Need Help with Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by StiinaQT, Aug 15, 2010.

  1. StiinaQT

    StiinaQT Private First Class

    You guys are the best and have been so great helping me in the past. I now have a critter that just won't go away. I started getting alerts from AVG (Free 9.0), but it didn't do anything. I tried going to the file and deleting it, but as you know, the root is lurking somewhere else and of course, it just came back.

    Most concerning was finding my wireless account locked due to too many attempts with incorrect passwords. I fortunately have learned to allow the computer to save passwords on low risk accounts and use different, difficult to guess passwords on high risk accounts (meaning banking and such). So far those have not shown any similar issues.

    Anyway, AVG shows this file when the warning comes up:

    "Found Tracking cookie.Liveperson";"c:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\n1l5urcl.default\cookies.sqlite";"";"8/15/2010, 8:00:03 PM";"file";"C:\Program Files\Mozilla Firefox\firefox.exe"

    I followed the malware removal guide and only made one error. I forgot to close out my web browser before launching MGTools, so I don't know if it ran correctly. I'm attaching all my logs.

    After going though all of this, I thought I was in good shape and did some surfing on Facebook and another social web site and when I closed the browser, there it was again. After going through the exercise, I had learned a bit more about the workings of AVG and I did a scan beginning at a higher level of that and came up with 5 things that were deleted/repaired. I am also including that log.

    I can't seem to find a name for this anywhere. Can you clue me in? I even tried the additional scans. I ran the CWShredder for CoolWebSearch and it found nothing--this was after AVG gave me the alert, but before I did the file specific scan. I also tried Trend Micro Housecall, but it didn't find anything either.

    I have more than the max of 4 logs, so the rest will be in a reply.

    I await your analysis. Thanks again!


     

    Attached Files:

  2. StiinaQT

    StiinaQT Private First Class

    Now that my post is active, I'm attaching the rest of the logs. FYI, I didn't get any more errors after having AVG scan that specific file location. I tried to get the AVG log, but I can't remember where it saved and I now need to leave for work. Thanks!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the C:\MGLogs.zip --> from running the C:\MGTools.exe.
     
  4. StiinaQT

    StiinaQT Private First Class

    Here it is. I ran it, but couldn't find the log file. I reran it tonight, but of course I had turned the user control back on and all my anti spyware was on...I hope it isn't a total mess. If it is, I will go back and get my computer where it needs to be and rerun it. I sure do appreciate your help.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What malware issues are you having? Your logs are clean. You can use windows explorer to find and delete this leftover from when you had Avira:
    C:\ProgramData\Alwil Software
     
  6. StiinaQT

    StiinaQT Private First Class

    Obvious to you, but I had no idea that this was a residual from using Avast! Thank you!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds