Still Getting ....

Discussion in 'Malware Help (A Specialist Will Reply)' started by ForeverYoung, Feb 26, 2009.

  1. ForeverYoung

    ForeverYoung Private E-2

    I'm still getting Found Adware. Rogue Suspect on my AVG antivirus. OS is Windows Vista & this is my sons computer. I need my files checked.
     

    Attached Files:

  2. ForeverYoung

    ForeverYoung Private E-2

    Malwarebytes
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what AVG is reporting.
     
  4. ForeverYoung

    ForeverYoung Private E-2

    Found Adware.RogueSuspect

    HKU\S-1-5-21-1199803121-450095120-661195697-1000\Software\Ascentive

    & that's all it shows on AVG when I scan the computer.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ascentive offers a number of software programs that offer to speed up your internet, etc.

    Did you at one time have one of their products?

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Registry::
    [-HKU\S-1-5-21-1199803121-450095120-661195697-1000\Software\Ascentive]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach that log and also rescan with your AV software.
     
  6. ForeverYoung

    ForeverYoung Private E-2

    Just to let you know, I had to work 14hr days this week end & had no time to work on my sons computer. I got home today & found another "something" on his computer called Anti-virus-1 which I know is a threat on this computer. I am going to have to redo the read & run me first tutorial again, & then go back & try what you said below. I have no idea how this crap is coming on this computer but bear with me please. Darn teenagers anyways!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...it would be best to start over with the instructions and get me new logs. :(
     
  8. ForeverYoung

    ForeverYoung Private E-2

    ok here are the "new" results & after I post these, I will complete what you posted previously & repost. Everything seems to be working good at this point.;)
     

    Attached Files:

  9. ForeverYoung

    ForeverYoung Private E-2

    and here's combofix
     

    Attached Files:

  10. ForeverYoung

    ForeverYoung Private E-2

    Ok here's the other combofix log after I created the CFscript.txt. Also, sadly to say, I just started re running my AVG & it still displays the

    Found Adware.RogueSuspect: HKU\S-1-5-21-1199803121-450095120-661195697-1000\Software\Ascentive

    If I go to local disk C - program files, I can see an Ascentive folder there & if I double click on it there's a file that says performance center and then when I click on that there's a GUID file & a SOUND.WAV file. Would that have anything to do with the antivirus picking up the RogueSuspect or is that something totally different? :confused However, it's the only "bad thing" listed on my AVG. This is a windows vista & was also wondering about why the AVG in the windows security center says the AVG is turned off? When I try to turn it on in the windows security section it won't....yet it seems to be running & updating just fine.
     

    Attached Files:

  11. ForeverYoung

    ForeverYoung Private E-2

    I fixed the AVG problem. apparently I was running AVG 8.0 & there's a newer version out AVG 8.5. Now I'm "not" getting the Found Adware.RogueSuspect message.... & everything seems to be just fine. When I tried to remove AVG 8.0 it wouldn't uninstall no matter what I did. So I just went ahead & downloaded the new version anyways & installed the new version. Once the new version was up & running, the old version completely disappeared, including in the add/remove programs.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....AVG has been a bit buggy since they have released the newer version.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds