Fonts File Corrupt or System 32

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kissfans2004, Jul 16, 2008.

  1. Kissfans2004

    Kissfans2004 Private E-2

    I have a problem with Windows XP. I have a Continually Growing Windows Fonts folder that I would really like to get fixed. I have tried a Few of the Thread fixes on this site and had minimal progress. I now get a System 32 Error on User Logon and a Black Box for Text. I can get around it if I go to Windows Task Manager and End Process of Explorer.exe and Re-Enable Explorer.exe from the Type Field Then all is OK except for the Fonts File. All the Files under Windows Fonts are Locked and Passworded so that I cannot Delete or do anything with them! PLEASE HELP!!!!!!!!!!!!!!:cry:(:confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Kissfans2004

    Kissfans2004 Private E-2

    The only Log that I could retrieve was ComboFix and it is in the Attachments of this Post now. Thanks for the Reply and Further Help!!!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run all of the tools and attach all of the logs! We cannot help you based on only a log from ComboFix which you have not attach anyway.
     
  5. Kissfans2004

    Kissfans2004 Private E-2

    Working on it as we Speak:eek:
     
  6. Kissfans2004

    Kissfans2004 Private E-2

    Hopefully the Logs are Attached This time and ALL 3 are there if they Did.:-D
     

    Attached Files:

  7. Kissfans2004

    Kissfans2004 Private E-2

    I Also have The MG Zip Files Ready for You When you Need Them!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need it now. As requested in the READ & RUN ME, you need to attach all 4 logs.
     
  9. Kissfans2004

    Kissfans2004 Private E-2

    Just got back home----Is this what U Need?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I need what is requested in the READ & RUN ME. Here is what it states
    You just need to attach the MGlogs.zip file since you attached the other 3 already.
     
  11. Kissfans2004

    Kissfans2004 Private E-2

    OK On the Way
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you are running without any protection software? No antivirus, antispyware or real true firewall protection (the Windows firewall is not a good firewall).

    Is the below a start page you configured? Bearshare was a P2P program famous for bundling malware!
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/

    Rename this: C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe.exe
    To have one EXE file extension like this: C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe


    Uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. Kissfans2004

    Kissfans2004 Private E-2

    I will be REInstalling McAfee Now. I took it off because it had a Fatal Error. EVERYTHING Looks and Acts GREAT now!!!!!!!! Thanks for ALL of your Help!!!!!!!!!!!!!!:-D:cool:wave
     

    Attached Files:

    Last edited by a moderator: Jul 17, 2008
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds