Can't remove final few Malware issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by amberH, Jan 20, 2010.

  1. amberH

    amberH Private E-2

    Hello,
    Thanks to your instructions to remove malware, I was able to get a completely non-functioning PC to run - but can't quite get it completely clean.
    I got SuperAntiSpyware working, and it now shows no malware when I run it.
    After much grief, I am now able to run Malware Bytes - it always comes up with 3 items - says it cleaned 2 and will clean the 3rd on reboot, but it always come up with the same 3 on a rescan.

    I am also unable to install AVG because it says Malware Defense is installed on the PC.

    The log from MalwareBytes:


    Any help would be greatly appreciated!

    A
     

    Attached Files:

    Last edited by a moderator: Jan 22, 2010
  2. amberH

    amberH Private E-2

    And here is the hijackthis log.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make.

    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Were you able to run RootRepeal and combofix? If so then please attach the logs from doing so into your next reply as I would prefer to see those also.

    2. Please disable frostwire from running at start-up whilst we are removing malware. :)

    3. You need to move MGTools.exe from your desktop now before we continue and put it where it belongs, directly on your C Drive.

    4. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.

    5. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    6. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    7. Now go to C:\MGTools and locate analyse.exe. Double click it to run it. Click on CONFIG > Mics Tools > click on Open Uninstall Manager > choose to "save list" save the log to your desktop and attach it into your next reply.

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger and also the uninstall list log.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. amberH

    amberH Private E-2

    Thank you so much for your help!
    I was able to run RootRepeal, log attached.
    I wasn't able to run combofix (nothing ever happened when I double clicked it)
    One thing to mention re: my logs - I didn't remove FrostWire from start up until after I ran these things. Will that screw things up? I wasn't sure if I should redo everything after I realized I missed a step, or not...

    Cheers,
    Amber
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    don't forget to let me know how things are running now! :) Reviewing your logs right now.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are using an outdated version of MGTools!

    Go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new MGTools.exe and attach the C:\Mglogs.zip that it creates.
     
  8. amberH

    amberH Private E-2

    Really? Whoops!
    I've ran the new MGTools and attached a new log.

    Since I've managed to get SuperAntiSpyware and MalwareBytes running - the computer SEEMS fine. (no popups - can go to any site I want). BUT - whenever I try to install AVG I get a message saying that Malware Defense is installed, so AVG is unable to install.
    The only other oddness is that SAS won't open in normal mode - just "alternative start".

    Thanks again for your help!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, then let's try clearing up some avg remnants to make a fresh start and we will also see what might be lurking of malware defense still, which is preventing you from installing avg or causing a very incomplete install.

    1. Now download Registry Search (see the link titled RegSearch Download Link)

    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • In the top 3 boxes under the Enter search strings case independen) and click Ok... option, enter the below string (use copy and paste)
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.


    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Attach the log from avenger and the log from RegSearch into your next reply. :)
     
  10. amberH

    amberH Private E-2

    Attached are the two logs.

    :)
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running it in safe boot mode, and also may I see the log from running SUPERantispyware?
     
    Last edited: Jan 23, 2010
  12. amberH

    amberH Private E-2

    It's good! Yahoo!!
    This time I was able to run SAS in regular mode and run ComboFix in regular mode. After these 2 ran I could tell something had changed because suddenly I was getting pop ups telling me I had no AV or Firewall installed.
    I installed AVG no problem.

    Thank you so much!!!
    :-D
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good to hear! I would still like to see the logs from both Combofix and SAS before I give you final steps. :)
     
  14. amberH

    amberH Private E-2

    oh oh - guess I got overexcited - and gave the computer back...
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK well don't panic, I was just making sure absolutely everything was covered, but those logs were looking good so not to worry :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds