Malware Removal Step 3

Discussion in 'Malware Help (A Specialist Will Reply)' started by warmum, Jan 5, 2009.

  1. warmum

    warmum Private E-2

    I am doing a follow-up to the Malware Removal. I am currently at Step 3 and am attaching all my logs to see if I can get help making sure I'm getting rid of everything.
    I am running a laptop with Windows XP Professional. It is a work computer and has VPN connection for the company and regular wireless connection for everyday use. I went through every single step on the malware removal guide after getting these symptoms on my computer:

    Lots of pop-ups
    Antivirus and firewalls disabled
    Even when I try to turn them on, they don't
    They say they're running when I go to their properties but Windows Security says they are turned off
    LimeWire has been present on the computer previously
     

    Attached Files:

  2. warmum

    warmum Private E-2

    4th Log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You had some real problems, but the scans took care of most of it.

    Let's do this:

    Please use add/remove programs to uninstall:

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):


    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  4. warmum

    warmum Private E-2

    Okay, I did all the steps above and I am attaching the new log from MGtools and the log from Avenger.

    Everything on my computer seems to be running fine, no pop-ups or anything have come back. The only issue I have is that my Windows Security still does not recognize my antivirus program. It is Symantec Professional put on by the company that owns the computer and some of the programs on it. I've never noticed a problem before. The antivirus program is always running and can never be disabled, and the security warnings only started occurring when I got the malware problems. I don't know if it's something I need to worry about, but I just told my Windows Security that I would monitor the antivirus program myself so it would quit showing warning errors.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Windows security does not recognize various AV programs. You are clean, but I would like you to use windows explorer to find and ( unless you know what it is) delete:
    C:\WINDOWS\KU2RZNUI7E3BRZ7W

    If you are not having any other malware issues, then:

     
  6. warmum

    warmum Private E-2

    I'm having one more problem. I'm now getting an error message when the computer starts:

    Error loading C:DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.30.2.sxt
    The specified module could not be found.


    I used to have Kodak Easy Share and took it off my computer a long time ago, but now this message is showing up. It says it is a RUNDLL at the top. Any help?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do a search for easy share and delete anything that is found. Then run CCleaner, both the cleaner and the issues/registry ( making sure you do the backup when prompted).
     
  8. warmum

    warmum Private E-2

    Thank you for all your help! My system is clean and running great!!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds