help with malware removal- logs attached.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by 1i1paco, Apr 9, 2011.

  1. 1i1paco

    1i1paco Private E-2

    Just finished the malware removal procedures and my computer seems to be having the same problems. I am using google chrome browser and has crashed on me a few times before. It hasnt crashed on me since i started the procedure but the internet is still not at its best. I just moved in with my gf and it is her laptop so i am not quite sure how long the computer has been having this problem. She says maybe a few months but it could be longer. I attached logs from SUPERAntiSpyware, Malwarebytes Anti-Malware, and MGtools. When i tried running combofix my computer crashed and restarted in recovery mode. I started windows normally and skipped this step. Also when i tried running Root Repeal i got an error message: FOPS- Device Io control error!. I also had to skip this step. Everything else ran fine and logs are attached. Any help is greatly appreciated. Thank You.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing much in your system, though I need you to tell me what these are:
    C:\ProgramData\aPcIcEn08509
    C:\ProgramData\dNpMdAm08509
    C:\ProgramData\WqehTRYH.dat

    If you don't know, delete them. Also delete this:
    C:\Program Files\AVG

    Tell me exactly what issues you are having.
     
  3. 1i1paco

    1i1paco Private E-2

    Mostly just slow internet. We were using IE before but switched to google chrome browser. But like i said before chrome would crash out of nowhere,although it hasn't done so since the scans and the internet seems better also. But if everything seems fine should i just continue to the next steps? Also i am not sure what those files are. I will delete them.
     
  4. 1i1paco

    1i1paco Private E-2

    I couldnt seem to find those files you mentioned. How would i go about deleting them?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if they still exist:

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  6. 1i1paco

    1i1paco Private E-2

    Logs attached
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My mistake, let's do it again.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Then attach the below logs:

    * C:\Avenger.txt
     
  8. 1i1paco

    1i1paco Private E-2

    Ok here it is.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That should have done it. Tell me what malware issues you are still having, if any.
     
  10. 1i1paco

    1i1paco Private E-2

    Everything seems to be doing fine. Thanks for the help, i really appreciate it.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  12. 1i1paco

    1i1paco Private E-2

    I was unable to uninstall combofix. My computer crashed and restarted right before it could finish. Also how do i uninstall rootrepeal?
     
  13. 1i1paco

    1i1paco Private E-2

    Nevermind. Everything was cleaned up after i ran the mgclean.bat file. It even uninstalled combofix :). Again thanks for everything.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds