Maleware Suspected...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lwhitneysmith, Mar 8, 2011.

  1. lwhitneysmith

    lwhitneysmith Private E-2

    I suspect there is Malware on my computer. I have seen some things periodically pop up and because my computer is older, I was able to see them. Such as, a pop up I saw, it looked like the command prompt, and then it disappeared. So I read and run me first Malware Guide and here are my logs. My credit card has been used once in February (Which may have come from my laptop) and someone used my Yahoo.com mail to send a porno type link email to my address book. So I will be trying to fix both computers. And a BIG Thanks for the help!

    I am having trouble finding:
    combofix.txt
    RRlog.txt

    rolleyes

    Lisa
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Also please run Combofix as per the instructions in the R&R and attach the log for that too.
     
  3. lwhitneysmith

    lwhitneysmith Private E-2

    OK Got it. Will download new SuperantiSpyware. And attach that new log.

    Having a hard time with AVG and running Combofix. I have tried everything on your site to disable AVG, but still having a problem with the combofix. Should I uninstall the AVG, then run Combofix, then reinstall AVG?

    Thanks!
    Lisa
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you will need to uninstall AVG:

    Please go here and download and run the AVG Removal Tool.

    Leave it uninstalled until Kes tells you to reinstall it.
     
  5. lwhitneysmith

    lwhitneysmith Private E-2

    OK Thanks Tim.... But... I came home this afternoon, after running the new superantispyware (Which did not find anything) to an AVG Resident Shield Alert. It says Win32/Heur was found in two places. I pretty much don't want to uninstall AVG unless you say so. So should I remove these Infections. Uninstall AVG and then run combofix? OUCH!

    Lisa
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


    Yes. Exactly. ;)
     
  7. lwhitneysmith

    lwhitneysmith Private E-2

    OK so I Removed the Win32/Heur on AVG. Then I removed AVG and AVG identity protection. Then I redownloaded the combofix and ran it. It shows an error:

    ComboFix cannot run when AVG is installed. This is due to AVG's targeting of ComboFix's file/processes. It would be dangerous to continue.
    Please uninstall AVG or use another tool.

    Now what? LOL!

    Right now I got one of those pop up screens which flashed really quickly... preparing to install. And then it was gone. HELP! LOL!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. lwhitneysmith

    lwhitneysmith Private E-2

    yes! But the number on the install was a lil different..

    It was called AVG Remover(32bit) 2011
    (avg_remover_stf_x86_2011_1184.exe)

    went into the Uninstall Programs and c drive and cannot find anything left!
     
  10. lwhitneysmith

    lwhitneysmith Private E-2

    Oh there is a file on the c drive in Programs. Folder called AVG. When I open it is contains a folder called AVG 9. With a bunch of folders and files in it! AHA! How shall I remove that?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just delete it and then run Combofix regardless of any warnings.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What actual malware problems remain because your logs look good to me. We can do the below after you have run Combofix:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. lwhitneysmith

    lwhitneysmith Private E-2

    It wont let me delete it or move to the recycle bin. Here is what happens...

    Cannot delete utmp: Access is denied
    Maske sure the disk is not full or write protected and that the file is not in currently in use.
     
  14. lwhitneysmith

    lwhitneysmith Private E-2

    Let me preface the last post by saying the computer will not let me run combofix until I delete AVG entirely. AVG will not delete and is not in the Add/Remove program. I had a previous infection today....

    "AVG Resident Shield Alert. It says Win32/Heur was found in two places. I pretty much don't want to uninstall AVG unless you say so."

    After this, I killed the Win32/Heur and uninstalled AVG with your link..... and tried to run combofix.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I thought you already had uninstalled AVG but were just complaining of remnants. Is it now uninstalled or not? If not then please uninstall it. But first SHOW me the actual file paths of the threats being found. :)
     
  16. lwhitneysmith

    lwhitneysmith Private E-2


    It's complicated! :confused I did follow the Malware removel process. I have been working on this for three days. I have removed AVG but still have a AVG folder in Program Files, called , AVG, Which has a folder in it called AVG9. And it will not let me delete it.
    As far as the paths go for the Win32/Heur .... It was c: and was attached to some starwars program in which I did not copy the path, because I did not think it was important. But I do have a AVG Vault file which may have the info. It was created about the same time. (V_00000001.fil and vvfolder.idx) You can use them if you need them.

    So I am still in the same place. Cannot run combofix at all. It is claiming the AVG thingy! I cannot seem to find anything on AVG9 removal even on their website. They say I have to install 11 and then manually uninstall some files????

    What so you think I should do now? Kill the Computer and start over?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I could get rid of all remnants of avg for you however I am not seeing an urgency for combofix to be run if you say all that avg was finding was
    Obviously you had it quarantine them so now I am asking you, what malware issues remain? :)
     
  18. lwhitneysmith

    lwhitneysmith Private E-2

    Ok Kes. I get it! As I said before, My CC was stolen from either my laptop or desktop, so I just wanted to run the logs and see if there was something the software was missing. So I guess not? Do you want me to try the Root Repeal and the MG tools? Or not?

    Lisa
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If your credit card has been used you should consider this:

    • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    • From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

    Now do this so I can get a fresh look on what your status is: We can later try combofix again just to cover all angles. :)
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. lwhitneysmith

    lwhitneysmith Private E-2

    Thank you for your help!

    Here is the mglogs.zip
     
  21. lwhitneysmith

    lwhitneysmith Private E-2

    The log was attached in my very first thread..... will not let me attach a new one. Appreciate you!

    Lisa
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need you to actually do this before a new log will be created, Lisa.

     
  23. lwhitneysmith

    lwhitneysmith Private E-2

    Re: Malware Suspected...

    Kes, Is that a spider on your profile picture?

    OK here is my new mglogs.zip file.

    Thanks for your help! :)
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Malware Suspected...

    Nope LOL
    No problem!

    Ok so to clear up from avg and a few other things before we attempt to run Combofix again.

    Please disable Spybot's TeaTimer as requested or it will hinder any fixes we try to implement.

    How to disable Spybot's TeaTimer


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe (file missing)

    After clicking Fix exit HJT.



    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    C:\Documents and Settings\Lisa\Application Data\mainhst.zgh <--- What is this?

    Now run Ccleaner (Not the registry section just the cleaner itself)

    Can you run Combofix at this point? If so then attach the C:\combofix.txt
     
  25. lwhitneysmith

    lwhitneysmith Private E-2

    Was finally able to run combofix. attached are the logs.....

    Thanks for sticking it out with me. Do you need anything else?

    Lisa
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing anything else to do. How are things running for you? :)
     
  27. lwhitneysmith

    lwhitneysmith Private E-2

    Hey things sound great! My computer is running like a horse! Thanks for helping me thru this.

    I have started a new thread for my laptop! That was easier to get the log for!

    Soooo... What is that on your profile pic? LOL!

    Thanks again!

    Lisa
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\Lisa\Application Data\mainhst.zgh <-- Yes, kill it.

    It's meant to be a female with ALOT of red hair :-D

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds