System integrity scan

Discussion in 'Malware Help (A Specialist Will Reply)' started by nowiamhere, Apr 18, 2008.

  1. nowiamhere

    nowiamhere Private E-2

    Hi - can someone please hep me! My PC has become infected with the virus which brings up popups like 'system integrity scan' and others which refer to abebot, security system protection control panel etc.

    I have tried used a couple of programs to get rid of it with no luck. I currently have Avast installed as my anti-virus program (have used it successfully for years) and since the issue occurred have been using Spyware Doctor.

    I gather this virus infects each PC slightly differently from what I have read. It also seems to be that people suggest doing a log with HiJackthis - which I have done. See below. Please help as my PC is running slow and so far I have wasted several days trying unsuccessfully trying to remove this.

    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Apr 18, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. nowiamhere

    nowiamhere Private E-2

    Hi TimW

    I have been following all the steps closely. Some of the scans have taken 2-3 hours to run. I just wanted to update you to let you know I have now completed and install / run of SuperAntispy which I had to run twice as the machine locked up partly through (in fact I then had to reboot several times before the machine returned to normal to allow me to rerun the scan). After having now run this and picking up several trojans it now appears that the virus has gone. I have left the machine running for a while and no sign of the popups as yet...

    I am reluctant to run SpyBots as suggested, as I did try installing and running this when the problem began. it seemed this was picking up things and causing compatibility issues with the anti-virus and Spyware Doctor (which I purchased).

    Is it necessary to continue with Malwarebytes etc?

    Other than waiting to see if it reappears - what do you suggest I do?

    Also I have been using Avast for some time and now have SpyDoctor and SuperAntispy installed - should I keep all of these running from now on?

    Final question - if I donwload something from p2p - what should I use / do to check a file before opening it?

    Really appreciate the advice...this is the first real experience I have had with a virus in many many years and it has been painful and time consuming!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Skip the SpyBot ....do do the MalwareBytes and the MGTools.exe as I want to see if there are any traces left ......and if you download something, scan it with your anti-virus before opening or installing.
     
  5. nowiamhere

    nowiamhere Private E-2

    Hi TimW

    I have now run the MalwareBytes and MGtools as suggested. Attached are the MGtools log files.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You ran MalwareBytes but you did not have it fix anything that it found! Please re-run it and do so. Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. nowiamhere

    nowiamhere Private E-2

    Hi

    I ran it again - attached. Both times I have run it (yesterday as per previous post and today) it has not detected anything.

    I am still suspicious that things are running a little slow still (could be I am paranoid now)...but there has been no sign of the original virus and the popups.

    Let me know what if anything I should do next.

    thanks
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Administrator\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  9. nowiamhere

    nowiamhere Private E-2

    Hi Tim

    I have followed all your steps closely and attach the log as requested.

    Things are still running slow. For example when I go to load a program it takes much longer that it should to load.

    Can you tell me also if I can now delete the things you asked me to save to the desktop?

    Also do you recommend I continue to run all the follow: Avast, Spy Doctor and SuperAntSpyware? What about any of the others I have downloaded and run during this process?
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can delete whatever was saved to the desktop....as to the slow performance, that would be best addressed in the software section.....Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  11. nowiamhere

    nowiamhere Private E-2

    TimW

    I thought I have followed each step pretty closely - but I don't recall this program and can not find any trace of it on my machine???? Is this something I should still install and run and then uninstall?

    Do you recommend removing the SuperAntiSpyware and Malwarebytes programs?

    I am definitely having a problem with everything running slow. It takes some time to register even when I do simple things like trying to get a list of program or scroll down a list of my files.

    thanks
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. nowiamhere

    nowiamhere Private E-2

    Hi TimW

    Thanks for all your help.

    Just a final couple of questions...

    Can you please let me know whether I should continue to be running all of the follow:

    1. Avast
    2. Spyware Doctor
    3. SuperAntiSpyware
    4. Malwarebytes

    Also when if ever should you run the CCleaner again?

    :confused
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I usually run ccleaner once a week ...but it would depend on how much time you spend on the web.

    Is Spyware Doctor a paid for version? If not, uninstall it.

    You can keep the others...avast is your real time protection...and the other two will give you back up and I would run them whenever you notice that there might be a problem ( or weekly if you want--- until you know/see what all is getting on the system from surfing the web).
     
  15. nowiamhere

    nowiamhere Private E-2

    Thanks TimW

    Yes Spy Doctor is a paid version. I will keep all four running for now - unless there is any way you think this may be causing my machine to run so slow?

    I will now have to investigate what could be causing everything to run so slow - there is definitely still a problem here. Even to switch between program or say different windows of firefox, I have to click on it three times before it responds. Opening even the list of programs from the start menu can take a couple of minute let alone actually opening a program.

    Can you suggest a particular forum for me to post problem?

    :confused
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just post in the software section...and good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds