didnt get it all, Antivir Solution Pro is back!!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by dewdesigns, Aug 1, 2010.

  1. dewdesigns

    dewdesigns Private E-2

    ok this is getting old, I have ran the complete cleaning system you have recommended twice. now 2 weeks later this thing is back, and since the first time I used read and run my IE does not work. my last post was( help comp is down ) you can look at every thing we done to clean it up. does anyone have any new Ideas?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never completed your last thread with TimW. He replied to you on 7/24/10 and you did not answer.

    Two weeks on the internet is a long time and we need to know the current status of everything on your PC. The READ & RUN ME provides us with this status so please rerun the cleaning procedure and attach the 5 requested logs. We will go from there.
     
  3. dewdesigns

    dewdesigns Private E-2

    thats because I didnt know he replied again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's up to you to check your threads for answers.;)
     
  5. dewdesigns

    dewdesigns Private E-2

    ok I try it again. as soon as I figure out how, it wont let me in to any thing.
     
  6. dewdesigns

    dewdesigns Private E-2

    I thought we were done he told me to go to another forum.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At one point your were; however; you continued to post and he continued to answer.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not even in safe mode?

    Are any of the previous programs on your PC or had you run final instructions to remove MGtools?
     
  9. dewdesigns

    dewdesigns Private E-2

    ok my bad with Tim W.
    not even in safe mode. I ran final clean up. Last time I was able to out smart it by putting malwarebytes on stick and got it to run before ASP came up on start menu. will try that again.
     
  10. dewdesigns

    dewdesigns Private E-2

    hey while down loading mgtools kapersky said there was a trojan in the read and run me post....:MGTOOLS.EXE TROJAN DROPPER.WIN32.AGENT.cmdw.
    might want to chech to make sure.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is a direct quote from the Using MGtools instructions link in the READ & RUN ME. ;)

     
  12. dewdesigns

    dewdesigns Private E-2

    I didnt say it blocked the download, it downloaded just fine, it blocked the trojan trying to go thru the download.

    here is 2 of the logs SAS & Mbam.
     

    Attached Files:

  13. dewdesigns

    dewdesigns Private E-2

    ok here are the other 3 logs.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My point is that there is no trojan so what you are saying is incorrect since there was not trojan in the download. Kaspersky is just totally incorrect!!

    You need to stop downloading files into your C:\Program Files folder as show below. They do not belong here and will be suspected to possibly be malware. In addition, we specifically requested some of these like MGtools and RootRepeal to be saved on your Desktop or in the C:\ root folder.
    Code:
    2010-08-02 00:45 2394045 ----a-w- c:\program files\MGtools.exe
    2010-08-02 00:44 464491 ----a-w- c:\program files\RootRepeal.zip
    2010-08-02 00:29 6153376 ----a-w- c:\program files\mbam-setup-1.46.exe
    2010-08-02 00:04 9190248 ----a-w- c:\program files\SUPERAntiSpyware.exe
    2010-08-01 22:39 16409960 ----a-w- c:\program files\gotcha.exe
    2010-04-19 20:00 16529184 ----a-w- c:\program files\jre-6u20-windows-i586-s.exe
    2008-12-12 20:59 270128 ----a-w- c:\program files\utorrent.exe
    2008-01-22 10:59 32981120 ----a-w- c:\program files\avg75free_516a1225.exe
    2008-01-22 10:46 2733928 ----a-w- c:\program files\ccsetup204.exe
    2007-02-18 00:53 2855080 ----a-w- c:\program files\aawsepersonal.exe
    In fact, gotcha.exe is already assumed to be malware ( see:http://spywarefiles.prevx.com/RRBJEH946304/GOTCHA.EXE.html )
     
    Last edited: Aug 3, 2010
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a little more to fix.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5643
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. dewdesigns

    dewdesigns Private E-2

    ok, hopefully this worked. here are the logs.

    still get a blank white screen on IE for yahoo.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Your PC did not appear to have a network connection when you ran the last scans. You really should have it connected so that scans can collect proper information. Or do you have a problem connecting to the internet?

    If IE is only giving you a white screen on yahoo.com, and not for any other address, the problem is on your end. Perhaps you are blocking connection in your firewall or somewhere else. Maybe even a hosts file problem. Have you tried connecting via IP address rather than via URL?
     
  18. dewdesigns

    dewdesigns Private E-2

    thats odd, it is always connected to the internet. I have checked every thing I can think of on my end, nothing seems to be blocking it. when I try to update IE at the yahoo or the microsoft pages. they both say cannot update because I have Vista and firefox. my ops is xp pro s3 and normally use IE. something else is wrong I just dont know what it is. Every thing worked fine until this virus showed up about 2.5 months ago, it has come back twice.
     
    Last edited: Aug 4, 2010
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have no problem connecting then all should be good but your logs did show the below indicating that you could not ping google via IP address nor via URL which would indicate no connection was available or something is blocking ping ( like your firewall ).

    You cannot update IE at yahoo. You need to update it at Microsoft and you need to use IE to update. You cannot use FireFox to get updates from Microsoft. For any additional questions/problems about IE or Windows Update, please post in the Software Forum. There are many many causes for Windows Update issues and many are not due to malware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. dewdesigns

    dewdesigns Private E-2

    ok Ill clean up. IF you go to yahoo downloads you will see IE 8 optimized for yahoo. It is a upgrade. I said when I go to microsoft to update the update page says it cant, because I have firefox as a browser and not IE.

    Thank you for the help.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds