Houston, have a problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by 1liter, Mar 19, 2009.

  1. 1liter

    1liter Private E-2

    I've gone through all the steps and still am having issues. PC speeds still slow and still showing infections on SAS. SAS goes through the cleaning process and reboot. But infection remains. Thanks for any assistance.
     

    Attached Files:

  2. 1liter

    1liter Private E-2

    Additional report.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    You missed this in the READ & RUN ME FIRST. Malware Removal Guide
    *You also need to attach the 4th requested log -

    MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    Once you have completed attaching your logs - we will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks!
    dr.m
     
  4. 1liter

    1liter Private E-2

    Thanks for your response. I could not uninstall AVG, kept coming up with an error message. Finally got rid of it.
    Secondly, I cannot find cyberdefender anywhere on my computer. I did a search, and only found old .txt, no program. Went through MSConfig and couldn't find it in start up either. How can I find this program and get rid of it?

    Still getting the Peopleonpage hit on SAS...
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, 1liter

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    *Notes: I've found nothing pertaining to CyberDefender in your logs. We think that this is a false signal from ComboFix.

    Step 1:
    Using Windows Explorer, navigate to c:\windows\system32\drivers\C4C_BSC2.sys > right-click on Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important item is the company name. If there is no Version tab, tell me that too.

    Step 2:
    To be sure AVG is completely gone, run this tool and re-boot.
    AVG Removal Tool

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    New versions of SAS & MBAM has been released.
    Uninstall SAS > run CCleaner > download and update the latest version. Also - update MBAM.

    Step 4:
    Now run both SAS & MBAM scanners

    Step 5:
    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • SAS.txt log
    • MBAM log
    • C:\MGlogs.zip

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  6. 1liter

    1liter Private E-2

    Thanks Dr. M,
    Followed your directions. Didn't seem to have any problems with your instructions.
    Step 1; Here's the info requested for the file c:\windows\system32\drivers\c4c_bsc2.sys.
    File version: 4.6.14.0
    description: Fallback Driver
    Copywrite@conexant systems 2002
    company: Conexant suystems
    Internal Name: Fallback sys.

    Step 2: AVG removal completed.

    Step 2:Ran MGTools and deleated the two files you mentioned.

    Step 3-4: unistalled SAS and Mbam. Ran CCleaner. Appears to be the same versions as I had previously. Updated the new installs and ran them.

    Step 5: attached logs


    Computer is doing better, but is still not functioning as well or as quickly.
    Not sure if this is useful to you or not. I have been following my progress by going to speedtest.net. I generally ran at the high 15000 to low 16's in down loads. When severely infected downloads were around 2000. Currently running in the 8000's to low 9's now.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, 1liter

    *WARNING! Both McAfee SecurityCenter and STOPzilla had "real-time" antispyware blocking... you should only have one installed.

    Step 1
    Please download and run this tool > re-boot > run it a second time
    Norton Removal Tool (SymNRT) 2009.0.5.26]

    Step 2
    Please look in Add/Remove Programs for the following and uninstall:
    STOPzilla

    Step 3
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4
    Run Ccleaner

    Step 5
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  8. 1liter

    1liter Private E-2

    Wanted to say a huge thank you Dr. M.. My puter is back and working quickly. All scans show negative mal-spy-virus related crap and running as it should.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Glad to hear that!

    Please attach the requested logs so I can give your machine one last look. And if everything's clean -- I'll post our final clean-up steps.

    dr.m
     
    Last edited: Apr 9, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds