Total Vista Security

Discussion in 'Malware Help (A Specialist Will Reply)' started by krisangels, Apr 4, 2010.

  1. krisangels

    krisangels Private E-2

    Two days ago, I had a run in with the Total Vista Security Virus, which made it so I could not function. I rebooted, hit f8, did a system restore and everything seemed to be fine. 48 hours later the virus came back. I restored to the earliest point possible, and then went through the read me and followed all the steps. I do not have any noticeable problems right now, but I know the virus is ready to pounce. My logs are attached please help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not allow MGTools to run to completion. You are missing numerous files from the zip file. And unless you are running a 64bit version of Vista, I also need the logs from running RootRepeal and ComboFix.
     
  3. krisangels

    krisangels Private E-2

    I am running a 64 bit Vista. Here's the correct log file you need. Thanks for your help.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what these are:
    C:\Users\Niga Pleez\AppData\Local\8Cq4r
    C:\Users\Niga Pleez\AppData\Roaming\Microsoft\Windows\Templates\8Cq4r
    C:\ProgramData\8Cq4r

    If not, delete them.

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 15"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7"

    Use windows explorer to find and delete:
    C:\Windows\TEMP\GUR95D8.tmp
    C:\Windows\TEMP\GURB318.tmp
    C:\Windows\TEMP\MpSigStub.log
    C:\Windows\TEMP\UDD8872.tmp
    C:\Windows\TEMP\_asw_aisI.tm~a01536
    C:\Users\Niga Pleez\AppData\Local\Temp\4c235.msi
    C:\Users\Niga Pleez\AppData\Local\Temp\svjf7.tmp

    Reboot and download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. krisangels

    krisangels Private E-2

    I was able to do everything except locate and delete the following files...

    C:\Windows\TEMP\_asw_aisI.tm~a01536
    C:\Users\Niga Pleez\AppData\Local\Temp\svjf7.tmp

    The computer seems to be running fine, except for the fact that my anti-virus Avast is and has been in an "inconsistent state" and if I click fix or re-start it does nothing. I also have the Windows security alerts constantly in my taskbar because of this. Its never usually there. Should I just try and get a new anti-virus...I still have the feeling somethings lurking but here's my logs and let me know what to do next. Thanks a lot.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You at one time or another had Avira installed. So, since I am not seeing any malware left on your system, you should try uninstalling Avast, run CCleaner and then try to re-install it.

    In the meantime, lets remove the old Avira items.

    Use windows explorer to find and delete:
    C:\ProgramData\Avira
    C:\Program Files (x86)\Avira

    Tell me how that goes and if re-installing Avast worked.
     
  7. krisangels

    krisangels Private E-2

    Ok, everything seems to be working solidly. Can you just send me the instructions for resetting everything like User Account control and re hiding the files. Thanks for your help! Were those first files you had me delete malware or just useless program files?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some of the files were malware, while others were leftovers. Here are the final clean up instructions:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds