superantispyware stopping

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by icandoit, Jun 14, 2009.

  1. icandoit

    icandoit Private E-2

    I'd be grateful of some help here.
    Found yesterday morning that my daily overnight scan by AVG was still running after 11 hours (normally 1 - 2 hours), and the only way I could stop it was by turning the machine off. It would not stop from task manager either.
    Later recovered the log which mentioned "Trojan Horse Downloader Generic8.AGSJ" and "SkyNet********.***".
    Did some searching and came across this site, and followed the "Read and Run me first" post.
    The problem at the moment is when scanning with SAS it keeps stopping. The first time I left it running for 3 hours it found nothing but had stuck at "C:\windows\system32\config\SOFTWARE.LOG1". Tried it twice more but it seems to stop at "C:\windows\system32\config\Regback" after about 40 minutes.
    As far as can tell I've done everything to the letter, but will recheck now.
    Thanks in advance
     
  2. icandoit

    icandoit Private E-2

    As a follow on to my previous post, I have tried to complete the tasks required in the vista cleaning procedure link on the “read and run me post” and have encountered problems on all points as follows.
    Superantispyware failed while showing “C:\windows\system32\config\regback”
    Malwarebytes failed while showing “C:\windows\system32\wbem\xwizards.mof”
    Combofix failed
    MGTools appeared to finish and showed “C:\mglogs.zip” but cannot find
    The first 3 above all stalled and had to be closed with either task manager or by turning off the machine, the mgtools seemed to complete but the file cannot be found.
    I’m starting to lose the will to live at the moment and any help and advice will be greatly appreciated.
     
  3. icandoit

    icandoit Private E-2

    Got there, eventually

    I have started a new post regarding my previous attempts to scan and obtain logs. I eventually managed to complete the range of scans needed and have attached logs.
    It seems pointless to fill this post with possibly unnecessary ramblings, as far as I can tell everything was carried out to instruction, just ask.
    Many thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome:

    Okay just so we cover all bases let's try this assuming you haven't already done so when you followed the R&R:

    If you have problems where no tools seem to run, please try following the steps given in the below:

    TDSSserv Non-Plug & Play Driver Disable


    1. For SUPERantispyware let's try:
    • Try the Alternate start method (start > all progs > Superantispyware > alternate start)
    • Also if the above doesn't let you open up the program then please try:
    • Rename SuperAntiSpyware.exe to SAS.EXE and then navigate to C:\Program Files\SUPERAntiSpyware and again rename the superantispyware.exe to SAS.exe. See if it will run now, if it does don't forget to update > scan > fix all it finds and get me the log it produces.

    Also:

    NOTE: If you get a blue screen type crash when trying to run the scan then after reboot, configure the below options and rescan
    • Run SuperAntiSpyware
    • In SUPERAntiSpyware under Configuration and Preferences, click the Preferences button.
    • Click the Scanning Control tab.
    • Under Scanner Options uncheck the below two options
    • Use Kernel Direct File Access (recommended)
    • Use Kernel Direct Registry Access (recommended)
    • Then try doing a new Complete. If it still crashes, just skip SUPERAntispyware and continue with the other instructions. If the scan runs, continue on with the below steps.
    • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    • Make sure everything has a checkmark next to it and click "Next".

    2. For Combofix:

    • Please ensure that it is indeed downloaded and attempted to be run from your desktop. If it already was here before you tried running it then please let's rename it to 123.com and again have another go at running.
    • Attach the log it generates if you were successful.

    3. For MGTOOLS

    So the logs should be sat right on your C drive:

    C:\Mglogs.zip

    Please attach this into your next reply as well as trying all that I suggested above and let me know how you get on with it.

    Thanks
    kestrel13!
     
  5. icandoit

    icandoit Private E-2

    kestrel13
    Thanks for responding, I started a new thread a couple of days after this one, once I managed to complete the R&R as I didn't wish to upset anyone. This is now on Page 5 headed - "got there eventually". Shall I post the logs again here?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your threads have been merged... so I'll go thru your logs this evening soon as I have had some coffee and some food and get back to you with a response ASAP :)
     
  7. icandoit

    icandoit Private E-2

    Had to bring this to the top, before it gets lost.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, you didn't have to do that at all ;) I was getting around to answering you don't you worry... I had not forgotton you.

    Don't Bump! It Only Hurts You!!!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The scans took care of things just a couple things left to do:

    1. You are not running any anti virus on this machine which is leaving yourself wide open to attack each time you surf. Once we are done here you can install some from our recommended list which will be in a link I give in my final instructions called "How to preotect yourself from malware"

    2. Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3. Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    4. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. icandoit

    icandoit Private E-2

    Kestrel13
    Thanks for the reply in answer, I do have AVG 8.5 (paid version) on my machine but could not disable a couple of the components so uninstalled for the scans. One of them, not sure which, but I believe combofix warned me permanent damage was possible so took the "safe" way out.
    This now means that your third line:
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    Is pertinent to AVG, could this be the other 2 lines as well and which ones would I select?
    Thanks
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    select all three of them :)
     
  12. icandoit

    icandoit Private E-2

    kestrel13
    Merged the fixME.reg no problem. Went through your list as far as 7. and MGclean.bat does not appear to exist. Have attached snapshot of MGTools folder contents.
    Thanks for your patience.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That was my fault, it is part of the newest version of MGTools which we did not use. I forgot to disinclude that part in my final instructions.

    Safe surfing! :)
     
  14. icandoit

    icandoit Private E-2

    kestrel13
    How then do I remove MGTools and anything associated with it, or do I even need to?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Simply go to your C Drive and delete the MGTools.exe and delete any mglogs.zip files.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds