PC Antispyware 2010 removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by d4hess2614, Sep 1, 2009.

  1. d4hess2614

    d4hess2614 Private E-2

    Hello,
    Ran CCcleaner & MGTools.exe and here are the files. Antispyware program will not install or Symantec EndPoint protection at this point.
    Thanks,
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC with no protection which makes you easy game for infections like this? As you will see from the below, you are very badly infected.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [PC Antispyware 2010] "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide
    O8 - Extra context menu item: &Search - ?p=ZCxdm801YYUS
    O20 - AppInit_DLLs: cru629.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Admin\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. d4hess2614

    d4hess2614 Private E-2

    What can I say it's my wife's PC LOL, and my 17 year old son went to pirate bay. Finally got Symantec EndPoint protection loaded, dont ask me how and it fixed it.
    Thank you for the reply.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it removed everything based on what I saw. None of the major antivirus programs remove this stuff let alone detect it. At least not from what we have experienced here in the forum with hundreds of people each week posting logs that illustrate that Symantec, McAfee....etc have completely missed all the problems. Did you run my fix before or after running Symantec? Did you run the fix at all?
     
  5. d4hess2614

    d4hess2614 Private E-2

    I did not run it at all, let me do it and send you the logs you asked for, thanks.
     
  6. d4hess2614

    d4hess2614 Private E-2

    Ok here are the files after the full cleaning.
    Seems to be much better so far! :)
    Doug
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it's a good thing I asked you because obviously Symantec missed quite alot including actually removing the malware. You can see how much was still removed from the Avenger log. And we still have some more to do since the infection had spread more after I created my last fix. Symantec also missed all of these. Hope you did not waste too much money.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    DO NOT attach a log from it right now. We just needed to run th current version to get some files in place that we need to finish your fixes.


    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    PC Antispyware 2010 <-- if you don't see this or it will not uninstall. Don't worry. Just continue.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 19, 2009
  8. d4hess2614

    d4hess2614 Private E-2

    Here are the logs, the Java updates would not uninstall gave an error.
    Combo fix gave exception error and so did Hyjackthis when I ran getlogs from MGTools - see attached jpg. Avenger.txt is still dated 9/14 so new one was not created?
    Thanks for the help,
    Doug
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even though ComboFix did not create a log, it appears that it removed what we wanted to remove.

    Now see if you can run SUPERAntiSpyware and Malwarebytes as instructed in the READ & RUN ME and attach the logs.


    How are things working now?
     
  10. d4hess2614

    d4hess2614 Private E-2

    Both programs ran perfectly, I ran the full scans and did not change any options. The MGlog is attached.

    Thanks,
    Doug
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I asked for logs from SUPERAntiSpyware and Malwarebytes.

    I also asked "how are things working"?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds