possible malware keeping me from running antivirus software

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by coloradomama, Sep 4, 2011.

  1. coloradomama

    coloradomama Private E-2

    Here is my thread from an avira forum that gives details of all that I have done so far:

    http://forum.avira.com/wbb/index.php?page=Thread&postID=1110416#post1110416

    The issue started as my computer was extremely slow to boot, freezing up, chrome would not load, and Avira free version would not open. I immediately ran malwarebytes scan - nothing was found. I wanted to run a virus scan, so tried to uninstall Avira in order to re-install. It would not uninstall in CP/Add Remove programs. It took help on the avira forum to figure out how to remove it, including an uninstaller and booting in safe mode to delete folders that had denied access. There are still some registry keys that will not delete with avira regcleaner.

    After I removed all Avira files that I could, i tried to run a fresh install of Avira. The installer would not run. I then downloaded AVG 2012 and installed. All went well until trying to open the program - nothing.

    I have followed the instructions for malware removal on xp computer up until ComboFix. Nothing was found in SAS or MWB scans. Prior to this,
    I have ran numerous scans in addition to SAS and MWB (HJT, gmer, TDSSKiller, Kapersky virus scanner) - nothing is found.

    I have not ran ComboFix..yet.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Note: While we appreciate that you very likely posted at multiple forums in order to ensure a response, in the future please do not cross-post. Resources that help perform malware removal are very precious and very limited, and cross-posting only serves to tie up the time of multiple helpers who could be using that time to help someone else who also has problems.

    In the future - choose one forum and stick with that one until they've resolved your problem.
     
  3. coloradomama

    coloradomama Private E-2

    Thankyou for your reply. You are right, i did not intentionally cross-post. I was not posting to ensure a response; rather I'm at a point of going beyond the original Avira issue and now needing malware direction. It seemed this was out of the scope of what I was addressing on the Avira forum, so I moved over here. I have used this forum once before and thought this was the best place for malware issues. I have very limited knowledge of how it all works and am very leary of running ComboFix (my next step) w/o someone guiding me.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. coloradomama

    coloradomama Private E-2

    Could it be something other than malware that's causing ONLY antivirus software not to load after being installed fine? I have tried some other options today, including installing AVG in Safe Mode. It seems to install fine, it just doesn't open.
    All the other malware software i have downloaded from the Maleware Removal Guide downloads, installs and runs just fine. My computer is no longer freezing or stalling, so this seems to be the only issue I'm aware of.

    I am very leary to run ComboFix as I do not have recovery cd's if I ever needed to reinstall the OS.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well then skip Combofix and just get the rest of the tools run and attach their logs.
     
  7. coloradomama

    coloradomama Private E-2

    Before I rec'd your reply last night, I decided to try a third antivirus software. This time i downloaded the free version of Avast, installed it, and amazingly it opened! It seems to be working ok so far. I ran a scan and it was clean. I have no idea why Avast worked to open and Avira and AVG both did not ( i previously had Avira for a yr).

    I will still attach those logs late tonight. Should I also run Root Repeal and MG Tools?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try RootRepea, but definitely attach the log from running MGTools.
     
  9. coloradomama

    coloradomama Private E-2

    See attached logs for SAS, MWB and MGTools. I did not run Root Repeal, but can if needed.
     

    Attached Files:

  10. coloradomama

    coloradomama Private E-2

    most recent MWB log.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs, but let's do this just to be sure.

    Uninstall your version of TDSSKiller first. Then:

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  12. coloradomama

    coloradomama Private E-2

    3 logs attached. I ran Root Repeal before I rec'd your message, log attached.

    The MBR check said something about another drive - I'm thinking this must be my external hard drive which is 300gb and is currently attached.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are not seeing any malware in those logs. You have leftovers from Avira and Avast on your system, but nothing is showing in the way of malware. Perhaps you need to post in the software forum for your issues with running AVG?
     
  14. coloradomama

    coloradomama Private E-2

    Ok, that's great news. I'm wondering if the originally issue was some conflict with Avira that caused it to stop working, freeze up some other programs, and not let me uninstall thru the CP.

    Should I run CCleaner in the registry periodically? I already ran it so any remnants that you mentioned i will have to search for.

    Should I unistall/delete any of the downloads: TDSSKiller, MBR,Root Repeal?

    I assume I should leave SAS and MWB and run periodically?

    Lastly, do you suggest an additional firewall in addition to XP one?

    I will watch for a few days and then go to software forum to see if i needed. Right now I'm very happy Avast is working!

    THANKYOU for your help!!!!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome>

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  16. coloradomama

    coloradomama Private E-2

    Great, THANKYOU!! You all are life-savors on this forum!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem! :) Safe surfing.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes.
    Definately.

    Lots to choose from in our How to Protect yourself from Malware thread. :)
     
  19. coloradomama

    coloradomama Private E-2

    Thankyou Kestrel13!
     
  20. coloradomama

    coloradomama Private E-2

    one last question: should msconfig be left on normal startup mode?

    update - i was having several BSOD crashes, mostly while using Chrome browser. After a quick search, it is likely either problem with Chrome & Avast compatibility, or MS Visual C++ which was installed recently w/o my knowing.

    I uninstalled Visual C and also Avast. I was successfully able to install AVG! All times in the past it did not work, so whatever conflict was occurring appears to be resolved.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It should always be on normal start up, any other mode is primarily for troubleshooting/diagnostic purposes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds