Rogue AntiVirus Program

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by racarl, Apr 10, 2010.

  1. racarl

    racarl Private E-2

    Ran thru README directions, attached are files.

    Could not access internet or run any of the embedded programs already uploaded nor could get updates. Downloaded latest scan programs from read me to a thumb drive and then copied logs back to thumbdrive.

    Only way to get scan prograsm to rum was by startin infected PC in SAFE Mode.

    When restarted in normal mode, rogue virus popped back up.

    On fault I had was unable to get MGLogs to run. On ecexcute, screen flys by and nothing seems to occur.
     

    Attached Files:

  2. racarl

    racarl Private E-2

    Reran files again in SAFE Mode, this time got everything to update and run. See attached.
    Seems to be clear of infection.

    MGTools uploaded next post
     

    Attached Files:

  3. racarl

    racarl Private E-2

    MGTools attachment
     
  4. racarl

    racarl Private E-2

    After posting above, I tried to access the internet using my IE6 browser. Surprise, no access. I tried my email and was able to download and succesfully send out test email messages. I also "pinged" my ISP and then Google, with no problem. Seems IE is now "broke". I guess the 2nd thing I will do after resolving this issue is to switch to a non-MSN browser. I had tried IE7 some time back, but all it did was bring my PC to a crawl, so I deleted and went back to IE6. Also since I had this problem I ran SPyBot, and is successfully updated and found another Fraud Trojan and removed it.

    As a side question, when I ran the READMEFIRST programs, I had to run in SAFE format. When you get told to reboot to continue removal process, does it have any impact whether you restart in SAFE or let PC autotmatically start in Normal?
    Also does running in SAFE in Admin user any different than running in "normal User" mode?

    Thanks in advance for your assistance.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need to attach the C:\MGlogs.zip file from running MGtools. Do not try to attach anything other than MGlogs.zip.

    You need to put ComboFix.exe on your Desktop as specified. You must not run it from the F drive. Also only run scans once as stated in the READ & RUN ME. We specifically stated not to rerun any scans.


    Do a quick check to see if what is mentioned in the below link is your problem:

    Proxy Server - Changing Settings


    Steps are best followed in normal boot mode whereever possible. If not possible, safe mode is the next step but you should always check if normal bootmode works. For example: just because SUPERAntiSpyware or ComboFix may not work in normal mode, it does not mean that MGtools would not.


    If you want to clean a specific user account that is having problems then you need to login and run scans and attach logs from the problem user account.
     
  6. racarl

    racarl Private E-2

    Attached MGTools.zip, again.

    I will try to run again from my Desktop from my normal user account.

    Thanks,
     

    Attached Files:

  7. racarl

    racarl Private E-2

    Attached is new MGTools run from desktop.


    As far as my IE connection problem, the Virus had changed my LAN settings. Seems to be working, now.

    I know there is a place where I can check thanks, other than just saying it in this email, but I do net see the link anywhere on this page. Does not seem to obvious, to me:-D

    Thank yopu again for your support.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MGtools does not belong on the Desktop. ComboFix.exe does which is what I said previously. Download and save the current version of ComboFix.exe on directly to your Desktop folder now so that you can do the below.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 17

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    O4 - HKCU\..\Run: [vusmvxdo] C:\Documents and Settings\Roger\Local Settings\Application Data\fytxvjuec\vwweywotssd.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 13, 2010
  9. racarl

    racarl Private E-2

    Ok,

    Ran files as requested.
    Had some troubles along the way but managed to get thru them.:-D

    See attached MGLogs and Combofix log.

    Thank you again for your assistance. It is greatly appreciated.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You're logs are clean. Since you did not tell me how things are working, I will assume everything is okay and give you final steps since you need to get this PC properly protected.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    racarl likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds