Gone from Virus to Plague!

Discussion in 'Malware Help (A Specialist Will Reply)' started by kdegs, Nov 17, 2008.

  1. kdegs

    kdegs Private E-2

    It started last week when AntiVirusPro got past my McAfee. Since then I have tried everything with deteriorating results.

    No internet access so I have to use another computer.
    The computer virtually freezes in normal mode so I can only run in safe mode.
    I have tried desperately to follow the "Read and Run" but I can't complete many of the steps.
    Can't uninstall Java
    Can't install SpyBot - Error Message: "Server name could not be resolved"
    Can't update any spyware because of lack of internet access.
    Can't stop writing in bullet point format.

    The only logs I was able to generate were with combofix, malwarebytes and mg tools.

    Thanks in advance for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try this...

    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):


    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
    Last edited: Nov 18, 2008
  3. kdegs

    kdegs Private E-2

    Thanks Tim. I'll give it a try. However, as I mentioned I can only run the computer in Safe mode and in that mode it will not allow me to remove the Java program.

    Will your other suggestions still work without that step?
     
  4. kdegs

    kdegs Private E-2

    Also, how do I disable a User account?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We can skip those until we are farther along the removal process...go ahead and do the rest

    (Note= I had a formatting problem in the quote box for avenger, but it is fixed now)...

    Mainly you need to do the avenger fix and then get me the new logs.
     
  6. kdegs

    kdegs Private E-2

    Tim-

    Did as instructed absent the Java and User Account issues we discussed previously. Logs attached.

    Still can only run in "Safe Mode". Desktop freezes in normal mode.

    Thanks again.

    KD
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running more than one anti-virus programs....you should only be running one:
    Norton Security Center
    McAfee SecurityCenter
    Kaspersky Internet Security 7.0

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.

    Can you now boot to normal mode...what happens if you do, exactly.
     
  8. kdegs

    kdegs Private E-2

    Tim-

    You are the MAN!!

    Was able to startup in normal mode and access the internet. So far so good.

    Logs attached as you instructed.

    Standing by for your next command, sir.

    KD
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Only one item showed up in your logs, so use windows explorer to find and delete:
    C:\WINDOWS\system32\pevagope.dat

    Now you should be able to uninstall the old java and after a reboot install:
    Java Runtime

    To disable the guest account...go to the control panel / user accounts / click on the guest account and disable it.

    If you are not having any other malware issues, then:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds