Help removing malware, please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by echappee, Oct 30, 2015.

  1. echappee

    echappee Private E-2

    Dear Major Geeks

    My laptop has a weird trojan that I believe is the Zero Access trojan (determined by looking at the logs.) When I try to start some programs I get an error saying that the "security.dll is not a valid Windows file." Research led me to believe that the computer is infected. Log files are attached.

    Thanks for your help!
    Ed Chappee
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, echappee

    Re-run HitmanPro, activate the 30-day trial license and fix these detections:
    Malware
    Potential Unwanted Programs


    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest HitmanPro log

    Please re-run RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button.
    Then delete everything shown under the Files tab.
    Afterwards immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in the original instructions and attach the new log.

    Please download the latest version of

    Farbar Recovery Scan Tool
    and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it also to your reply.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select "Run As Administrator").

    Then attach the below logs:
    • updated Hitman Pro log.txt
    • updated RKreport.txt
    • FRST.txt
    • Addition.txt
    • C:\MGlogs.zip
     
  3. echappee

    echappee Private E-2

    Here are the logs as requested/

    Thanks again! Your assistance is greatly appreciated!

    Ed Chappee
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    These outdated programs should be uninstalled:
    Java 2 Runtime Environment, SE v1.4.2_03 <= outdated software
    Spybot - Search & Destroy Version: 1.6.0 <= outdated software

    Your logs are clean but I'm sure you know Windows XP is also outdated and hasn't been supported by Microsoft for about 18 months now. Personally, I wouldn't connect this machine to the internet again, even with full backups/images. It's a matter of when and not if it will be re-infected.
    _____________________

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  5. echappee

    echappee Private E-2

    Hi Dr. M,

    Thanks again for your assistance. Your comments regarding the XP OS are understood.

    I am unable to uninstall the programs you requested that I remove. When I try to remove these programs I get an error saying: Error 1327 Invalid Drive: F:\.

    Also, I am still having the issue that originally brought me here. When I start the programs I need to run in this computer, I get the error that says that the "security.dll is not a valid Windows file"

    Anything else I can do to eliminate this error?

    Thanks,
    Ed
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please view this article: http://answers.microsoft.com/en-us/...e/be444176-5c67-4271-9ccf-9fb3dec0834a?auth=1

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right click FRST and run it as admin.
    • Click the FIX button.
    • A report should pop up, please attach it here in your next reply.
    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. *Do not do anything while it is running or it may stall the program.
     

    Attached Files:

  7. echappee

    echappee Private E-2

    Hi Dr. M,

    I am still getting the security.dll is not a valid windows image error when I start some programs.

    Log files from FRST and Combofix are attached.

    On a good note, I was able to remove the other programs...

    Thanks again for your assistance!
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Last edited: Nov 3, 2015
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, echappee

    Using the previous steps to run FRST , next do this:
    * Type the below bolded text in the edit box after "Search:".
    security.dll;sendmail.dll
    Then click the Search button.

    A progress bar will show the search has began and a pop up message will indicate when the search is completed. The Search.txt log is saved at the same location that FRST.exe is located. Please attach it to your next reply. HOW TO: Attach Items To Your Post
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds