Can't Finish Running MG tools

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cuchulain64, Oct 26, 2008.

  1. cuchulain64

    cuchulain64 Private E-2

    please help i'm trying to clean a friends machine. I have tried following all the steps on the read and Run me first but MGtools gets to runkeys 15 and then it locks up. A messgae pops up saying that

    "c:\windows\system32\cmd.exe
    C:\windows\system32\autoexec.nt The system file is not suitable for running ms-dos and microsoft windows applications. chose close to terminate the application"

    I have attached the log files.

    I know that the system needs to have updates and patches applied and that antivirus is not installed but I wanted to try and remove all the infections first before patching and updating.

    PLease advise the best course of action.

    Thanks
     

    Attached Files:

  2. cuchulain64

    cuchulain64 Private E-2

    Attached are the logs from the aborted mgtools
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please see this thread...scroll down to your error message and apply the fix:
    http://forums.majorgeeks.com/showthread.php?t=137630

    In the meantime, copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  4. cuchulain64

    cuchulain64 Private E-2

    Hi Tim

    Major problem

    I Followed your steps
    1 downloaded xppro fix for running mgtools
    2 created and merged fixME.reg
    3 Downloaded and rang avenger
    4 Input text into script input box
    5 rebooted system - Or tried to

    This is where problem arose once presented with the welcome screen and selecting user name left with an eggtimer cursor and walpaper picture no startbutton or icons.

    Same thing when i tried rebooing into safe mode.

    Help?
    how can i get back in to run mgtools and get log file for avenger
     
  5. cuchulain64

    cuchulain64 Private E-2

    ctrl alt del x 2 let me bring up task manager and run explorer which allowed me back in.

    so attached now are avenger log and new mgtools log.

    I know its not sorted as i have an icon red shield with x and pop up ballon text saying "your pc is infected by virus. click here to remove this virus" (yeah Right) That's probably how they got here in the first place.

    There has on a few occasions on rebot during thei process an installer has started to install sexvid knowing that this is a family pc and the owners ask me to try and clean it because adult popups had started appearing as well as the slowness etc any idea's as to where the installer is and how to stop it trying to run also would be appreciated.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...we are making progress...however I want you to remove all of the MGTool files and folders and download the latest version from the Read and Run First instructions.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now use add/remove programs to uninstall:
    Viewpoint Media Player

    Now download and install:
    Java Runtime 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the new MGLogs.zip after downloading and running the latest version. :)
     
  7. cuchulain64

    cuchulain64 Private E-2

    Hi Tim

    I have riun the latest batch of cleaning tools as requested

    attached logs

    but still on reboot i have to use ctrl alt del and then once task manager comes up run explorer to see desktop icons.

    also when this machine wouldn't connect to the internet at the early stages of cleaning i had to download combofix etc to usb drive and then transfer to desktop, could this have spread infection?
     

    Attached Files:

  8. cuchulain64

    cuchulain64 Private E-2

    I'm still getting the icon and quote ballon in taskbar saying "your computer is infected by virus. click here to remove virus"
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you run SAS and MWB's on each user account? Please log into each account and run them..if they find anything, attach that log. Do this on each user account.
     
  10. cuchulain64

    cuchulain64 Private E-2

    Hi Tim

    there were 5 users so it took a while to run all scans.

    I have attached the logs from SAS & MBAm

    The last user was the one i Think as when sas was running i got lots of popups appear.

    Think it's clean now but await your response.

    Thanks
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please log into that user account and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  12. cuchulain64

    cuchulain64 Private E-2

    Attached MGlogs files for the user which had problems
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still in that user account....

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  14. cuchulain64

    cuchulain64 Private E-2

    I could only find the first two lines
    fixme.reg merged sucessfully into registry

    wouldn't let me delete anything in windows\temp even older than today's date most folders refered to file desktop.ini but all said access denied.

    There is a desktop.ini file on the desktop for this and at least one other user. Should these be deleted?

    all seems fine avenge.txt and mglogs.zip attached. After last work automatic updates turned back on and installed sp2.

    I have SP3 downloaded to usb drive and ready but didn't want to install until you think it's ok. Please advise when i should install it and other updates from windows update and install antivirus as the Norton on this machine is 5 years out of date. defs 23/05/2003.

    Thanks.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Having Norton without updates is worthless....you should run the Norton Removal tool and then choose a new anti-virus program.

    You need to disable the guest account in the user accounts, run the Messenger removal tool on this user account.

    Otherwise you look good......if you are not having any other malware issues, then:

     
  16. cuchulain64

    cuchulain64 Private E-2

    Thanks for all your help Tim
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds