no success with malware removal - SECOND PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by adventuresinspace, Oct 17, 2011.

  1. adventuresinspace

    adventuresinspace Private E-2

    here are the details from the second laptop (very similar to first):

    i have run the full malware cleaning program outlined here, but can still not connect. i encountered two problems while trying the fixes: while i uninstalled all of the anti-virus programs on the computer, windows security centre says i am still running avg anti-virus. this is after i ran the avg remover from your site. so this prevents combofix from properly completing. also a problem for combofix is that i can't connect to the internet, and it says that it needs microsoft windows recovery console.

    also interesting is that the combofix folder on the c: drive is called Qoobox instead of combofix. not sure if that means anything?

    also, i ran malware before i went through this whole process, as i already had it on my computer, but then i deleted it by accident after i started this process. i didn't run it again, because it didn't come up with anything the last time.

    the other problem i encountered on this laptop is that it could not properly clear the java cache. the following error message appeared "java.lang.NullPointerException"

    logs attached
     

    Attached Files:

  2. adventuresinspace

    adventuresinspace Private E-2

    Re: no success with malware removal

    2nd computer logs
     

    Attached Files:

  3. adventuresinspace

    adventuresinspace Private E-2

    Re: no success with malware removal

    not sure where the message about the second computer went, it disappeared after i typed it. but basically, it had the same problem at #1, with the additional problem of not being able to clear the java cache due to the following error "java.lang.NullPointerException"

    1st half of 2nd computer logs

    the avgremover log was too large to attach, it's below:

    2011-10-17 23:22:36,328 INFO AvgRemover 2012.0.5
    -------------------------------------------------------
    [Edit: thisisu >> Inline AvgRemover log removed]
     

    Attached Files:

    Last edited by a moderator: Oct 18, 2011
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to run Malware Bytes, SUPERantispyware, MGTools. Also the below.

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Please then attach the logs from each. (As explained in the R&R which I will link to for reference)

    READ & RUN ME FIRST. Malware Removal Guide
     
  5. adventuresinspace

    adventuresinspace Private E-2

    ok i ran the whole process again, and here are the logs attached.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is just Combofix's backup folder.

    Running from: E:\ComboFix.exe <--- Do not run Combofix from here, delete it from this location if it is still there. It should be on the desktop.

    I would like to see a log from it regardless, thanks.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    File::
    C:\Documents and Settings\scott\Desktop\Shortcut to ComboFix.exe.lnk
    C:\Documents and Settings\scott\Desktop\Shortcut (2) to ComboFix.exe.lnk
    Folder::
    C:\Documents and Settings\scott\Local Settings\Application Data\AVG Security Toolbar
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
    Please open up SUPERantispyware, open up the repairs tab, and see if the "Repair broken network connection (Win Sock LSP Chain) " fix works to mend your connection.

    If that does not work then please download WinSock XP Fix and see if that does the trick.

    Let me know.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds