windows 7 internet security 2011 installed

Discussion in 'Malware Help (A Specialist Will Reply)' started by locodave, Mar 9, 2011.

  1. locodave

    locodave Corporal

    Windows 7 HP Pavillion.

    Ahh, when a friend brings over his girlfriends computer her teenage son decides to say yes! yes! Want to ok this on sights he goes to? Got this ugly. Wants me to fix. From what I learned here. I ran rkill 1st. Now running Malwarebytes full scan. Had to get them there thru a USB drive. Left the drive in to have MWB scan it too.

    She was smart enough to not click on anything when the program installed to try to "fix-repair" it. Should I run Super anti-spyware also? What about Trend-micro-housecall?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. locodave

    locodave Corporal

    Thanks Tim, I'm slowly going thru it. Saving scans as I go. I had to use rkill 1st as Malwarebytes wouldn't run when I tryed. As I had installed it on the computer last time I helped her with another prob she had on uglys. 8 months ago. She took it to G--k s---d before I got it and they didn't clean it out like they should have. Free tools listed here are what I used before when I played with it last. It also has My web search tool bar now and I need to get rid of. Running Spybot I installed before and it found 3 more uglys. Had to re-start to fix one thing and doing a full scan. Browser hy-jacker, trogen, my search.

    I'm un-experienced with Win7 on settings. I'll list later when it stops scanning. If I remember from earler. Admin privys was turned off on settings. Normal or not. Any program I had installed before is now not letting me run it unless I r/click on the shortcut and chose run as admin. Even if I do this, some anti-virus programs won't run. And had to re-install by the USB drive.

    By the by, I've been comming to this sight for years and recomended it to others on safe downloads. Just didn't pay attention to the forums. I've always liked your top freeware picks on downloads.
     
    Last edited: Mar 10, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the logs that you can get so I can take a look at what is happening in that system.
     
  5. locodave

    locodave Corporal

    Dual post as I got a you have to wait 30 seconds before posting again. I re-posted the same as below. as I didn't think the original post got posted.
     
    Last edited: Mar 12, 2011
  6. locodave

    locodave Corporal

    Tim, I screwed up on Combox. When it wanted to up-date to a new version. I said yes. Thinking it was going to install it when I clicked on run. It installed it, but also ran the program. I haven't shut off the computer.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me where you are at, at this point. Did you get a Combo log? Have you gotten any of the other logs?
     
  8. locodave

    locodave Corporal

    When I ran Combox the 1st time it said it saved it. C:\ComboFix.txt I can't find it. Ran Combox a 2nd time to get another log. That was not a good thing. When I try to open a browser. I get the message that lllegal operation on a registry key that has been marked for deletion.

    Same thing if I try control panel. I can get into pictures, documents. I'm going to back up as much as I can to a USB drive just incase.

    Another thing this has is Recovery manager. In advanced. My choices are Computer checkup, Software program re-installer, Hardware driver re-installer, Misrosoft System restore, System recovery, Recovery disk creation, View recovery report, Remove recovery partition.

    Combox did create a recovery console when it 1st installed. But think I won't see it unless I re-boot.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should go away once you reboot. If you can't or don't have the Combo log, please just move on and get me the rest of the requested logs.
     
  10. locodave

    locodave Corporal

    Think I'm doing it right on here are the logs. I was thinking bad-bad things when I got that error message before.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put ComboFix directly on your desktop, not here:
    Running from: F:\ComboFix.exe

    I still need the C:\MGLogs.zip.
     
  12. locodave

    locodave Corporal

    I ran another Combox and later saw I needed to dis-able UAC. Followed the instructions. Thank you for your patience. I was replacing an intake manifold on a 97 ford today.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Assuming that you did have MBAM fix what it found, let's just do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Users\zosia\AppData\Local\.))S](VL)0[(+
    C:\Users\zosia\AppData\Roaming\Microsoft\Windows\Templates\.))S](VL)0[(+
    C:\ProgramData\.))S](VL)0[(+
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  14. locodave

    locodave Corporal

    Tim, Here are the logs. I gotta hand it to you. I feel like a highschool kid talking to someone with a master degree and trying to keep up. I've gotta re-enable UAC before I forget.
     

    Attached Files:

  15. locodave

    locodave Corporal

    Tim, I did a little more this morning on up-dates. It's working like normal as far as I can tell. I can't thank you enough on helping me thru this.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  17. locodave

    locodave Corporal

    Tim, Went thru the steps. Only prob I had was the MGclean.bat file. Said empty. I reloaded MG and the process had it. Went thru the steps to use it. Not too swift sometimes on clicking run as Admin & thinking as UAC was back up and running. Why the prob.

    I do think it did it ok on the re-do. I'm re-loading Java. MG tools are gone. ( I un-installed Java and Flash player. ) Going to re-load Flash player next.

    On fixing this with your help. On a previous post. She took it to G--- S----. ( You can figure out where she took it. ) She paid $300, got it back. Still yuked up. Her boyfriend, my friend. Brought it over. Only took me a day to get rid of things using Malwarebytes, ect. What I know. Worked fine till her son got on it. You took me thru the steps I never knew were avaliable to do. Kudo's to you. One ell of a sight you have here and passing it on to ppl I know.

    I installed Zonelabs free firewall. Do you see a prob with doing it? Most of all it keeps programs from being a server.
     
    Last edited: Mar 16, 2011
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good. You need to have a firewall installed. Windows firewall is pretty worthless.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds