Author Topic: Need help removing Scorpion Saver Malware  (Read 13099 times)

0 Members and 1 Guest are viewing this topic.

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #15 on: March 04, 2014, 09:33:29 PM »
More properly - which set of commands do you want me to run for the OTL Fix?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37473
  • Not a avast user
Re: Need help removing Scorpion Saver Malware
« Reply #16 on: March 04, 2014, 09:36:34 PM »
3. not necessary now
4. never install more then one AV
5. follow essexboys instructions


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Need help removing Scorpion Saver Malware
« Reply #17 on: March 04, 2014, 10:04:31 PM »
4) I can uninstall Avast, but not Symantec (corporate controlled). On the other hand, the file quarantining has stopped ever since I installed Avast - should I?

Follow Essex from now on. Solution to that. If you like Avast! more, ask them about getting a subscription to Avast! for your computers.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #18 on: March 04, 2014, 11:44:54 PM »
I was not certain if the OTL Fix ran correctly - it appeared that a reboot was supposed to happen automatically, but it never did.  Regardless, here is the output from the "quickscan" after the boot (was it really supposed to take over 30 min?)

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #19 on: March 05, 2014, 12:00:59 AM »
Here are the logs from ADWCleaner

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #20 on: March 05, 2014, 12:23:34 AM »
OK, I think I followed all the steps suggested, except perhaps for the timing of uninstalling Avast -- I didn't do that until all the other steps were completed because I could not find a method to do so. Finally after a google search, I found the link to the Avast Uninstall Tool, which I had to run in Safe Mode. 

I really appreciate all your help on this forum, unfortunately, ScorpionSaver is still showing in my Programs and Features (although SS Services is gone now).  And I'm still getting notice from Symantec that it is finding and quarantining files.   

Suggestions?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing Scorpion Saver Malware
« Reply #21 on: March 05, 2014, 10:38:43 AM »
It has returned in Firefox so I will use a different analysis tool to check other areas

Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from. 
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #22 on: March 05, 2014, 12:03:50 PM »
Here are the FRST files.  Thanks again for your help!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing Scorpion Saver Malware
« Reply #23 on: March 05, 2014, 12:17:43 PM »
Download the attached fixlist.txt to the same location as FRST
Run FRST and press fix
A log will be generated on completion please post that


TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #24 on: March 06, 2014, 04:51:37 PM »
Sorry about the delay, I was on the road yesterday.  Here is the fixlog file.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing Scorpion Saver Malware
« Reply #25 on: March 06, 2014, 04:56:21 PM »
No problem, is it still appearing ?  If so where

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #26 on: March 06, 2014, 05:18:37 PM »
Symantec is still capturing and quarantining files in c:\Users\...\AppData\Local\Temp\.

Also, ScorpionSaver still shows up in Control Panel and refuses to uninstall.

Offline Tangy

  • Full Member
  • ***
  • Posts: 149
Re: Need help removing Scorpion Saver Malware
« Reply #27 on: March 06, 2014, 05:34:23 PM »
« Last Edit: March 06, 2014, 05:38:17 PM by Tangy »
OS:Win xpsp3 pro, CPU:2.8 GHz, Ram:4 Gb HD:500 Gb,Avastfree18.8.22356,OSArmor,Basilisk+NewMoon(Roytam1),ublockorigin,Adguard, SystemExplorer, MCShield, MBAM on demand, FW:PC Tools Plus ,WinPat,Decentraleyes,privacy badger,minerblock.
OS : Windows 7 pro 64bits Avast free Malwarebytes antiexploit

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing Scorpion Saver Malware
« Reply #28 on: March 06, 2014, 07:24:04 PM »
All that remains as far as I can see is the uninstall entry

So the temp file would tend to suggest something else

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

TboneDaddy

  • Guest
Re: Need help removing Scorpion Saver Malware
« Reply #29 on: March 07, 2014, 05:39:06 AM »
So after running ComboFix (which took nearly an hour, including after the reboot), here is the output log.

BTW, Symantec must have restarted immediately after the reboot, because it started capturing errors even before ComboFix was finished, however when I looked at it's status just before sending this, it shows as "disabled".