working fine. I complied with your requested actions as well as the "How to protect yourself from malware" link. Loaded up the free edition of Comodo Anti-virus and Firewall software and as my last actions before I give the laptop back to my daughter in-law I complied with Comodo a/v, Malwarebytes, and SAS scans.

    Malwarebytes quick scan found 10 more issues, did a full scan after the quick scan and found 0 items, Comodo since I've loaded it has found 18 issues, not sure if they are false positives or not, and SAS full scan found nothing.

    I feel confident about the Malwarebytes and SAS scans but not so with Comodo since it's new to me. Again the lap top seems to be working fine just these last issues. Attached are the logs, hopefully the Comodo log works for you, it's a zipped .htm document, I had to improvise with my limited knowledge.

    Regards

    Joe
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You sent me a shortcut to Comodo......:-D. Bad day, eh?

    You can try attaching the actual log. It appears as though MBAM and SAS are working. Which is good! But go ahead and attach the Comodo log. I am curious.
     
  7. Ashj1

    Ashj1 Private E-2

    Tim,

    Sorry I'm not able to attach a log from Comodo it will only allow me to export to HTML which the Major Geeks site will not allow. As a side note, while downloading Microsoft critical updates, Comodo anti virus flagged a virus event so I quarantined it, turns out it was actually one of Microsoft's critical updates, I was downloading 2 updates and only 1 survived Comodo. I didn't know it at the time, however when I reviewed the installed updates only 1 had installed.

    Thanks for your help.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't need to "export", you only need to copy and paste the log into notepad and then attach.

    Are you saying you are not having any other malware issues?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds