Security Tool...

Discussion in 'Malware Help (A Specialist Will Reply)' started by anita1, Jan 26, 2010.

  1. anita1

    anita1 Private E-2

    Hello, this is my first time posting.
    I somehow installed Security tool onto my computer and can't get rid of it. I don't have any anti-virus software and can't open anything i try to download. I read the "Read Me First" post and did as much as i could (except whatever I can't open after downloading). I am also unable to get system restore to open. Is there anything else I can do?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. anita1

    anita1 Private E-2

    Hello Kestrel13!, thanks for replying.
    I was able to open AVPFind.bat and exeHelper (log attached).
    I had no luck with running the online spyware scan or MGtools. I was able to download them, but this "security tool" thing blocks it from running.

    Btw, while I was in the middle of typing this, my screen went blue and it said something about the problem is caused by SPCMDCOM.SYS and rebooted - if this helps anything. Thanks.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about safe mode? Have you tried running at least Combofix and MGTools in safe mode? Have you tried renaming MGTools and Combofix to something like 123.com or abc.com and then tried running them?
     
  5. anita1

    anita1 Private E-2

    I didn't know about safe mode, but I just tried and nothing.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you try renaming them? Please try and answer all of my questions :)

    Did you really restart your computer and tap F8 and therefore see a screen full of various options?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following but do not reboot the computer before doing so.


    Then try running Combofix and MGTools.

    If none of the above works I will have to have a word with Chaslang and see what he can do to help.
     
  8. anita1

    anita1 Private E-2

    Got it...
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why are you using this machine without anti virus protecting you? You will need to install some soon, but first we have some work to do.

    1. I would like for you to be in normal mode now and not safe mode to apply these fixes.

    2. Please go to Add/Remove programs and uninstall the following software:
    • Ad-Aware SE Personal <--- This version is now outdated and useless, I suggest you uninstall it.
    • J2SE Runtime Environment 5.0 Update 11
    • Java(TM) 6 Update 17

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    6. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    7. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  10. anita1

    anita1 Private E-2

    Thank you for all your help. Apparently I had an icon called BitDefender on the bottom corner of my firefox. I clicked on it and it removed 3 trojans. Immediately after, the "security tool" disappeared, so I think it's fixed. I also followed the instructions on how to be protected.

    Once I get home I will uninstall the stuff you recommended. Should I still follow the other instructions? I would like you to review the log to make sure everything is clean.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. I want to see the results from avenger and the new MGlogs.zip so please attach those as previously instructed and I will review them as soon as I get chance. :)
     
  12. anita1

    anita1 Private E-2

    Hey, everything seems to be running smoothly. I followed all your instructions and attached the logs.

    Let me know if I'm good to go!
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    2.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    3. Also delete all files in the below bold folder except ones from the current date (Windows will not let you delete the files from the current day).

    4. Don't forget to install the new Java.

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  14. anita1

    anita1 Private E-2

    Done.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You didn't empty temps: (You also didn't attach the avenger log, but I do not really need to see it now anyway as I can see the folders I wanted gone are indeed gone.)

    Delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. anita1

    anita1 Private E-2

    I am trying to follow the instructions to disable system restore, but I don't see a system restore tab after right clicking on My Computer icon and selecting properties.

    For Windows XP:

    1: Right click on the My Computer icon on your desktop and select properties.
    2: Click on the system restore tab.
    3: Check the box that says "Turn off system restore on all drives". Click OK.
    4: Click Yes if you are prompted to restart the computer.
    5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.
     
  17. anita1

    anita1 Private E-2

    nvm...found it :-o
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad you're sorted :) Surf safely
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds