Cannot run all the Removal Steps, still having problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by schmitz5, Sep 28, 2009.

  1. schmitz5

    schmitz5 Private E-2

    I first noticed a problem Saturday 9/26/09. To the best of my memory, I got redirected to a website on saturday that my antivirus said was malicious. I use AVG 8.5 but when I left the site my computer began giving warnings that it was infected. My browser started to open what appeared to be inocuous websites. I went to my AVG and ran it. It detected a virus and a couple of Trojans and deleted them but I got an errror mssg after trying to delete the other files it detected. When I tried to run the AVG again, it appeared fine but wouldn't start a scan. I went to Major Geeks and downloaded various spyware removers and a virus remover, i.e AVIRA which detected and deleted some torjans and/or viruses, AdAware which also deleted some malware and Spybot Search and Destroy which errored with a message that it would not run because I lacked the special priveleges. I was still having trouble with AVG so I deleted it and reinstalled, at first it would get error messages and wouldn't allow me to delete it but I eventually got it to delete. I reinstalled and ran a scan again. Subsequent to that, I was unable to run again and unable to delete it. I went to your forum and followed the malware removal instructions. SuperAntispyware ran well and found infections that it deleted but Malewarebytes wouldn't run, If memory serves, it would start but the quickly disappear from the screen. ComboFix, Rootrepeal and and MGTools all ran well. Unfortunately I am still having the same problem. Internet function well thus far but I am unable to run AVG scan, SpyBot S&D and now am unable to open SuperAntispyware to retrieve my log so I am unable to include that.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You don't need to run it to attach the log. The log is already save to the below location. Just attach it.
    Code:
    "C:\Documents and Settings\Gary.CHLOEII.001\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Sep 27 2009 1073 "SUPERAntiSpyware Scan Log - 09-27-2009 - 12-11-22.log"

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now we need to reset the permissions altered by the malware on some files.
    • Download this tool and save it to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). While this is running, you will get several/many popups that have a title FInish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Now see if you can run scans with Malwarebytes and SUPERAntiSpyware.


    Now attach the below logs:
    • C:\ComboFix.txt
    • logs from Malwarebytes and SUPERAntiSpyware if they ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Oct 3, 2009
  3. schmitz5

    schmitz5 Private E-2

    Thank you for your response. I have attached the SUPERAntispyware log from 9/27/09. I have also run the Items you requested. Everything went well except the SuperAntiSpyware that still won't run. I uninstalled it and downloaded it again. During the install process for it I got an error that said "Error 1321 Windows Installer has insufficient priveleges to modify this file: C:\Program Files\SUPERAntiSpyware\SuperAntispyware.exe" I was given the options abort, retry or ignore. I tried "retry" and got same error so I tried "ignore". The install completed and when I tried to run the program I got an error that said "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to Access the item." After this I tried to go to the "start" menu and typed "gpedit.msc" and got a message that "Windows can't find "gpedit.msc" Make sure you typed it correctly and then try again". In short, I was able to run Malewarebytes this time but AVG still won't run a scan and was not able to run SuperAntispyware scan even with the alternate scan.

    I also tried to download Spybot S+D again. During the install I get the error C:\Program Files - Search and Destroy\SpybotSD.exe The existing file is marked as read only. Click retry to remove the read only attribute & try again, Ignore to skip or abort to cancel install" I tried retry first and got same error then tried skip at whch point the install completed but when I tried to run the program I got the message:"Unable to execute file: C:\Program Files - Search and Destroy\SpybotSD.exe. Create process failed; code 5. Access denied." After this I tried to uninstall Spybot on the remove program menu. After a restart of the computer there were still Spybot files remaining that could not be removed, I got a message that said "Cannot delete SpybotSD.exe:access is denied. Make sure the disc is not full or write protected and that the file is not currently in use"

    Thanks again for your assistance. I'll await your reply.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please only do what is requested. For example, I did not ask you to reinstall SUPERAntiSpyware nor Spybot. Doing things we do not ask for will most frequently cause more problems and will delay getting finished.

    When you ran FixPerm.bat, did you get lots of popups to OK?

    Try the below:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r
     
  5. schmitz5

    schmitz5 Private E-2

    Sorry about that--thought I was being helpful

    yes I did


    --Took me a while to figure this out, I'm not very computer savvy and did this wrong a couple of times until I figured how to save direct to C:\WIN32...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log.txt file from exeHelper
    • a log from the online scan if you could get one
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. schmitz5

    schmitz5 Private E-2

    SuperAntiSpyware found some tracking cookies but nothing else. AVG still won't run a scan.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Back in message # 4 I requested the below
    Why have you now deleted inherit.exe from you Desktop that was previously downloaded? We may not really be finished using.

    Also in my last instructions I asked you to run C:\MGtools\GetLogs.bat, but you ran C:\Documents and Settings\Gary.CHLOEII.001\Desktop\Anti-Malware stuff\MGtools.exe

    This file does not even belong on your Desktop ( it should be C:\MGtools.exe ) and I did not ask you to run it. Please delete it now and please follow instructions properly and only do what is requested.

    Now download and run the below AVG Removal Tool

    AVG Remover(32bit)

    After running it, it should ask you to reboot. Make sure you immediately reboot your PC.

    After reboot, download, install and update AVG from this:AVG AntiVirus Free Edition

    Does it run properly now?
     
  9. schmitz5

    schmitz5 Private E-2

    I didn't delete it. After I ran it, I placed it in a folder on my desktop called Anti Malware stuff in an attempt to organize my desktop. I have now moved it back to my desktop. I didn't realize this would cause a problem. Sorry.

    When I downloaded MGtools originally it said to save it to root folder. I have no clue what a "root folder" is and even tried Googling it to figure it out. At that point, I punted and saved it to my desktop. I ran it because I could't figure out what C:\MGtools\GetLogs.bat was or how to locate it, and I was therefore unable to double-click on it. I figured that if I ran MGtools.exe, it would run the requested program. My bad.

    I deleted it.

    I am not intentionally disobeying instructions. I appreciate the service that you are providing but understand that tasks that are simple and obvious to you can be difficult for some to understand.

    done


    done

    It ran and did not detect any threats, just some tracking cookies. It placed 2 icons on my desktop (both are shortcuts to AVG Anti-Virus free Edition). One is labeled AVG 8.5 and the other is labeled AVG Free 8.5. Not sure why there are 2.

    Is there any good reason to reinstall my paid version of AVG anti-virus or will the free version accomplish the same thing?

    Again, I realize that you are not paid to help computer novices like myself fix the troubles that we get into and I really do appreciate all of your help. This has been quite a learning experience for me.

    I will await your next communication before I do anything further on my computer with regards to malware.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which is why I previously said, "Please only do what is requested." Which was also stated in the READ & RUN ME.

    Yes it said the below
    C:\ is the root folder of your hard disk. Root means the highest level folder where everything traces back from (i.e, roots ;)). If you did a search on root folder you would get many many hits so I'm not sure how you searched. Just look at the output from the below:

    http://www.google.com/search?q=root%20folder



    C:\MGtools is a folder link directly to the root folder. I guess your problems stems from the fact that you do not know how to use Windows Explorer (the Windows file manager) which some people mistakenly also call MyComputer since it is one way of seeing Windows Explorer. If you are going to use Windows, you need to learn how to use Windows Explorer. There are many ways to open up Windows Explorer from which you can navigate thru files and folders on your PC. Here are a few examples besides double clicking My Computer:
    • press the and hold the Windows key on your keyboard and then hit the "e" key (for Windows Explorer)
    • right click Start and select Explore
    • click Start, Run, and enter explorer into the run box and click OK.
    When Windows Explorer opens up navigate to Local Disk (C:) and expand the contents by clicking the plus sign. You will see in the list of folders the C:\MGtools folder appears. If you click on MGtools, you will notice the right window pane will list the contens of the MGtools folder. In this folder you will see many files, one of them is the GetLogs.bat file that my instructions had asked you to double click on. If you do this now, you will see that it will run.


    Yes your paid version had more features that you may want. I just wanted to make sure we could resolve your problem. I suggest that you now use Add/Remove Programs to uninstall AVG Free and then run the removal tool again to make sure all is removed. Then reboot your PC and reinstall your paid version to make sure it works properly.


    Are you having any more malware problems?
     
  11. schmitz5

    schmitz5 Private E-2

    I have reinstalled AVG and everything seems to run well now. Thanks for your explanation on root folders. I ran C:\MGtools\GetLogs.bat and have attached it in case you need to see it. I plan to follow the instructions on your site to protect my computer from malware as soon as you give me the go ahead.

    Thanks for your help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. schmitz5

    schmitz5 Private E-2

    I ran each of the steps you recommended. The only problem that I encountered was installing and running Spybot SD. I have used this product in the past on a different laptop. I had tried to install it prior to first contacting you for this mess I got myself into and had trouble with it so I removed it. My current problem occurs during installation.

    When I try to install, I get an error:
    " C:\program files\Spybot Search and Destroy already exists. Would you like to install to that folder anyway?" to which I respond yes.

    I choose the options to install both the SDHelper and Tea Timer.

    Setup goes well but during installation I get this error:
    " C:\program files\Spybot Search and Destroy\SpybotSD.exe
    The existing file is marked as read only.
    Click retry to remove the read only attribute and try again, ignore to skip this file or abort to cancel installation"

    If I choose retry, I get the same error again. If I choose ignore, the installation completes but when I click "finish" to exit setup I get this:
    "unable to execute file:
    C:\program files\Spybot Search and Destroy\SpybotSD.exe
    Create process failed code 5
    Access is denied"

    If I try to run SpybotSD I get:

    "Windows cannot access the specified defined path or file. You may not have the appropriate permission to access the Item"


    I have deleted Spybot SD from my computer using “Add or Remove Programs” in Windows but it leaves a file behind:
    "Spybot Search and Destroy" in C:\Programs

    It is marked as “read only” in properties and if I try to uncheck the “read only” box, it seems to allow but when I return to properties it is checked again. I don’t know if this means anything, but it is not checked with a checkmark. Instead it is marked with a small shaded box within the check box.

    The subfiles within this folder are:
    advcheck.dll
    SDHelper.dll
    TeaTimer

    Neither the folder nor the subfiles will allow me to delete them. The subfiles are not marked “read only” in properties and none of them allow me to delete them. When I try to delete, I get:

    “Cannot delete SDHelper.dll (or advcheck.dll or TeaTimer) Access denied. Make sure the disk is not write protected and that the file is not currently in use”




    I would really like to be able to intall and use Spybot SD but more importantly, I want to make sure my computer is not screwed up. Any help you can offer is appreciated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Spybot!

    Then boot into safe mode and see if you can delete the C:\program files\Spybot Search and Destroy folder. If not, try using inherit.exe which we previously used and drag the folder ontop of inherit.exe Then see if you can delete it.

    And don't install Teatimer!
     
  15. schmitz5

    schmitz5 Private E-2

    It worked. Thank you for your time and help.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds