Need help with Spyware or Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by escott68, Jan 5, 2008.

  1. escott68

    escott68 Private E-2

    First off hello and thanks for any assitance I may receive

    This is my issue: I run Windows XP. I recently was infected with a virus or some type of spyware. I continuously get a box that pops up that is titled "System Error" and it sometimes slows/freezes my system. This started yesterday. Inside that box it says:

    Your computer was infected by unknown trojan
    It's dangerous for your system(critical files can be lost)
    Click OK to download the antispyware program to clean your system(Recommended)

    I ran two spyware programs and an adware program
    I have a virus program set up as well

    I think I picked this up on a site I logged on

    Can someone help me get rid of this box if possible without totally restoring the system?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

  3. escott68

    escott68 Private E-2

    I wasn't able to run Spybot and AVG turned up no issues at all but here are the other two results.

    Edit by bjgarrick: Inline log attached!
     

    Attached Files:

    Last edited by a moderator: Jan 6, 2008
  4. escott68

    escott68 Private E-2

    Here's the other.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post inline logs like you did with ComboFix. All logs must be attachments. Please ATTACH your ComboFix log now. Inline logs are more difficult to read because they lose formatting and they make threads take longer to loaded up and slow down scrolling. All of this requires more time on our part and we don't have the time to spare. We are way toooooo busy.

    You also need to go back to the READ ME and follow any instructions that you may have skipped because I already see you ignore the early step about not having more than one antivirus installed. I see AVG7 and McAfee. Uninstall all but one antivirus now. Then do any other steps you may have skipped.

    Then do the below
    • run the C:\MGtools\GetLogs.bat file by double clicking on it.
    • run the C:\MGtools\VunFind.bat file by double clicking on it.
    • Then attach the new C:\MGlogs.zip file
    • Also attach your ComboFix log
     
  6. escott68

    escott68 Private E-2

    I hope I did it right this time
     

    Attached Files:

  7. escott68

    escott68 Private E-2

    For some odd reason the Combofix.txt file and the Mglogs.zip won't up load. I'll keep trying
     
  8. escott68

    escott68 Private E-2

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't need a list of your attachments. I need you to attach the new MGlogs.zip file.

    Did you uninstall the duplicate antivirus programs yet? Did you complete all other steps from the READ ME that you may have skipped?? You need to make sure you have done this as requested.

    You will see below that BJGarrick changed your inline ComboFix log into an attachment for you and thus you don't need to attach it. But you do need to get a NEW MGlogs.zip file following the instructions in message # 5. If you don't follow those instructions you will be trying to attach the same old log which you are not allowed to do.
     
  10. escott68

    escott68 Private E-2

    I thought that list would possibly show the logs themselves.
    I get getting a message that the attachment attempts were errors

    Let me try now
     

    Attached Files:

  11. escott68

    escott68 Private E-2

    I could not uninstall the Mcaffe program but I did go into the control panel and stop it from running
    I completed all of the other steps
    The Spybot program says I have 2013 errors but I have to purchase it in order to remove them
     
  12. escott68

    escott68 Private E-2

    There is a gaming program called Wild Tangent that I saw on the Malware list
    I can't uninstall it from Control Panel because it's not listed there.
    Is there another way to get rid of it?

    Sorry for all the questions
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That will not work and as you can see from your HijackThis log it is still running. Why couldn't you uninstall McAfee? What problem did you have? You can try using the below to uninstall it:

    McAfee Consumer Product Removal Tool

    I need a to see a new MGlogs.zip file after you have uninstalled McAfee.


    I'm not sure what you are referring to. Spybot is a free program. What exacty were you running and what errors are you talking about?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just saw SpywareBot 1.9.0 in your logs! I assume this is what you were talking about. We did not ask you to install this program. We asked you to run Spybot Search & Destrory. You did not click our link and install and run what we requested. You need to follow our instructions.

    You need to uninstall SpywareBot as this is not a program you should have on your PC.
     
  15. escott68

    escott68 Private E-2

    I started it all from scratch
    I used all of the links your provided
    Here is the MGlogs file
     

    Attached Files:

  16. escott68

    escott68 Private E-2

    Here's the new combo file
     

    Attached Files:

  17. escott68

    escott68 Private E-2

    AVG finished with 5 possible errors but produced no report
    I used the action command to delete them
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Spyware Doctor a paid version or free trial version. If free, uninstall it now.

    You have a few left over services from Symantec. Do you have anything from Symantec still installed? Did you have Symantec or Norton Antivirus installed at some point.


    Let's remove a service left over from Wild Tangent.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to GameConsoleService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Rates - {834B0DD4-3A68-4F58-B265-D9FDB3D8F88B} - C:\WINDOWS\toprates.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  19. escott68

    escott68 Private E-2

    I think AdwareAlert & Spywarebot were unabled to be removed according to the logs because I worked on them before i ran thdelete program

    It seems to be working fine now, I will keep you posted
     

    Attached Files:

  20. escott68

    escott68 Private E-2

    It's working great!
    I thank you. Not only did you solve
    my problem but it also gave me some
    good insight into avoiding spyware, adware
    and viruses

    Thanks a million
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure that you are really clean yet. All those strangely named files in your Temp folder are back along with many many more. See this folder:

    C:\Documents and Settings\EmmanuelX\Local Settings\Temp\

    See if you can put one the files that is 77 bytes in size and one that is 1930 bytes in size into a ZIP file and then attach the ZIP file here. Examples of file of that size are:

    IVBUCJLUIIUUI
    IVFCOMVIHGCBH


    If you know that these files are for something that you run on your PC then just tell me.
     
  22. escott68

    escott68 Private E-2

    Here it is
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this procedure: Trojan.Win32.Agent.akk (aka IEDefender) Removal Procedure

    Then delete any of those randomly name files in your Temp folder.

    Then reboot.

    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  24. escott68

    escott68 Private E-2

    I didn't know what some of those items were in C:\Documents and Settings\EmmanuelX\Local Settings\Temp\ so i didn't delete them

    Here is the MGTools log
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need anything in a Temp folder. That is why it is called Temp. ;) No valid program would save anything in a temp folder that is necessary for normal operation.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds