Anyone ever heard of suurch.a? Help me get rid of this and other problems.

Discussion in 'Malware Help (A Specialist Will Reply)' started by MANDR88, Sep 15, 2008.

  1. MANDR88

    MANDR88 Private E-2

    HELP! I'm new here. I'm a home small business user in the Milwaukee area. I run Windows XP and CA Anti-Virus and CA Spyware remover. My CA anti-virus is telling me in my realtime scanner REPEATEDLY that it is detecting Win32/suurch.a in my "documentsandsettings\owner~1\localsettings\temp files. It gives a random number each time. It tells me the temp file is infected and then, it deletes it. Then, it happens again. I have repeatedly deleted my temp files. I am running Firefox as my browser, but IE7 is on the computer. I can't figure out how to get rid of it, nor am I sure I want to, but somewhere in the last month, IE7 quit showing pictures and after pulling my hair out, I downloaded and now use Firefox. Anyone have any problems like this?

    I also downloaded Ad-Aware yesterday in the hopes it would pick up something that my CA does not. It's still happening - getting infected real time suurch.a messages.

    Also, about a month ago, my husband went to an innocent looking website, researching some information on a sugar substitute, and the computer got the Fake.AV trojan from it. That trojan is gone now, but so are two of my Control Panel categories: accessories and Folder Options! The latter makes me pull out the remainder of my hair that was left over from wrestling with suurch.a. HOW do I restore those? I cannot see hidden folders at the moment, and that may be why I can't get rid of the suurch.a.

    Any thoughts, oh wise ones?

    Robyn
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. MANDR88

    MANDR88 Private E-2

    How Can I do the Malware Read and Remove process if Folder Options is Missing?

    Thanks, Chaslang for the protocol for getting rid of my suurch.a, which is a VIRUS. However, as I read through it, my heart sank because I cannot tell my computer to show hidden files. That's part of the PROBLEM. The "folder options" and "accessories" categories are missing from my Control Panel! So how do I proceed with your malware removal protocol? I'm running XP Home Edition. Thanks, Robyn
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: How Can I do the Malware Read and Remove process if Folder Options is Missing?

    Please remain in one thread for you current malware problems. I merged you back with your first thread.

    As stated in my first post
    So just continue.
     
  5. MANDR88

    MANDR88 Private E-2

    Hi Chaslang. OK - I ran the whole Read and Run procedure. I could not tell my computer to show hidden files because my Folder Options was missing from my Control Panel. It is now back. YEAH!!! However, my Accessibility Options icon is still missing. Should I worry about that?

    I'm attaching two of the logs the protocol asked for: the SASlog and the Malwarebytes Anti-Malware Log to this reply. The other two will come next.

    By the way - when I ran Combo Fix, since I did not have an XP disc that came with this computer, I downloaded the document at support.microsoft.com/kb/310994, and I dragged it into the Combo Fix icon, as instructed. When I launched the program, it began to run, and right off the bat, told me that ComboFix had an updated version available, so I updated it. Then, after it began to run, I got a message saying "Windows Recovery Console is already on this machine". It aborted the procedure. I started over. It ran OK after that.

    Finally, when I ran MGtools, after it was done, I got the following message:
    "Application has generated an exception that could not be handled. Process id=0x398(936), Thread id=0xaa8(2728). It said I could press OK to stop the application, or "cancel" to debug. I chose to debug. I then immediately got this message: "Registered JIT debugger is not available. An attempt to launch a JIT debugger with the following command resulted in an error code of 0x2(2). Please check the computer settings. cordbg.exe !a0x3a8".

    So, whatever all THAT means. I just 'x'ed out of the message, and the final screen came up. "Scanning Complete". I did not see a sample error message that compared to mine, so I did the best I could, being the "ungeek" I am.

    So, I'm attaching two files here, and I am NOT getting suurch.a notifications anymore. The only thing that seems to be missing is my Accessibility Options in the Control Panel. THANKS for ALL your help!

    Gratefully,
    Robyn
     

    Attached Files:

  6. MANDR88

    MANDR88 Private E-2

    Hi Chaslang - Here are the remaining two log files from ComboFix and MGtools. Let me know if you see something else I need to address.

    Thanks!
    Robyn
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go to the Add / Remove Programs Control Panel. Select the Windows Setup tab, and tick ‘Accessibility’ in the list of components. Then click OK and follow instructions.

    Did that bring it back?

    Your logs are clean.


    Now we need to cleanup a few additional things.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds