av security suite virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by jcdgl, Jul 8, 2010.

  1. jcdgl

    jcdgl Private First Class

    av security suite has taken over my computer can you help
     
  2. jcdgl

    jcdgl Private First Class

    i found a post from someone else that was having the same problem and followed those instructions computer seems to be fine now i hope by doing this i saved you a little time..I still tell everyone how great your team is at helping and will continue to for a long time
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would still be a good idea to attach the requested logs so we can check to be sure it all is gone. :)
     
  4. jcdgl

    jcdgl Private First Class

    tim
    thank you but now i have a lot going on because my mom just passed if i continue to have problems i will let you know
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My condolences!! Don't worry about it, I will be here if you need assistance in the future. :major
     
  6. jcdgl

    jcdgl Private First Class

    thanks tim still having a few issues not sure if it is just facebook connection or other will take me a day or two i will try to do all the other things first you guys have taught me well
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just attach the logs when you can and I will double check them to be sure you are clean.
     
  8. jcdgl

    jcdgl Private First Class

    Morning
    Sorry i have not responded to this post in such a long time but i ran all of your cleanup programs and computer was running great so i did not want to bother you. However now I am having issues with Internet explorer and mozilla not responding from time to time when i am on facebook not sure where to look for assistance. I had to disable my proxy server inorder to get internet explorer to work can you direct me to the right place
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you ran all of the tools in the Read and Run me First thread and you still require assistance then the best thing for you to do would be to attach all of the requested logs ;)
     
  10. jcdgl

    jcdgl Private First Class

    it has been awhile and nothing was found so all logs were deleted which means i will have to start over this may take me a day or two
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    well if you are still having problems, running the scans again would be the bst course of action. :) Ideally you should have attached the logs in the first place
     
  12. jcdgl

    jcdgl Private First Class

  13. jcdgl

    jcdgl Private First Class

    View attachment MGlogs.zip
    sorry having trouble sending logs so you may get one at a time i have 2 more to try to get through. i still have combofix rootrepeal to post but it is giving me a hard time will try one more time
     
  14. jcdgl

    jcdgl Private First Class

    sorry these are not attachments but for some reason IT is not letting me upload them still need to figure out how to get you combo fix ...I have done this before with no problems not sure what is up




    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4524

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    2010-09-01 01:42:57 PM
    mbam-log-2010-09-01 (13-42-57).txt

    Scan type: Quick scan
    Objects scanned: 157474
    Time elapsed: 10 minute(s), 59 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)




    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time: 2010/03/09 20:47
    Program Version: Version 1.3.5.0
    Windows Version: Windows XP SP3
    ==================================================

    Hidden/Locked Files
    -------------------
    Path: C:\hiberfil.sys
    Status: Locked to the Windows API!

    Path: C:\Program Files\AOL Games\Cradle of Rome\cradleofrome.exe:{930F330A-1510-221A-1CB8-E786B31DB412}
    Status: Visible to the Windows API, but not on disk.

    Path: d:\system volume information\_restore{70304573-ab33-4072-aa96-4495c42d15e3}\rp373\change.log.2
    Status: Allocation size mismatch (API: 16384, Raw: 4096)
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. There are a few things we can clean up:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Documents and Settings\Owner\Local Settings\Application Data\pbkchiacw

    Let's uninstall Firefox and see if a new install will fix your problem:

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\Diane\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
  16. jcdgl

    jcdgl Private First Class

    Thanks Tim I have been away and just got this my internet seems to be fine i think i am just to impatient for it to all load so i am going to save your e-mail in a save place and use it if I need it Hope that is ok
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I can suggest is that you, as a minimum, double the amount of RAM you have installed. 2gigs would be better.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds