Can't run TDSS Fixers

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by occcctane, Oct 26, 2012.

  1. occcctane

    occcctane Private E-2

    I downloaded both the tdsskiller and FixTDSS onto a flash drive from a public computer, then copied them from the flash drive to the desktop of the infected computer. Neither will run either as Admin or with a double-click. All that happens is a pause (denoted by the blue circle) and then that stops and I'm back to where I was. Nothing opens, nothing appears to run, nothing....

    What am I doing wrong? Do I have to be on the Internet for these to work?

    Win 7
    HP Pavilion dv6

    Problem: bts.scour redirect issues
     
  2. occcctane

    occcctane Private E-2

    I do have the log from MBR Check. Is that helpful yet at this point?
     
  3. occcctane

    occcctane Private E-2

    I've attached it.

    I am on a public computer and some of the download websites you provide links to are blocked. For example, the Rogue Killer(?) download site is blocked for 'malicious content.'

    I am attempting to follow all your instructions in the "READ AND RUN ME FIRST" post, and I've completed the first three steps (except I don't have Firefox). I've been foiled at Step 4 and don't know if I should attempt to move forward, because your instructions clearly say not to skip steps.
     

    Attached Files:

  4. occcctane

    occcctane Private E-2

    Correction: I clicked the link in the "READ AND RUN ME FIRST" and made it through the first three steps of the "Fixing Google Redirection/hijacking..." instructions.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Skip that and run the real full READ & RUN ME FIRST from beginning to end just ignore going off on the tangent to the Google hijacking link. The logs from the READ & RUN ME FIRST are what we will need. Just skip TDSSKiller if it still does not run when you get to it.
     
  6. occcctane

    occcctane Private E-2

    I was fooled by the part of the step that said "See this first" and it sent me to the Google Redirect Problems.

    When I got to the final step, "Windows 7 Malware Removal...." things started going haywire starting with Step 3. RogueKiller and MalwareBytes seemed to do as they should, however the TDSSKiller still didn't run. HitmanPro also didn't run as described. When trying to run as Admin, a window popped up that said that the program didn't run as expected, and that Windows applied some changes. It said to try again, When I did, the program opened, and I clicked the Settings button, but got a blank blue window without the tabs that you showed.

    It seems I am doomed.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but see where the end of step 5 in the redirect link sends you back to when still having problems. ;)



    Okay keep going as stated at the beginning of the READ & RUN ME which said the below
     
  8. occcctane

    occcctane Private E-2

    Logs are attached. I still could not get the TDSSKiller to run. All I got was the blue circle, but nothing opened. HitmanPro also still didn't have the tabs after I clicked the 'Settings' button.

    Win 7 64bit
    HP Pavilion

    suspect bts.scour, and received the FBI lockout screen
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you have a ZeroAccess infection.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  10. occcctane

    occcctane Private E-2

    Uh oh. That doesn't work. When I select "Repair Computer" I get a black screen. I let it sit for 15 minutes, and it never came off the black screen. It will boot up otherwise.

    ????
     
  11. occcctane

    occcctane Private E-2

    ....and, I got the FBI lockout again. The only way I know how to get past this is to do a system restore, so I did so to yesterday, at a Windows Defender restore point.

    This is just FYI just in case you'll need me to repeat any of the steps I've already completed.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Users\Tiger\AppData\Local\Temp\2147483647.dat
    C:\Users\Tiger\AppData\Local\Temp\3CE4.tmp
    C:\Users\Tiger\AppData\Local\Temp\dat69AB.tmp
    C:\Users\Tiger\AppData\Local\Temp\dat69CB.tmp
    C:\Users\Tiger\AppData\Local\Temp\datC9F2.tmp
    C:\Users\Tiger\AppData\Local\Temp\datD551.tmp
    C:\Users\Tiger\AppData\Local\Temp\datD562.tmp
    C:\Users\Tiger\AppData\Local\Temp\datD7E8.tmp
    C:\Users\Tiger\AppData\Local\Temp\dump.dat
    C:\Users\Tiger\AppData\Local\Temp\*.tmp
    C:\$Recycle.Bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$I3J4CA0.txt
    C:\$Recycle.Bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$IB2S49K.txt
    C:\$Recycle.Bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$IQTV3EV.exe
    C:\$Recycle.Bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$R3J4CA0.txt
    C:\$Recycle.Bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$RB2S49K.txt
    C:\$Recycle.Bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$RQTV3EV.exe
    C:\$recycle.bin\S-1-5-18\$e8bed0ce2337b17a6cb4df5d74554160\@
    C:\$recycle.bin\S-1-5-18\$e8bed0ce2337b17a6cb4df5d74554160\U
    C:\$recycle.bin\S-1-5-18\$e8bed0ce2337b17a6cb4df5d74554160\L
    C:\$recycle.bin\S-1-5-18\$e8bed0ce2337b17a6cb4df5d74554160
    C:\$recycle.bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$e8bed0ce2337b17a6cb4df5d74554160\n
    C:\$recycle.bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$e8bed0ce2337b17a6cb4df5d74554160\@
    C:\$recycle.bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$e8bed0ce2337b17a6cb4df5d74554160\U
    C:\$recycle.bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$e8bed0ce2337b17a6cb4df5d74554160\L
    C:\$recycle.bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$e8bed0ce2337b17a6cb4df5d74554160
     
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now since you did a System Restore, rerun Malwarebytes and fix anything it finds. Attach the new log.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:

    • the C:\_OTM\MovedFiles log
    • the the new Malwarebytes log log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. occcctane

    occcctane Private E-2

    Done. At least I was able to complete all those things. Do I attempt to return to the former instructions on System Recovery? I've stopped with only the instructions in your last post.

    Also, does this mean I could be clean now? I'm almost afraid of going to the Internet with that computer, except when the public computers don't allow me to go to a site that I have to go to.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the log from Malwarebytes' scan. Please attach below two files:
    Code:
    1,874 2012-10-29 18:07:11  C:\Users\Tiger\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2012-10-29 (14-07-02).txt
    2,260 2012-10-29 19:11:57  C:\Users\Tiger\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2012-10-29 (14-07-25).txt
    How are things working?
     
  15. occcctane

    occcctane Private E-2

    I do apologize. I had the wrong path.

    When I got my laptop home, I found it had rebooted on its own because it was giving me the "shut down improperly" message. It seems I can browse to the website I want only if I know the address. If I type in words that aren't an address, IE invokes Bing (which I normally do not use) to search, and then I get redirected to someplace I didn't ask for. It did this once and when I saw where it was going, I immediately killed IE and tried again, using only my browsing History or known addresses in full.
     

    Attached Files:

  16. occcctane

    occcctane Private E-2

    In addition, I am getting a Windows Defencer Alert. It says it has detected Trojan:Win32/Sirefef.AN and wants me to allow it to remove this. I believe it did so by itself once. To my knowledge, I don't have Windows Defender, so I am a bit leary about doing anything with this.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you do! It is built into Windows 7. ;) However it may only be finding the things we already quaranteened. Let's ignore it for now and cleanup what we have done and then see if it continues to find anything. So let's do all of the below.

    1. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    6. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    Now reboot your PC. See if Windows Defender still finds Win32/Sirefef.AN
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot, one more to do!


    Uninstall the below old versions of software:
    Java(TM) 6 Update 22

    Now install the current version of Sun Java from: Sun Java Runtime Environment
     
  19. occcctane

    occcctane Private E-2

    Done.

    I just noticed you are from NJ. Are you floating in a raft with wireless electricity to be able to post to the forums?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not this time. Thus far I have been lucky. We have a lot of damage around. Many many trees are down, but I currently still have power. That does not mean it will not go out. Residual damage sometimes occurs as trees/branches laying on wires eventually break the wires. And also transformers get overloaded when power is rerouting and sometimes the transformers eventually blow.
     
  21. occcctane

    occcctane Private E-2

    Good to hear.

    Here is what I've done this session, in order:
    0. I previously re-enabled UAC through the Control Panel.
    1. Replaced the Java.
    2. Downloaded and ran the Defogger.
    3. Attempted to uninstall HijackThis via Add/Remove, but it was not there.
    4. Ran the EnableUAC from MG Tools (for good measure, I hope).
    5. Deleted all the files for the tools we've been using, which were on the Desktop.
    6. Ran MGClean.bat.
    7. Went to Add/Remove to uninstall what I could find, and uninstalled CCleaner only. All others were not present, except Malwarebytes, which I opted to keep.
    8. Flushed the Restore Points, with reboot. Now it has been re-enabled.

    I am possibly noticing an uptick in the speed of IE loading webpages. Before all this, it was noticeably slower than typical, and my battery was being heavily taxed. I also hear my fan running a lot, which is not typical. I've not tried using any search engines - I still go only to pages through their full addresses.

    Should I be good to go?
     
    Last edited: Oct 30, 2012
  22. occcctane

    occcctane Private E-2

    OOPS! I still have redirect issues. I accidentally typed in an inaccurate address and Bing searched it. I thought I should just try the link to the correct site to see what happens, and I went to a different site. When I look at the browser back button, I see a list of about six redirects between Bing and where I actually went.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it. ( Note: If using Vista or Win7, don't double click on it, use right click and select Run As Administrator )
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    • Now reboot your PC.
    • After reboot, test your browsers again. If still being redirected, answer the below:
      • Are you redirected when you use IP addresses instead of URLs?
      • Or are you redirected only when using URLs?
      • When you go to google and do a search for something ( say "malware" ) when you select any of the matches, are you redirected then?
     
  24. occcctane

    occcctane Private E-2

    I did the download, unzip, run, and reboot. Here is what happens:

    I put in the IP for yahoo and it first went to a Yahoo page that said that the page could not be found, however after a few seconds I ended up on http://failsafe.fp.yahoo.com/

    I put "Google" into the Bing box, and when I clicked on the link, I got to Google. I did this two separate times.

    I put "Facebook" into the Bing box, and when I clicked on the link, I went through several redirect pages and ended up on "Daily Freshies." Among the links is bts.scour.com/index.html?3 Another one was mayoclnict.com..... There's more to it, but I didn't catch it all.
     
  25. occcctane

    occcctane Private E-2

    And yes, this morning Windows Defender found the Sirefef trojan again. I'm still ignoring it until you tell me otherwise.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please tell me exactly where it is finding it. Check for somekind of additional details/info.
     
  27. occcctane

    occcctane Private E-2

    I've opened WD and clicked the first entry. A screenshot is on the attached document, zipped to fit the file size limit. It shows that the problem was removed, however this was done by WD, not me.

    UPDATE: While writing this, a new warning showed up, so I clicked on details and took another screenshot. It is on the second page of the attached document.

    My computer runs extremely slow, and web pages often time out. When I look at my browsing history, I see pages that I didn't request, such as menshealthbase, womenshealthbase, and if.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure why this is showing. In the previous procedure with OTM, we removed that folder and OTM said it removed it. It also did not show in follow up logs.

    Is this still showing up in new alerts or new scans?

    Let's do a new scan with a new version of MGtools.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  29. occcctane

    occcctane Private E-2

    Downloaded new MGTools, saved to desktop, disabled UAC, ran as Admin, attached zip file.

    Notes:
    1. When the SteelWerX error came up, it not only said it quit working, but a second window came up that asked me did I want to send info to Microsoft, to which I answered yes. A second window came up asking did I want to send additional info, and I again answered yes. These two additional windows did not come up the last time I ran MGTools.
    2. When it was doing the DNS server test with nslookup, I got an error "Ordinal 1108 could not be located in dynamic link library WSOCK32.dll". I had to click OK to allow the script to proceed.

    I hope you find my problem in this attachment..... You are the greatest! :)
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have your PC's ethernet cable unplugged or since you seem to be using wireless, did you have the wireless interface disable? No connection to the internet could be seen.

    I don't see any sign of the folder in question. That is the below does not exist and this is what we remove with OTM and Windows Defender was also complaining about a subfolder of it:
    C:\$recycle.bin\S-1-5-21-1761797464-4276213647-1293801174-1000\$e8bed0ce2337b17a6cb4df5d74554160
     
    Last edited: Nov 2, 2012
  31. occcctane

    occcctane Private E-2

    I believe I ran the MGTools with the wireless turned on, in a public library. I can run it again and assure I have an Internet connection at the time if you need me to.

    My recycle bin (from my desktop) has only these files in it at this time:
    CCleaner shortcut
    CCleaner exe
    FixTDSS exe
    Malwarebytes shortcut
    Malwarebytes exe (mbam-setup-1.65.1.1000.exe)
    A pptx that I recently tossed

    I have also these other unusual things happening:
    1. I cannot eject my flashdrives the usual way. One has the U3 lauchpad that it prefers I use, and the other I eject via the USB link in the tray. In all cases I have to go the Windows Explorer and eject.
    2. IE routinely (2-3x/week) says it has stopped working, however none of my windows close. When I would get this message in the past, I'd lose at least one session of IE. Now everything freezes, but if I just leave it alone for a minute or two, I'm ready to go. Nothing ever closed or reopened.

    I don't know if these last little tidbits help any, but maybe they are clues for you. I figured (hoped) they'd go away once I am clean.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really. The all just sound like issues with various things in Windows that are broken. You could try the below to see if it helps at all but you will probably need to see if you can get any help on these issues in the Software Forum.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    You are clean based on all the last logs.
     
  33. occcctane

    occcctane Private E-2

    Thanks, I will do that next.

    I hate to tell you, but I am still having IE redirect issues. For example, I go to google.com and get Google. I search for "weather" and get expected results. I click on the title of the first one, with address "www.weather.com" which is an expected result. Here is where my browser goes:
    1. www.bacotreaent.com/go.php?id=a05a7821fed1fc8027abc939....
    2. http://distributorovernight.net/?a=YWZmaWQ9MDU1ODg=

    It never actually gets to weather.com. It stopped on a blank page at the address given in #2.

    Most of the time, it just times out, which is what happens when I try to go to the download link you provided in your last post. I'll keep trying.

    I hope you are staying warm and dry up there in Jersey. Sandy is still getting top billing in the news down here on most days.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do other browsers also get redirected? Make sure that you only have one browser open at any time when you test.

    Also download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
     
  35. occcctane

    occcctane Private E-2

    Glad you asked! :) I ran it last night, so here is the file..... uh oh. I notice the date on this file is 11/1, and yesterday is 11/3. I don't recall it asking me if I wanted to overwrite or not.... I probably assumed it just would. I do remember that it found 9 things, and most of them were "0Access" and several others were a Trojan. I also remember the "C:\$recycle..." location. I had it fix everything, so if I run it now, it probably won't find anything, right?

    And no, sorry, I tested only IE. When I've tried Chrome the computer becomes so slow that everything just times out, but I do have IE open at the same time. I'll close out my IE and test Chrome next.

    Sorry I am being such a pain! I wandered out on my own and that was a mistake! I should've waited for your instructions. I was frustrated with the long waits and locked up computer, and I'm in a class, so really need the Internet to just work! So sorry!!
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download the current version of MGtools.exe and rerun as requested. The most recent version is from just tonight.
     
  37. occcctane

    occcctane Private E-2

    Oh, my brain is so fried from studying all day!!! I meant that I ran Malwarebytes last night. I'm downloading the latest MGTools now, and will disable UAC and reboot before running it, then will send results. I'll be sure I have Internet access during the run as well.

    BTW, I went to Chrome and first I had to click on the Google Search icon, and when I, I saw in the bottom left 'youtube.com' - I'm not a youtube person, so I'm thinking that is a redirect. I then typed "weather" in the search and it returned the expected results with weather.com on top. I clicked on that and watched the lower left corner. It first went to "click.searchwebresults.com...." and then "adconversation.com...send request..." and then landed on "63.209.69.107...." which shows another set of search results for 'weather' in a very crude format. I dare not click on any of those..... :)

    Will check back in a minute with my MGTools results.....
     
  38. occcctane

    occcctane Private E-2

    Attached is the lastest MGTools log. I will also attach the Malwarebytes from yesterday for good measure, but have to go back through the forums to get the path correct.

    I hope running Malwarebyes doesn't mess up the MGTools results.
     

    Attached Files:

  39. occcctane

    occcctane Private E-2

    Here is the Malwarebytes log from yesterday.

    Thanks again for your patience with me!!
     

    Attached Files:

  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We really need to run the Farbar Recovery Scan Tool steps that I gave in message # 9. Are you sure that you cannot get this to work? Do you know someone who has a Windows 7 boot DVD that you could borrow?
     
  41. occcctane

    occcctane Private E-2

    I still get a black screen. I've tried it both with the "Restart" option from the start button and also by turning off the computer and booting it up cold. I get the F8 menu but when I select Repair Computer (which is the default) I get the black screen. I waited about 5 minutes each time.

    Sounds like this guy is messed up good, huh? I really haven't had trouble with it up until the initial 'FBI' screen. Once I had it telling me that my hard drive was bad, but the results that whatever tool I was using were conflicting (such as some parameter was too high and too low).... I installed and ran SeaTools, and all has been good. That was over a year ago. That's the only trouble I've had since this thing was new.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my other question
     
  43. occcctane

    occcctane Private E-2

    I do apologize. No, I do not. However, my computer came with a partitioned hard drive. Drive D is labelled 'Recovery' and Drive E is labelled 'HP Tools.' I've screenshot the the file folder tree so you can see what it there. I expanded it as much as possible. Some of the folders I can't expand; they shouldn't be hidden because I've taken off the 'Hide system folders.' Not sure why I can expand it any more than that.

    I don't know how to use either of these drives to do anything for me. Let me know if this could be a solution.
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not what we need at all. Using the Recovery Partition ( which assumes that malware has not damaged it ) would put you back to out of box from the factory state. Thus you loose everything you have installed/saved. It basically reimages your drive. For some infections, this does not remove the malware. I cannot say for sure that would be the case for you.

    Let's try something else to see if we can work around this. First uninstall any protection software that you still have installed. Don't worry about Windows Defender.


    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then right click on it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.
     
  45. occcctane

    occcctane Private E-2

    The Norton that came with the computer does not allow me to uninstall it. I've not used it past the 90-day free term, and have not renewed it, so hopefully it didn't cause any problems with the Combofix.

    Before I got your email, my computer became so slow that I couldn't get anything via the Internet. I ran a Malwarebytes scan last night. That will usually speed things up a little bit, and it did. Then I got your response and followed your instructions for Combofix.

    Both the Malwarebytes and Combofix logs are attached.
     

    Attached Files:

  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix to remove some more.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  47. occcctane

    occcctane Private E-2

    The computer is still running slow. This was a well-oiled and quick Internet machine before all this started. Just to bring up the Reply-Manage Attachments box took about 2 minutes.

    Google searches in IE still redirect. I did a search for "weather" and got the expected results. I clicked on the first result, 'weather.com' and watched the lower left corner. Here is what I saw (incomplete addresses, sorry):
    1. copytech.....
    2. bacotreaent.....
    3. click.livesearhcnow.com/ads-clicktrack/click/jump2.do?affiliateid.....
    4. I end up on the funky-looking search results page I mentioned before, addy: http://63.209.69.107/search/web/weather/a22/47539-525-direc47/v5

    I did the same search in Chrome, and got this:
    1. protection-searcher.com.....
    2. answers.nixxie.com/s.php?k=weather....3. I end up on Nixxie Answers with another funky-looking search results page. addy: http://answers.nixxie.com/s.php?k=w...tection-searcher.com/index.php?search=weather

    Oh, woe!
     

    Attached Files:

  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of your logs are clean so it does not appear to be from any present malware ( but we will scan for more below ). You did have a ZeroAccess infection to start, but right now, it appears to be gone. It is possible there is still residual damage and this is part of the reason I said to uninstall Norton and I still suggest that you do this. It may be broken. Even the trials that come with PCs can be uninstalled.

    Since you still have redirects, rerun RogueKiller and attach a new log. Also see if Hitman Pro will run now. If so run it and attach the log. I want to make sure the original MAX++ MBR infection got fix. If not, we need to fix this. You never answer my question about whether you have the Windows 7 boot DVD. Without this, you may not be able to fix the an MBR infection unless we get lucky with other tools and one we already tried (FRST you already cannot run).
     
    Last edited: Nov 8, 2012
  49. occcctane

    occcctane Private E-2

    When I try to uninstall the factory Norton, I'm doing it via 'Uninstall or change a program' in the Control Panel. I right-click on the program and choose "Uninstall/Change" and then nothing happens. It just returns to where I was. When I uninstalled other programs (Norton Online Backup, for example), it opened a progress box.

    I'm still looking for somebody with a Win7 disk, but no luck yet. It seems everybody gets their computers without disks these days, as was the case when I purchased this computer.

    I've been using random library Internet connections, so I don't believe it is a router issue. When I am at home, I am tethered to my smartphone for Internet access, but since I am up against my data plan limit, I'm not really using it much lately.

    I'm using a library computer to be able to reach you now, and will attach the logs when I get them.

    Thanks for your continued patience. Hope you are staying warm and dry up there. It looks devastating by what they show on the news.
     
  50. occcctane

    occcctane Private E-2

    Update on Hitman Pro. I copied the downloaded file to the desktop, then right-click 'Run as Administrator.' I get a popup that says:

    "Windows has detected that this program did not run correctly. To try and fix the problem, Windows has applied compatibility settings to this program. Windows will use these settings the next time you run the program. If you noticed that this program didn't run correctly, try running the program again. Program: HitmanPro 3.6 Publisher: SurfRight B.V. Location C:\Users\Tiger\Des...\HitmanPro36_x64.exe"

    This is what happened last time as well. When I close the window (the only option) and try again to Run as Admin, I get the green frontscreen. I click the 'Settings' button and again get the blue window. I tried holding the LEFT CTRL button as instructed. After the second try I get the Force Breach message at the bottom: "HitmanPro terminaged 19 processes." Now I can continue.

    I am doing this offline, so I clicked the "I'm an expert...." box on the Advanced tab, as instructed. I then selected EWS, and then "No...one-time scan."

    It is running now, so PROGRESS!!! Yeah! I will IGNORE all detections when it is complete.....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds