Can't Elim Win 7 Antispyware and others

Discussion in 'Malware Help (A Specialist Will Reply)' started by LMarvet, Dec 1, 2011.

  1. LMarvet

    LMarvet Private E-2

    I have a Dell laptop running Windows 7. From about 5 days ago, on the main account, when I try to open a browser it either doesn't open or it opens a "Win 7 Antispyware 2012" window, saying there is malware and to buy the software. Since yesterday, when trying to open almost any program, the "Open With" dialog opens but the program doesn't run (even from the dialog).

    I am now writing from the same machine's admin account, which seems to be running ok for some reason. I followed the guidelines in the Read and Run Me First post. Per the Vista & Windows 7 Malware Removal/Cleaning Procedure, I have posted the requested logs. (I didn't run RootRepeal cause 64bit OS.)

    Thank-you in advance for the help fixing these problems.

    Larry
     
  2. LMarvet

    LMarvet Private E-2

    Sorry, the attachments didn't seem to stick. Will attach later when I get home. L
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will be here when you are ready.
     
  4. LMarvet

    LMarvet Private E-2

    OK, here are the enclosures. Must not have clicked the "upload" button the first time.

    Thanks again for the help!

    Larry
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much in the way of malware, but let's do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    ClearJavaCache::
    KILLALL::
    
    File::
    C:\ProgramData\121518b2t827b281r656r4vbi8m1
    C:\Users\Jenna\Local Settings\TEMP\is1598539481
    C:\Users\Jenna\Local Settings\TEMP\Jjg4gODa.rar.part
    C:\Users\Jenna\Local Settings\TEMP\udcRjDqI.exe.part
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. LMarvet

    LMarvet Private E-2

    Thanks, TimW! I will follow the directions when I get home.

    One thing I haven't mentioned and not sure if important: I ran all the cleanup activities per the attached logs using the admin account, not the main user account. I did this because the main user account isn't working too well, obviously. However, I was thinking that all these software routines looked at the whole computer, so it wouldn't matter where I launched them from. If that is incorrect, let me know and I will try again.

    Larry
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just to be sure, re-run the instructions on the user account that is being problematic. ;)
     
  8. LMarvet

    LMarvet Private E-2

    I can't do anything from that account now. Any program I try to run just starts an "Open With" dialog that, even if I browse to the executable, doesn't run the program. I tried the portable edition of SAS from a memory stick, same thing. Not sure how to bypass this latest bug, so I will work from this admin account (which seems fine). I will follow the last directions you gave. Will post results when available.

    L

    Note: as I was logging out of admin to try the cleanup routines on the main account, I noticed that Avira had found a bug. Here is the log notice:

    The file 'C:\Users\Jenna_2\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\939556b-6df35110'
    contained a virus or unwanted program 'EXP/CVE-2010-0840.FI' [exploit]
    Action(s) taken:
    The file was moved to the quarantine directory under the name '4aa3c7f5.qua'.
     
  9. LMarvet

    LMarvet Private E-2

    I ran per your instructions using the admin account, since the other is completely hosed (for now). I have enclosed the MGlog and also the combofix log (not sure you needed or not).

    Logging back into the main account, it is still not working. Can't open a browser, can't open a program. Can open IExplorer right clicking on the Windows button, but that's it.

    Let me know next steps, please. Thanks!

    Larry
     

    Attached Files:

  10. LMarvet

    LMarvet Private E-2

    In the below post I said I could open IExplorer, but I meant Windows File Explorer. Sorry.
    L
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I assume you are using the Jenna account and the Jenna_2 account is the one that is hosed. If so, just delete it.

    What malware issues are you still having, if any?
     
  12. LMarvet

    LMarvet Private E-2

    Tim,
    Deleted the account, started a new account--everything seems great! A strange ending in my experience. What do you think happened?

    I would guess that there was the Win7 Antispyware bug to start, then when I ran the cleaning routines, it was eliminated. What I don't understand is why the problems still persisted in that specific account and not the admin or the new accounts.

    Anyway, thanks for your great help!

    Larry (and Jenna)
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I really don't know how that account became corrupted. But good to know you are running smoothly now.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  14. LMarvet

    LMarvet Private E-2

    All done, thanks again!

    Larry
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds