help with malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by devil_jester, Aug 31, 2011.

  1. devil_jester

    devil_jester Private E-2

    I was using my limited user account while chatting with a friend using yahoo messenger and surfing allrecipes.com and all of a sudden some scan was running in the background. Immediately, I knew it was some bug but I don't remember going to any link or purposely downloading anything. So I scanned with malwarebytes and superantispyware. It captured some bugs so I restarted and logged into that limited user. The second time I logged in, all these other bugs started coming out, like for example fake scans and fake alerts about my hard drive that can't be detected. Out of frustration, I deleted the limited account user that was infected while on my administrator account.

    I'm currently on my administrator account and now every startup it says that my ATI Catalyst isn't working or has been disabled. I don't even know how to do that so I'm sure I didn't do it. It was showing that same message with the limited user account that I had already deleted. Thinking that by deleting the infected user I was fixing the problem and obviously I was wrong.

    I ran the suggested scans, I wasn't able to run combofix since at time I was following the steps it said that the link from bleepingcomputer wasn't available. I also didn't run rootrepeal since I have a 64bit system.

    I also tried to look for the log for superantispyware but there wasn't any on the log tab. So I'm only able to attach logs for malwarebytes and mgtools.

    I probably did stuff wrong, I'm sorry. I need help with what to do next. Thank you in advance! :)

    P.S. I forgot to tell you about my system sorry.
    *Win7Home 64bit
    *i7 720QM
    *1GB ATI Radeon 5650 for quadcore
    *6GB RAM
    *640GB HDD split into 2 physical hdd
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you using for AV protection?

    Use windows explorer to find and delete:
    C:\ProgramData\P1kAlMiG2Kb7Fz

    See if you can run Combo from here:
    ComboFix.
     
  3. devil_jester

    devil_jester Private E-2

    I used to use AVG but it messes up any download I attempt so I got rid of it. I shamefully don't use any AV :-o

    I pretty much really on superantispyware and malwarebytes when I have issues with bugs. They have been good so far unless it's a really bad bug. I also have windows defender but I don't have much confidence in that.

    I was able to run combofix and I'm attaching the log. Also, I don't want to jinx myself but after running combofix the alert that says my "ATI catalyst is disabled" doesn't pop up anymore.

    Please tell me if I need to run anything else. Thank you once again to your team of experts. :)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go HERE. Download the version for your computer and run it.

    Your logs are looking good, so after running the above, let me know how things are running.
     
  5. devil_jester

    devil_jester Private E-2

    I wasn't able to load the security essential, it kept on giving me errors even after trying all their solution suggestions.

    So far no more pop ups or weird fake alerts/scans. Shall I continue with the remaining steps for malware removal? I'm currently headed to step 5 :)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. devil_jester

    devil_jester Private E-2

    I got avast for AV and did a quick scan, so far it said no threats found. Can I continue with the removal steps and also restore previous set ups? Thank you
     
  8. devil_jester

    devil_jester Private E-2

    I don't know if this is still related but after everything, I tried to create a new limited account user and when I tried to log onto that it would say that it can't load the profile. Is this part of the malware problem? How do I fix this? Thank you!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't believe it is a malware issue. I will probably send you to the software forum for assistance with that issues. However, let's take one more look at your logs:

    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  10. devil_jester

    devil_jester Private E-2

    Thanks for all your help! I actually posted my question about the user account in the Software forum. Hopefully someone can help me there. Anyway, I'm attaching the log you requested
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, your logs are clean. You might try enabling the Admin. account and then see if you can create a user account:

    * First you'll need to open a command prompt in administrator mode by right-clicking and choosing "Run as administrator"
    * Now type the following command:
    net user administrator /active:yes


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  12. devil_jester

    devil_jester Private E-2

    Thank you again for all the help! I'm thinking of purchasing SAS and MalBytes :)
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds