I need some help removing my malware.

Discussion in 'Malware Help (A Specialist Will Reply)' started by louis cardinal, Feb 14, 2011.

  1. louis cardinal

    louis cardinal Private E-2

    okay i have done many of the steps in the post of the list to remove malware. (read me&run)

    nothing so far helps.

    i have some questions before I do go any further.

    Some information on my malware:

    when i first got it task manager was disabled by administrator, solved.

    i did my anti virus scan, found and removed all the bad stuff and then i had to restart my computer.

    Now i noticed many things new, atually plenty of things:

    whenever i turn on my computer CMD on start runs for 0.5 seconds and then disappears, something to do with my malware, i would like to know why.

    i remember that the malware file that i double clicked (stupid...) had a picture icon of a angry grey dog on it, not sure if this helps at all but perhaps may identify something.

    After restarting my computer as required after scanning+removing "all" of the malware detected by my anti virus, when i turned my computer on it took longer than usual followed by that CMD pop up for half a second.

    i commenced with a second computer scan just to be sure, for some reason my scan took X3 the amount of time longer than it used to, i am very angry as my performance has been hindered.

    as far as i know, my computer has still been tampered with even though my anti virus tells me there is nothing there.

    SO THESE ARE MY QUESTIONS THAT I WOULD LIKE TO BE ANSWERED PRETTY PLEASE:

    why do i get a CMD pop up at the start of turning on my computer after logging in?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Many of the steps? Which ones? Can you attach logs for me then please as I cannot answer your questions without seeing those.
     
  3. louis cardinal

    louis cardinal Private E-2

    On the (read me&run me)

    i have fully done parts:

    step 1

    step 2 was skipped because i only have one anti virus installed and one firewall installed (default one that windows 7 gives)

    step 3, looked in add and remove programs. no i dont have any of those.

    removal of quarantine folders? never heard of them and i cannot find them in my program folders of my anti virus. i think my anti virus software auto removes them from my computer and does not keep them.

    bin empty, as always.

    just about to install CCleaner and do the thing but as you know time flies and i am busy because i got to sleep for my next day of work. Timing is perfect when your in the middle of something aint it?

    Im just asking if theres anything i should know, i find that the CMD exe that runs every time i start up my computer are very strange, thats all.

    going to finish all steps soon.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not alot I can tell you as I said, until I see the logs. So as soon as you have the time to properly run through the procedures you can then attach the requested logs and THEN we can finally begin some actual malware removal. :)
     
  5. louis cardinal

    louis cardinal Private E-2

    okay sure, sorry for my naivety, I am a "noob" at computers.
     
    Last edited: Feb 14, 2011
  6. louis cardinal

    louis cardinal Private E-2

    oh my goodness please someone help.

    my music folder, pictures, videos and others give me a error message that its denied, when i try to go to the options and allow full control it gives me even more "access denied"

    HELP I HAVE PRECIOUS FILES NEEEDED!!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about the logs? I ask you again: Did you run anything at all from our procedures? The longer you wait the worse things could be. I have no idea what is going on with your system because you have not attached any logs for me at all!
     
  8. louis cardinal

    louis cardinal Private E-2

    sorry if this sounds stupid (probably does)

    which logs do i show?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Take a look at this:

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  10. louis cardinal

    louis cardinal Private E-2

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I refuse to respond to this thread any further until you have done what I have asked. In order for me to help you, you need to help yourself! We could post back and forth like this for days (already we are 11 posts in and no actual malware removal has even been started.)

    Your request for help:
    Do you require my assistance or would you prefer to visit the software forum (if getting involved in discussions is what you wish to do?)

    In short, attach logs or I shall have to close the thread and you will have to begin a new one as this one will be far too lengthy. :) Thanks for understanding.
     
  12. louis cardinal

    louis cardinal Private E-2

    please dont close the thread.

    i have done all steps well except for the last one, im going to do this one tomarrow. (#7)

    step 7 looks lengthy and its the end of the day for me so i will report back to you later, sorry for any "off topic" like behaviour in the malware removal section of the forums.
     
  13. louis cardinal

    louis cardinal Private E-2

    okay i used superantispyware (SAS)

    i attached my log. No threats found during my 55 minute scan (god that took long).

    i have very limited time so i will reach back and show you some more logs of using the other software later.

    Does this tell you anything? it didnt detect any threats.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All it tells us is the same thing it told you.... nothing was found in that scan.
    Once you have attach ALL of the logs, we can begin. I suggest that you do not make anymore posts until you have completed the whole READ & RUN ME procedure as we need all of the logs to properly analyze your PC.
     
    Last edited by a moderator: Feb 16, 2011
  15. louis cardinal

    louis cardinal Private E-2

    Okay i have dont the entire read&run me instructions.

    attachments below.

    the rootrepeal didnt work, it has an error code and this occurs when i open it and attempt to scan with it.

    doesnt work.

    the SAS (superantispyware) is on a previous post.
     

    Attached Files:

  16. louis cardinal

    louis cardinal Private E-2

    wow amazing, combofix is legendary, im not getting those anonymus suspicious CMD files appearing at my computers startup anymore, it appears to be the problem has been solved but.

    with the info from my logs do you think it is safe for me to:

    use my accounts again? (steams... email... online purchasing)
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. If you uninstalled AVG before running Combofix but have since reinstalled it, you will have to uninstall it again as we are going to use Combofix.

    2. Uninstall the below outdated Java.

    • Java(TM) 6 Update 16
    • Java(TM) 6 Update 23

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O4 - HKLM\..\Policies\Explorer\Run: [Policies] c:\directory\CyberGate\install\server.exe
    O4 - HKCU\..\Policies\Explorer\Run: [Policies] c:\directory\CyberGate\install\server.exe
    O15 - ESC Trusted Zone: http://*.update.microsoft.com
    O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
    O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe

    After clicking Fix exit HJT.

    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\directory
    C:\Users\User\AppData\Roaming\Template
    C:\Program Files\Common Files\DESIGNER
    Driver::
    ASKService
    ASKUpgrade
    File::
    c:\directory\CyberGate\install\server.exe
    Folder::
    c:\directory\CyberGate
    c:\program files\AskBarDis
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
    [-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    [-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    5. Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    6. Please download and run Malware Bytes, you seem to have skipped that step for some reason. Attach the log once you have it.

    7. Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    8. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    9. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  18. louis cardinal

    louis cardinal Private E-2

    thanks so much these forums are great.

    I had some problems/irregularities during the instructions you have given me.

    This was for HJT:

    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O4 - HKLM\..\Policies\Explorer\Run: [Policies] c:\directory\CyberGate\install\server.exe
    O4 - HKCU\..\Policies\Explorer\Run: [Policies] c:\directory\CyberGate\install\server.exe

    O15 - ESC Trusted Zone: http://*.update.microsoft.com
    O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
    O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe

    two Q4 above that are bold, i couldnt find this when i scanned strangely.

    removed the rest successfully.

    Also... i am not sure yet.

    i am free to go yet :cry

    :confused i want to order my portal 2 via steam, help me before the promotion expires XD!
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds