Malware Wont Let me Open MalwareRemoval software

Discussion in 'Malware Help (A Specialist Will Reply)' started by rammairone, Oct 18, 2010.

  1. rammairone

    rammairone Private E-2

    Hi,

    I read all of the similar threads and did the READ ME. Nothing has solved my problem. My problems are:

    1) All search engines are redirecting to advertisement internet pages
    2) My previously installed Malwarebytes program no longer works (when I double click on it, it does not open).

    From the READ ME actions (specifically step 7 on Cleaning):
    a) I was not able to open the SuperAntiSpyware exe file so I had to use the portable file. It removed 4 infections. However, when I rebooted, my log of that activity was not there (no log at all, likely due to the portable) so I ran the scan again and have attached that below
    b) MalwareBytes will not uninstall, and so I deleted the contents of the Program Files/Malwarebytes folder and then installed the file you had me download (yes, i renamed it to mb.exe). It installed but still would not let me open the program. I did not attach a log below as I could not run this.
    c) Combofix - when I click on the exe file, I do not get a response. No log attached.
    d) RootRepeal - this ran fine. log attached
    e) MBTools - this ran fine. log attached

    Despite the running of the above, the problem still exists. Thanks for your help in advance. I will await your response. If I've not followed the instructions properly, please let me know. However, I think I've followed your instructions to the "tee".

    -TG
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Currently reviewing your logs and will get back to you with a set of instructions as soon as possible.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What software were you using from symantec?

    You have Spybot Search and Destroy's "Teatimer" feature active which I will need for you to disable otherwise it will hinder the fix.

    How to disable Spybot's TeaTimer

    Uninstall this outdated java
    • Java(TM) 6 Update 16
    • Java(TM) 6 Update 7

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Use windows explorer to find and delete:
    • C:\Documents and Settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}

    I suggest you run the AVG Removal Tool

    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now rename combofix.exe to 123.com and try to run it in normal mode. If you have problems, switch to safe mode.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\temp
    • C:\Documents and Settings\Dan\Local Settings\TEMP

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Don't forget to answer my question about symantec.
     
  4. rammairone

    rammairone Private E-2

    Hi,

    Thanks again for all your help. Here we go:

    1) I used Symantec's Norton Anti-virus program. It was loaded on my machine when I purchased it. I believe I deleted it many months (years?) ago
    2) I had previously deleted Spybot since I last attached my log so I did not have to disable TeaTimer as the program is no longer on my machine
    3) I uninstalled the Java 6 items you noted
    4) I ran the HJT program and removed the 3 items you suggested
    5) I deleted the folder you suggested
    6) I ran the AVG Remover Tool
    7) I rebooted and then installed Java Runtime 6
    8) I ran Combofix as instructed. During the scan, it said it found a rootkit and had to reboot before continuing. My log is attached
    9) I ran TDSSKiller. No issues found. Log attached
    10) I cleaned up my desktop. Nothing on it now except Recycle Bin and Combofix
    11) I ran the MGtools bat file...logs are attached

    This all has seemingly fixed the issue. I can search via Google, yahoo, Bing without the redirect now. Let me know if anything further needs to be performed.

    Thanks again!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are currently not using any antivirus and that is a wide open door for nasties to slip by often un-noticed.

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    Rename 123.exe back to combofix.exe

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    • C:\Documents and Settings\Dan\Local Settings\TEMP

    Install some antivirus! :)

    Run a full system scan with your anti virus and let me know how things are running after a couple of days.
     
  6. rammairone

    rammairone Private E-2

    There is still a folder named clclean.0001.dir.0000. What is this? It holds active files that are from today and cannot be deleted. Just curious.

    I did the rest. Thank you!
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing to be concerned about. Get back to me again tomorrow to let me know how things are running and then I can give you final steps.
     
  8. rammairone

    rammairone Private E-2

    A couple of other questions:

    1) I have a folder in C: named Qoobox. Can I delete?
    2) I have a folder in C: named RECYCLER. Can I delete?
    3) I have a folder in C: named found.000. Can I delete?
    4) I have 2 folders in C: named 123 and Combofix. These are from the installs I did. Do I do not need either of these now?

    Thanks and I will get back to you tomorrow after running the a Windows Update and Antivirus install tonight
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, don't delete anything!

    Most of what you mentioned are to do with combofix and will be gone when you follow final instructions anyway.
     
  10. rammairone

    rammairone Private E-2

    Update:

    1) Things are working much better, however things seem to be "dragging" when I click on applications. This seems to have happened after I installed SP3 but may or may not be related to it.

    2) I installed SP3 and all Windows Update security updates

    3) I installed Avira Antivirus and the full system scan found 6 viruses, two of which were Rootkits. All were quarantined.

    4) My Malwarebytes program now runs fine. A system scan found no issues.

    5) There is still a combofix.exe file on my desktop per your instructions

    6) I ran the Norton Removal Tool (twice per instructions)

    All in all, things are good but I'm disappointed in the # of seconds that go by when from when I double click to open an application and when it brings the app up. I never had this issue before. Any recommendations are appreciated!

    Thanks!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:

    Any non malware related issues can be worked out in the software forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds