having problems, read the read me first and did all the appropriate steps

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jackbenimble222, Jan 30, 2012.

  1. jackbenimble222

    jackbenimble222 Private E-2

    here is my root report

    ====

    and malwarebytes says : runtime error '0' and runtime error '440' ?


    ====

    please help me as soon as possible after i ran all the programs in the read me first my computer started to freeze for no reason and do other wierd things that it wasn't doing before. i believe before i had a virus called rootkit so i hope that helps
     
    Last edited by a moderator: Jan 30, 2012
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to take a look at this.

    HOW TO: Attach Items To Your Post

    You need to also attach logs from running MGTools and SUPERantispyware. Posting them inline the way you did is not appropriate, and hard for me to read.
     
  3. jackbenimble222

    jackbenimble222 Private E-2

    oh sorry sir.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have attached logs seperately from out of the zipped file. Because the file is zipped, there is no need to do what you did, please attach the complete MGlogs.zip file. Thanks.
     
  5. jackbenimble222

    jackbenimble222 Private E-2

    here is super anti spyware and the last log for mglogs
     

    Attached Files:

  6. jackbenimble222

    jackbenimble222 Private E-2

    I will try to make this one right, i apologize my friend
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, let's crack on...

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    JFYTGYU
    KUBPLLMFBDBV
    File::
    c:\docume~1\ADMINI~1\LOCALS~1\Temp\JFYTGYU.exe
    c:\docume~1\ADMINI~1\LOCALS~1\Temp\KUBPLLMFBDBV.exe
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint 
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. jackbenimble222

    jackbenimble222 Private E-2

    my icons are now really huge.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach the log from MBRCheck please? Thanks. Also does MalwareBytes run now? And apart from having "big icons" are there any remaining malware problems? (Do you mean the icons on your desktop are large? If not, explain.)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See it in MGlogs.zip ;) Why is such an old version of MGtools being used?

    The items delete with TDSSkiller should not have been deleted. See the instructions.
     
    Last edited: Feb 3, 2012
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No those items should not have been deleted/quarantined. @jackbenimble222, are you able to use System Restore to get back to a time as close to the 3rd as possible? TDSSKiller got those items on 3rd Feb, so restore back to somewhere close prior to that please and then do this:

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip
     
  12. jackbenimble222

    jackbenimble222 Private E-2

    ok so i've restored back to the 2nd and here is my updated mglogs and MBR report. the icons were big but i just had to adjust the appearance and also windows media player will not start it says "log of windows and log back on" but its been saying that since we started this
     

    Attached Files:

  13. jackbenimble222

    jackbenimble222 Private E-2

    malwarebytes does not run, same error messages and now my media is skipping and playing weird??? please get back to me
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry Jackbenimble you missed my radar somehow. It's late here now but I'll get to work on reviewing the latest logs. :)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not positive the restore worked to get those files back in place again. It looks to me like it did not.

    Rerun TDSSKiller but do not fix anything, just get me a new log.

    I want you to uninstall the version of Malware Bytes that you have, download a fresh copy, and reinstall. See if it will now run. If it still fails, check the Malware Bytes FAQ section, and look for issue 15 ISSUE: I'm getting a Runtime error 0 and 440 automation error. Follow advice.

    The other problems you have do not sound malware related to me.
     
  16. jackbenimble222

    jackbenimble222 Private E-2

    ok well my problems with media playback started only after i started this, and more exactly after i ran combofix here is the log from tssddkl
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Mere coincidence, Combofix did not make any deletions on it's own. The only deletions it made were ones I included in my script. I am seeking advice on those items that TDSSKiller quarantined.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have been advised by thisisu that you should reinstall your video card drivers.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds