Cannot remove malware/spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by mrgreenfeet, Nov 27, 2008.

  1. mrgreenfeet

    mrgreenfeet Private E-2

    I have done steps 1 and 2 on the Read Me First. I cannot complete step 3 for the following reason:

    I cannot connect to any antispyware/antimalware/antivirus sites on my computer. I used our second computer to download the programs on step 3, burned them to disk, and tried to install on my computer. I cannot install Spybot Search & Destroy, ComboFix, or MG Tools. I cannot run SuperAntiSpyware or Malawarebytes.

    I am currently using Zone Alarm Pro (15-day trial period), but I installed it after my computer was infected. Up until then, I was using Zone Alarm Firewall, AVG antivirus, and AdAware.

    I can reach many sites on the internet, but none for security. I cannot defrag my computer or use System Restore. My computer is running XP. Up until my computer was infected, I got updates as soon as they were available. Please let me know whatever additional information you need.
    Thank you for your help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you sure that you really tried to run MGtools.exe? It does not require a windows installation. It just runs. Did you try renaming the other installer programs as suggested in the instructions? Did you try running things in safe boot mode too? Have you tried physically unplugging your cable to the internet while trying to do all of these steps?

    Keep the following in mind. If you cannot run anything and cannot get us any logs, we cannot help you. Thus your next step is to reinstall.
     
  3. mrgreenfeet

    mrgreenfeet Private E-2

    I was reading your forum and I have av2009 virus. I kept getting the popups. I installed MG Tools in Safe Mode and have attached the logs. This is the only program I can run. (see first message) I hope this information is helpful to you in trying to resolve my problem. Thank you SO much for your help. Yes, I did unplug my computer from the modem while trying to run these programs.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not attach the logs. You attach a snapshot of a HijackThis log which is not what we need and it is only one of many logs from running MGtools. Please attach the log file that are requested not snapshots of logs. The log from MGtools is C:\MGlogs.zip as specified in the instructions.
     
  5. mrgreenfeet

    mrgreenfeet Private E-2

    I cannot reach your site on my computer because the malware is blocking it. I am using our second computer to communicate with you. If I send an attachment to this computer it will get infected also. That's why I printed out the logs, scanned them into this computer, and attached them to my message. I will go back to my computer and check for the mglogs.zip, but I can only send them by printing them out, scanning into this computer, saving them on notepad, and attaching in a message. Is that what you want me to do?
     
  6. mrgreenfeet

    mrgreenfeet Private E-2

    I have located the mgtools.zip file on my computer. It is rather a lengthy file, so can you suggest any other way I can get this file to you other than saving it to this second computer? I definitely don't want to infect this second computer because it's the only way I can stay in contact with you. Thank you.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log file is C:\MGlogs.zip not MGtools.zip (or perhaps you are looking at MGtools.exe which is the installer program you downloaded from us).

    We need the MGlogs.zip file which contains 9 text logs for us to even try and get started. All you attached was a scan of 1 file and a scan is of no use to us. We need the actual text logs that are in the ZIP file to create fixes.

    Just copying this ZIP file to the other PC should not be a problem. By what method are you going to transfer it. Are your PCs connected via file sharing or are you referring to using a flash drive, CD or floppy?


    When you tried to run SUPERAntiSpyware, ComboFix and Malwarebytes, exactly what happens?
    • were you able to download them okay?
    • were you able to install them okay?
    • when you try to run them after installing what happened?
     
  8. mrgreenfeet

    mrgreenfeet Private E-2

    I'm sorry. I meant to say mglogs.zip (brain lapse) I do have the mglogs.zip file.

    We don't have file sharing. I copied the file to CD and am attaching. I hope I've done this correctly.

    Downloaded SuperAntiSpyware on second computer, saved to CD, and installed on computer. When I try to run, I get the Microsoft message: Application has encountered a problem and needs to close.

    Downloaded Malawarebytes on second computer, saved to CD, and installed on computer. When I try to run, nothing happens at all.

    Downloaded ComboFix, CC Cleaner and Spybot S&D on second computer, saved to CD, but cannot install them on computer even in Safe Mode.

    I appreciate your help and patience with me. Thank you.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search for TDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
    • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.
     
  10. mrgreenfeet

    mrgreenfeet Private E-2

    Was able to locate and disable TDSSserv.sys. Rebooted and am now running SuperAntiSypware per instructions on XP Cleaning page (I printed them out earlier.) Will try to run Malawarebytes next. If it scans, I will try to install the other programs on the list that I couldn't install earlier.

    Again, thank you SO much!
     
  11. mrgreenfeet

    mrgreenfeet Private E-2

    SAS scan completed. Attached is the scan log. I can actually reach your site on MY computer now. I will be installing and running all the rest of the programs listed under cleaning. I will run Malawarebytes next and send log when it finishes. (May not be until tomorrow.)

    Thank you SO very much for your help!
     

    Attached Files:

  12. mrgreenfeet

    mrgreenfeet Private E-2

    Ran Malawarebytes. Scan log attached.

    Thank you again!
     

    Attached Files:

  13. mrgreenfeet

    mrgreenfeet Private E-2

    Ran ComboFix. Scan log attached. Still having a problem:

    Ran Spybot S&D after checking for updates. (No, I didn't install Tea Timer.) One problem could not be fixed:
    SpywareBot.Spyware Stop
    1 Entries MalwareC

    Rebooted computer and ran Spybot again. Still could not fix the problem.

    Thanks for your help with this.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this the only current problem? Attach the log from Spybot so I can see exactly what it is finding and where.

    Also do the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O1 - Hosts: # Copyright (c) 1993-1999 Microsoft Corp.
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)


    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Nita McLeroy\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 3, 2008
  15. mrgreenfeet

    mrgreenfeet Private E-2

    I removed Windows Messenger as instructed.
    I uninstalled Viewpoint Media Player (sorry I missed it the first time.)
    I ran MGtoolsanalyze and removed the items listed except for:
    01 - Hosts: #Copyright (c) 1993-1999 Microsoft Corp. because it was not on the analyze readout. Everything else on the list was removed.
    I ran ComboFix as instructed with the file CFscript.txt.
    I had already installed the current version of Sun Java, but I downloaded and installed again.
    I deleted files from C:Windows/Temp and C:Documents...../Temp
    I ran the CC Cleaner
    I ran the MGtools\Getlogs.bat

    I have searched every folder on my C drive and in Spybot Search & Destroy, and I cannot find any logs for S&D. Can you please tell me what to look for so I will know what to send you?

    After I did all this, I ran Spybot S&D again, and I still have the same problem with Spywarebot.Spyware Stop. S&D cannot remove it.

    Attached are logs:
    Combofix.txt
    Mglogs.zip

    This seems to be the only problem, but I don't know for sure.

    Again, I appreciate your help and patience with me.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot logs are normally stored in the below folder:

    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs

    You can also run a new scan and when it finishes, just right click in the scan results window and save a log where ever you wish.;)
     
  17. mrgreenfeet

    mrgreenfeet Private E-2

    Thank you SO much. Ran another Spybot S&D scan this morning and am attaching the log.

    chaslang: You have helped me so much, and I truly appreciate all the time you have spent on my problem. :)
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome.

    All Spybot is reporting is a leftover folder from a rogue program you had installed at one time. All you have to do is delete the below folder yourself:

    C:\Documents and Settings\Nita McLeroy\Application Data\SpywareStop\

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. mrgreenfeet

    mrgreenfeet Private E-2

    THANK YOU, chaslang!!

    I've done all the steps you sent, and I will follow the suggestions on how to protect yourself from malware. I will continue to check your site to see if there are any new suggestions. We are planning to purchase SAS and install on both computers.

    I sincerely appreciate your time and effort. You are A-number-1 in my book!

    BTW: I totally get this: "There are 10 types of people in this world. Those who understand binary and those who don't." Done some math in my day!

    Have a great day!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome ( and thanks ;) ) Surf safely!
     
  21. mrgreenfeet

    mrgreenfeet Private E-2

    chaslang:

    After reading 'how to protect yourself', I followed the instructions. I purchased SAS, am using Avast antivirus, spyware blaster, and online armor firewall. I also save all email attachments to my desktop and scan them before opening. After this nightmare with malware, I am going to be super careful! I never click on pop-ups, and I am very careful what sites I visit.

    My computer is clean as is our second computer (which has the above security measures also.)

    I really cannot thank you enough for all your help.

    Take care!
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I recommend that you not save attachments to your Desktop. Create a folder somewhere else and save them there for scanning. Once scanned and if they are clean, move them to whereever you want to save them (not your Desktop).
     
  23. mrgreenfeet

    mrgreenfeet Private E-2

    Thanks chaslang. I will create a folder in My Documents to save and scan all attachments before opening. If there is anything else I can do to protect these computers, please let me know. I always appreciate good advice! :)
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Would not be my preference since most downloads are not "documents". They are programs. But whatever works for you to manage things in the end. It's always your choice. However here is what I always do. I create a Downloads folder, like

    C:\Downloads

    Under this folder I create categories of subfolders, like:

    C:\Downloads\AntiVirus
    C:\Downloads\AntiSpyware
    C:\Browsers
    ..... etc

    And under those folders there are more category subfolders to contain the specific downloads. Like

    C:\Downloads\AntiVirus\AVG
    C:\Downloads\AntiVirus\Avast
    C:\Downloads\AntiVirus\McAfee

    And under them may even be more specifc folders like:

    C:\Downloads\AntiVirus\AVG\AVG AntiVirus Free Edition 8.0 Build 175a1382
    C:\Downloads\AntiVirus\AVG\AVG Anti-Virus Update December 15, 2008
    C:\Downloads\AntiVirus\AVG\AVG Internet Security 8.0.93.1283

    I think you get the point of the above. At any given point in time, I can always tell exactly what I have downloaded because the folder names (like a file cabinet) tell me exactly what I have. Even after months without looking at some file, I know exactly what is is because of where it is located. Example, if I had simply download and save WDC3Setup.exe to My Documents and then a few weeks or months later see it. I would be wondering, what the heck is this..... is it safe to run it to find out what it is??? However by my method, it is not saved to My Documents, it is saved like this:

    C:\Downloads\Drive-Cleaners\Wise Disk Cleaner 3.7.4\WDC3Setup.exe

    That is rather self-explanatory on what it is. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds