Malware - really could use help guys!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Northern_Pride, Nov 12, 2007.

  1. Northern_Pride

    Northern_Pride Private E-2

    Alright, so I'm using Avast! Antivirus and I've been using Torrent software for downloading. Recently I went to clean unnecessary files with CCleaner and when I did, Avast! went AWOL with alerts for what seemed like non-stop; viruses and trojans being detected.

    I had some system crashes as well prior to this so rational deduction says this was probably the cause.

    I've gone though the removal guide but still suspect there could be something left behind - better to be on the safe-side, eh.

    Please take a look at the results and reply if there is anything malicious left - on the GetRunKeys.txt file, towards the bottom, something about a trojan is worrying me! :(

    Regards.
     

    Attached Files:

  2. Northern_Pride

    Northern_Pride Private E-2

    And here's the HJT txt file.

    Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to put GetRunKey and ShowNew into a properly named folder as requested in the READ ME. We suggested MGtools and you used C:\SPYWARE TOOLS [MAJOR GEEKS] which is not an acceptable folder name. As a result, the tools did not run properly. Note that what you saw at the end of GetRunKey is not a problem. However DO NOT do this now. Since you are running Vista, I'm going to give you a new version of the tools to run further down.

    You also did not attach the other log from AVG Antispyware as requested.

    You also did not pay attention to step 3 of the READ ME. You must uninstall all but one antivirus program now. I saw Avast and Symantec.

    Uninstall the below old versions of Sun Java:
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6


    Now run thisUsing MGtools and attach the requested C:\MGlogs.zip file. Make sure that you download and run MGtools.exe from the root folder of drive C. That is you should have a file named C:\MGtools.exe
     
  4. Northern_Pride

    Northern_Pride Private E-2

    My apologies but the thing is I tried to uninstall the Symantec Antivirus but I can't - my laptop came with a trial version of it due to expire soon and when I go to remove the antivirus component as it is also my software firewall the only option available to me is "remove all" which i do not want to do. to overcome this I disabled the antivirus and spyware feature in its options menu.

    I have now uninstalled the unneccessary older versions of Sun Java - thanks for that.

    About, AVG - I do not use it. Forgive me if I've been misinformed but Avast! apparently has a higher detection rate which would seem to me to be correct because I used to use AVG then switched to Avast! and it discovered items which AVG did not and it would also be contrary to the guide if I install it: I would rather keep Avast.

    Attatched is what is requested, thanks.

    Oh and between the time of my last post and now, I am having a problem upon start up. I've run Spybot and not found anything. I thought about doing a virus scan but the program wont load up and neither will Norton and I think it is due to the following error. I get "MSCVR71.dll is either not designed to run on Windows or it has an erorr.....". It is such an annoyance, any ideas?

    Regards.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not an acceptable solution. Nor is it recommended. You must uninstall either Symantec or Avast. There are many free firewalls you can use to replace Symantec. (see this: How to Protect yourself from malware! ) If you do not plan on buying Symantec then you should just get rid of it now.

    I did not say AVG Antivirus. I said AVG Antispyware and while running the READ & RUN ME you were supposed to run either CounterSpy or AVG Antispyware and attach the log.

    This is not a malware issue. You would be better off addressing this problem in the Software Forum; however this is more than likely due to your downloading and using this: C:\Users\Hamilton\Desktop\msvcr71.zip

    You MUST NOT put anything else in the MGtools folder. I see Autoruns and unmsjvm in the MGtools folder. The MGtools folder should only be used for the MGtools.exe application and nothing else. You can also delete the C:\MGtools\ShowNew folder containing the old version of ShowNew. It does not below here either and it is not needed. However, all of that being said, your logs do not show any signs of malware.

    You should have HijackThis fix the below line:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    And be very careful using Messenger Plus! Live which can install malware if you don't properly pay attention while installing and reading the license agreement.

    You should also delete the below folder left over from AskToolBar:
    C:\Program Files\AskTBar
     
  6. Northern_Pride

    Northern_Pride Private E-2

    Ok, yes I can see your point - what software firewall would you recommend (I'm using a laptop if this would be a factor when considering) ?

    I will post the AVG log in a mo.

    About that, it begun to happen after I installed Blaze Media Pro to convert some .ogg files to mp3 and I downloaded the dll file in an attempt to move the original and put the DL'ed one in its place to see if that resolved the issue - it didn't. That .zip file was just lying there tbh.

    OK, I'll sort that now.

    Sorted that. Appreciated. And I made the necessary preferences when installing msg plus live, and I have now deleted the AskTBar folder. Cheers.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try Comodo.


     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds