Spyware & Malware, Privacy Protector & Error Cleaner

Discussion in 'Malware Help (A Specialist Will Reply)' started by mikem546, Jul 11, 2008.

  1. mikem546

    mikem546 Private E-2

    Well, I am currently in safe mode - I got nailed by the privacy protector virus and I am now trying to figure out what to do. I have had things disappear off my desktop. My start control panel, run area and allot more is not visible or working. I cannot do a search to delete bad files either. I have run AVG anti virus scan twice, I have run stopzilla twice and I have run Uniblue Spyeraser, all to no avail. I have 3 icons on my desktop, Spyware & Malware, Error Cleaner and Privacy Protector and they won't go away. I need some big time help
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please try doing the below in safe mode ...running ComboFix first.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. mikem546

    mikem546 Private E-2

    TimW, thanks for the reply, I am at work right now. At lunch I was able to print some of the report from Major Geeks so I now have something to work with when I go home. I read the start up information and allot more. I will start through the material in detail when I get home. Thanks again, everything is a mess on my home machine right now. I will get back to you soon

    Mike
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know what you can do.
     
  5. mikem546

    mikem546 Private E-2

    I am in Administrator Safe Mode, I downloaded CCleaner, when I try to install I get a Windows Installer Message that "the system administrator has set policies to prevent installation
     
  6. mikem546

    mikem546 Private E-2

    Guys,

    Last night I brought up my pc in normal mode and start through the READ & RUN ME FIRST. It took a couple of hours fighting off all the virus messages but I made it through steps 1, 2 and 3. Amazing,,,,, I think my system is back to normal. However, I still need to do step 4 in the cleaning procedures and I also need to do the CCleaner to Administrator in Safe Mode. Even after finished steps 1, 2 and 3 of the read and run me first I still get the following message when trying to run CCleaner for Administrator in the safe mode "The systems administrator has set policies to prevent this installation". I thought I should hold off on doing step 4 of the cleaning procedures until I hear back from you on the CCleaner install in safe mode. I will also send you the comboFix output files when all has been accomplished, you guys are great, great sight :)

    Mike
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just skip the steps that you can't do ...I really need the logs from the other scans:
    ComboFix
    SAS
    MWB
    MGLogs.zip
     
  8. mikem546

    mikem546 Private E-2

    Hi TimW

    I have attached SASlog.txt, ComboFix.txt and MGlogs.zip. I am have trouble locating the Malwarebytes Anti-Malware log. Do you know where it might be located. I used a malware product called XoftSpySE by Pareto Logic, but I can not find the log file. I will send you a scree shot of the log files for the 11th last night when I ran the app

    Mike
     

    Attached Files:

  9. mikem546

    mikem546 Private E-2

    I am attaching a log file search, let me know if you see the correct one and I will fwd, thanks

    Mike
     
  10. mikem546

    mikem546 Private E-2

    Systems did not take my last attachment (.ppt file)
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just start MWB ...you will see a tab for the logs. I'll get back to you in a few after I look at your logs.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) SE Runtime Environment 6 Update 1

    Download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  13. mikem546

    mikem546 Private E-2

    I removed all the Java apps and reloaded Java 6. I am attaching the new MGLogs.zip and Avenger.txt logs. A couple of side notes, 1) a shortcut appeared on my desktop called "Get OpenOffice.org" and 2) when I restart I get this funny sound that sounds like a space ship taking off. I have heard this in the past but it doesn't happen all the time. Do this things have anything to do with our activity ??

    Mike
     

    Attached Files:

  14. mikem546

    mikem546 Private E-2

    Disregard the reference to "Get OpenOffice.org" that came along with the new Java 6 load. I deleted it. Also I did find a log file in the XoftSypSE application but it produced and .xml file. I zipped the file and attached for your review, thanks

    Mike
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm sorry, I though you had followed the instructions and downloaded Spybot Search and Destroy....not the rogue program you have installed.

    Let's now do this:

    Please go to add/remove programs and uninstall:
    Search And Destroy

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and run:
    ATF Cleaner by Atribune.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  16. mikem546

    mikem546 Private E-2

    Ok, all step completed. I tried downloading from the free flag area originally and it did not work so I downloaded from the area on the lower right hand portion of the page. So, I probably bought more tools than I needed too. :eek: Ok, I have attached the 2 new files for review. Hopefully back on track, thanks

    Mike
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    What do you mean - "I tried downloading from the free flag area originally and it did not work so I downloaded from the area on the lower right hand portion of the page."
    The link in the instructions takes you right to MG's Spybot page.

    Are you having any other malware issues?
     
  18. mikem546

    mikem546 Private E-2

    Tim,

    Thank you very much for all the help, greatly appreciated, you guys do a great job. You have a plethera of information on your site. It's a resource that I will keep handy and I sure take advantage of from time-to-time.

    The reference to the flag and the free area just means that I went to some of your advertisers and downloaded their products. Why? because the first time I attempted to download from your free area it timed out, so instead of trying it again I went down a little further and saw the advertisements for similar products, dummy me, anyway thanks again for all your help, I'm back to normal:)

    No more issues with malware....

    Mike
     
    Last edited: Jul 14, 2008
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (substitute for cf whatever you renamed it)
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  20. mikem546

    mikem546 Private E-2

    Well, I thought I was doing pretty good, however, I may have not placed combofix in the right location. I attempted to do the run command and got an error so I must not have renamed it. I attached a zip file of the location for the apps I downloaded. I can take care of MGtools etc., along with the system restore but with combofix I am stuck unless I can go to Add/Remove Programs. Let me know if I screwed up here, thanks Tim

    Mike
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can just manually remove Combo form the desktop and the folders in the C: drive:

    ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt.
     
  22. mikem546

    mikem546 Private E-2

    Thanks Tim, I think we are good to go

    Mike
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds