New problems with Antivirus2008

Discussion in 'Malware Help (A Specialist Will Reply)' started by alankew, Jun 13, 2008.

  1. alankew

    alankew Private E-2

    I am still having problems with this.My pc recently came up with a message from antivirus2008 which told me I had got all sorts of problems.I tried trend micro housecall but this didnt detect any problems so did a search on antvrs.exe and this is a virus.malware.How can i remove this
     
  2. abri

    abri MajorGeek

  3. alankew

    alankew Private E-2

    Re: Adware_memwatcher

    Heres the text file from Smitfraud fix
     

    Attached Files:

  4. alankew

    alankew Private E-2

    Re: Adware_memwatcher

    Hers the file after cleaning
     

    Attached Files:

  5. abri

    abri MajorGeek

    Re: Adware_memwatcher

    Hi alankew,
    Did you run MalwareBytes? If so, please post the log if it found anything.
    Thanks.
    abri
     
  6. alankew

    alankew Private E-2

    Re: Adware_memwatcher

    Malware bytes log file before and after cleaning attached
     

    Attached Files:

  7. abri

    abri MajorGeek

    Re: Adware_memwatcher

    Hi alankew,

    Please run the following two scans:

    Using Combofix

    USING MG TOOLS

    Then attach the Combofix log and the MGlogs.zip (directly under C)

    abri
     
  8. alankew

    alankew Private E-2

    Re: Adware_memwatcher

    Abri here the CF logfile
     

    Attached Files:

  9. alankew

    alankew Private E-2

    Re: Adware_memwatcher

    And heres the MG logfile
     

    Attached Files:

  10. abri

    abri MajorGeek

    Re: Adware_memwatcher

    Hi alankew,

    It's hard to get rid of, because of the way it keeps itself going. Here's what McAfee has to say about it:

    http://vil.nai.com/vil/content/v_100635.htm


    Question: Does your antivirus find this if you boot up disconnected from the internet and run the antivirus scan?


    And now please do the following:

    1) To begin with, please disable Spybot's TeaTimer. This can be done two ways.
    First:
    • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
    • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
    • If you have Version 1.4, Click on Exit Spybot S&D Resident
    or Second, For Either Version :
    • Open Spybot S&D
    • Click Mode, choose Advanced Mode
    • Go To the bottom of the Vertical Panel on the Left, Click Tools
    • then, also in left panel, click Resident shows a red/white shield.
    • If your firewall raises a question, say OK
    • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
    • OK any prompts.
    • Use File, Exit to terminate Spybot



    2) Go to add/remove programs and uninstall the below:

    - Java(TM) 6 Update 5

    3) Reboot after uninstalling the above.

    4) Install the current version of Sun Java from: Sun Java Runtime Environment


    5) Next please download Registry Search (see the link titled RegSearch Download Link )

    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter HotEkc.exe in the top area of the form and then click "Ok".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.

    6) Then please run Silent Runners and Running GMER to detect rootkits as well. Try to run these scans right after Adware_Memwatcher has been found and if your browser is active, leave it running.Attach both of these logs together with the RegSearch results.

    Thanks.
    abri
     
  11. abri

    abri MajorGeek

    Hi Alankew,

    I've moved your most recent posts to this new thread. When you reposted in your old thread and wrote that you are still having problems with this, I understood this to mean Adware_Memwatcher. Chaslang suggests you mean you are having a new set of problems. If that is the case, you need to start over with the READ & RUN ME FIRST and do it over. You didn't uninstall Combofix when I asked you to last time, so I need for you to uninstall it before you do the READ ME. To uninstall it do the following:

    • If you installed Combofix to the desktop and renamed it cf.exe, it can be removed by going to Start/Run and copy-pasting in "%userprofile%\Desktop\cf" /u
    • Check for the following and if found, remove them as well by deleting them: ComboFix.exe (if it wasn't renamed), C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.


    After you finish the instructions in the READ & RUN ME, please attach the logs. You don't have to rerun those scans you already did except for Combofix, but you need to go through all the initial instructions again as there's been a lot of time to accumulate new temporary files that need to be gotten rid of and to see if Spybot picks up anything.

    Thanks.
    abri
     
  12. alankew

    alankew Private E-2

    Hi Abri,sorry should have made myself clearer.I am still having issues with pages being slow to load and lagging/hanging and presumed it was because of Malaware.I am not sure if its Antivirus 2008 that is causing the problem as I thought this had now been removed.I will work through the read and run list and post the appropriate files
     
  13. alankew

    alankew Private E-2

    Abri Spybots s and d still found traces of Antivirus 2008,this has now been removed but i am not sure how to completely remove it from quarantine,cn you advise.Thanks
     
  14. alankew

    alankew Private E-2

    Also I have a previous version of MGtools which is on my destop,how do i remove/uninstall this as it doesnt come up in the add remove programs
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just do a search for MGTools ...it should be located here: C:\MGTools....then look for C:\MGLogs.zip and remove it.....

    You should then do all of the Read and Run First instructions.
     
  16. alankew

    alankew Private E-2

    I have done steps up to running combofix but when i copy and paste in "%userprofile%\desktop\combo-fix.exe" /killall and press ok it comes up with c:\documents and settings\owner\desktop\combo-fix.exe is not a valid win32 application and will not allow me to run this program.Have tried to run from my documents and it tries to run but says that it is an out of date program but doesnt give me the option to update and then doesnt allow me to do anything with it
     
    Last edited: Jul 1, 2008
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You just need to follow Abri's instructions for manually removing ComboFix in post #11. And then starting fresh with the Read and Run First instructions.
     
  18. alankew

    alankew Private E-2

    Apologies for sounding dumb but in the part about show hidden files and folders should Hide extensions for known file types option.
    and the Hide protected operating system files (recommended) option have a tick in them or not.I have done this so many times and am a little confused as to their previous default state and when I do untick Hide protected operating system a warning comes up saying that doing so may cause the system to be inoperable
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per the instructions
    Thus you need to uncheck the last two.

    No the warning does not say that unchecking this will cause this problem. It says
    It is the files themselves that the message is referring to. Not the option you are changing.
     
  20. alankew

    alankew Private E-2

    So far SAS found nothing,Sand D found nothing,Malware antibytes found several trojans(attached logfile)
     

    Attached Files:

  21. alankew

    alankew Private E-2

    Heres the combofix log
     

    Attached Files:

  22. alankew

    alankew Private E-2

    Heres the MG file.I am not sure what the virus/trojan/malware is called as I think Antivirus2008 is now removed but pc has been very slow when browsing the net
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MalwareBytes did find a number of problems ....but the main problem was that you didn't have it fix anything!

    You need to re-run MWB's and have it fix/quarantine everything it finds!

    Then Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from MWB's.
     
  24. alankew

    alankew Private E-2

    Tim sorry about that!Here is the new MWB file.Do i need to delete the files in the previously run MWB that are now in quarantine
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. Whatever it was is gone now.

    Yes you can delete the quarantined files...though I suggest keeping MWB's.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2. Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox ( or whatever you renamed it to) and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds