Pre malware removal question

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bodybag219, Jul 19, 2008.

  1. bodybag219

    bodybag219 Private E-2

    One of the procedures required is to download a variety of tools, one of them being SUPERantispyware.

    I already have this on my pc, so should I remove this program and reinstall it when i get to the pc clean up section in the removing malware guide or is it ok that its already installed and won't effect any of the clean up procedure?

    Cheers and thanks

    bodybag
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that you have the current version and the current updates? Click our link. Is that the version you have? If yes, just get the updates and continue. If that is not the version you have then uninstall it and use the version in our link (also making sure you get the updates after installing).
     
  3. bodybag219

    bodybag219 Private E-2

    Hi Chaslang,

    Thankyou for your reply.

    As I was wanting to make a start on the malware removal I took the safer option of removing my existing SUPERAntispyware and doing a new instal via this website + updates.

    I have now done a scan with the above software and am about to proceed to the next phase. Will keep you posted when complete.

    Regards

    bodybag
     
  4. bodybag219

    bodybag219 Private E-2

    Read & Run Me completed (nearly)

    Hi again

    I have worked my way through the Read & Run Me First guide and i did encounter a couple of problem which i will mention in order of occurrence.

    Prior to commencing anything, upon starting my PC I was receiving the following message:

    "RUNDLL

    Error loading C:\WINDOWS\system32\terdsrmv.dll

    The specific module could not be found"

    This message has since stopped appearing following some of the scans

    During the basic computer maintenance section I did d/l IObit SmartDefrag to supersede my windows defrag however upon trying to commence a defrag I was met with the following message:

    "Access violaton at address 004D1B8A
    in module "IObit Smart Defrag.exe".

    Read of address 00000044."

    Not being able to defrag with IObit, I thought i would check the windows defrag function but received the following message:

    "Disk Defragmenter could not start"

    Consequently as part of the basic maintenance, I have NOT defragged pending your feedback in relation to this matter.


    During the spybot sd scan I did make the mistake of scanning more than once due to some items being unable to be cleaned etc and the software asked if it could after a reboot and i "politely" said yes. So it ran again but did not still clean everything that was detected.

    It was then that i reread the instructions and saw where it said about only running the scans once ...ooops my bad (sorry)

    The most problematic thing was the combofix and i am unhappy to report that I was unable to perform the scan thus there is no "log" to upload.

    Something I noticed from the instructions was the difference between what you had written to be copied and pasted into the run box and what was shown in your picture of how it should look if all was done correctly, see below"

    Copy & paste this: "%userprofile%\desktop\combo-fix.exe" /killall

    Image of how it should look: "%userprofile%\desktop\cf.exe" /killall

    Difference being, combo-fix.exe is cf.exe in the image. I am nowhere pc savvy enough to know what difference it would make but all i know is that i kept getting the following message:

    Windows cannot find 'C:\Documents and Settings\Owner\desktop\combo-fix.exe'.
    Make sure you typed the name correctly, and then try again. To search for a file, click the start button and then click search.

    I came back to the forums and conducted a search under combofix and found the following thread which seems to be the same as what I was/am experiencing

    http://forums.majorgeeks.com/showthread.php?t=164464&highlight=combofix

    In that thread it was determined that the person had not in fact saved Combofix to the desktop and that it was in C:\ drive. I checked my C:\ drive and it wasnt there. I deleted CF and saved it again to the desktop, checked the properties and it said it was in location: c:\Documents and Settings\Owner\Desktop. I also once again checked the C:\ drive and could not see it.

    I renamed the file to combo-fix.exe and went throught the copy & paste procedure as before with the same result.

    I am not sure what is the problem although i am certain that I may be a major goof as opposed to a major geek lol.

    I look forward to your further assistance in this matter re my malware, at your convenience.

    Thank you for your time and effort

    Regards

    bodybag
     

    Attached Files:

  5. bodybag219

    bodybag219 Private E-2

    Re: Read & Run Me completed (nearly)

    Couldnt find an edit button.

    Have just tried the IObit defrag and its working fine :)

    Just thought i should tell you in case you spend time pondering what could be the problem
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Read & Run Me completed (nearly)

    Thanks for the observation. This is now fixed. We recently changed the step to use combo-fix.exe and the image was not updated.

    This is occurring because you renamed the file incorrectly. The below is what you have on your Desktop:
    Code:
    "C:\Documents and Settings\Owner\Desktop\"
    combo-~1.exe  Jul 21 2008     2655750  "combo-fix.exe.exe"
    You have two .exe extentions and you should have one. This probably occurred at the time because you had not set the options for viewing hidden files and file extensions as requested. Running MGtools automatically changed the options properly now. So now you need to renamed combo-fix.exe.exe to combo-fix.exe and then you should be able to run it and attach a log. I want to get this log before continuing since it may fix some additional issues related to a WareOut infection that I see in your logs.

    When you attach the ComboFix log, also tell me what malware problems you are still having (if any).
     
  7. bodybag219

    bodybag219 Private E-2

    Re: Read & Run Me completed (nearly)

    Hi Chaslang

    Thank you for your reply and further instructions.

    Obviously looking at the copy of the code you pasted here seems to show the combofix problem. Although i must say that I did make the changes re: hidden files. However, perhaps i did something wrong although the procedure seemed fairly straight forward.

    Anyway, all is good and i will redo the steps and get the combofix log to you with any additional info re: continuing problems.

    Your help is very much appreciated, thankyou.

    Regards bodybag
     
  8. bodybag219

    bodybag219 Private E-2

    Hi once again Chaslang

    ComboFix:

    When i went to uncheck the hidden files via explorer, they were still showing as "unchecked". I rechecked them, then unchecked again > hit apply and went through the renaming of the CF file.

    The scan commenced and ran through without any dramas. Pleased find attached the CF log.

    I did notice at the top of the log that it made mention of my Recovery Console not being installed. Is this a problem that needs to fixed?

    PC's current state:

    From the outside everything seems to be running as normal ie
    No more pop up messages pertaining to virus's running rampant throughout my system.
    Internet Explorer appears to be stable and maintaining the selected home page.
    Desktop items which dissappeared have since returned after the completeion of the CF scan.

    I have changed my firewall from zonealarm to Online Armor due to seeing where ZA appeared on your list of leak tested firewalls.

    I have also swapped my free AVG to the Avast AV software due to its position on your recommended list and also because of the comments made about AVG making false detections.

    I have run a thorough scan using Avast and there were some items still detected and have attached the results log of that search for your perusal and comments, if you dont mind.

    It would seem that we are getting closer to the end of this little malware adventure and I do have some post removal question for you.

    1) In relation to the hidden files, should i go back and make them hidden again by rechecking those two boxes in Explorer?

    2) During the procedure of downloading anti malware tools, it was mentioned about not D/Ling to a temp folder. When i normally D/L stuff i generally just let the system decide where it puts them ie Temp Folder. Should I be saving them somewhere else and if so, where? C:\ Program Files?

    Thank you

    bodybag
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but the reason you initially had a problem and named Combo-Fix with two extensions was because you had not set the below option that is given in that same list:
    • Uncheck the Hide extensions for known file types option.
    When you ran MGtools, it set it for you automatically which is why it is now correct.


    This is normal. Windows does not install the Recovery Console by default. ComboFix points this out because you can run a procedure to install it with ComboFix. Having the Recovery Console installed can sometimes be a life saver if a PC becomes unbootable due to malware problems.


    For future reference, you should not change anything during malware removal procedures unless a helper requests it. Basically during the period of removal you should not do anything at all on your own. Only what is requested. ;) Including running Avast at a point where we were not finished. All it pointed out were things in System Restore which would all be removed once we do are final steps.

    Again final instructions will do this automatically. But you may want to consider always having everything unhidden. Remember that you allow malware to hide too when you have those settings put back to default. ;)

    NO! You should never download and save to C:\Program Files. That is where installed programs go when you run the installers. And no you should not save things to a Temp folder where they can easily be deleted and where you will have many things saved causing you to wonder what they are at some point in time. Make a folder like
    C:\Downloads and with in this folder create subfolders representing categories like AntiVirus, AntiSpyware, Firewalls, Disk Cleaners, ....etc and within each of those subfolders create addition folders for exactly what you are downloading. For example under C:\Downloads\AntiVirus you could have folders like
    • AVG AntiVirus Free Edition 8.0.135
    • AVG Anti-Virus Update July 22, 2008
    • Avast! Home Edition 4.8.1227
    • avast! Virus Definitions July 21, 2008
    That is just a small example that should demonstrate what I mean. This way you will always know exactly what you have saved where because the folder name along with the file name will tell you. Even months later, you will still be able to tell. A few months from now would you remember what mbam-setup.exe is when you see it in your Temp folder? Would you remember it is Malwarebytes Anti-Malware? Would you remember what version it is? Well if you use my method of saving files you would. ;)

    Now let's finish cleaning your PC.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {5da507d1-1024-bcba-f894-ddf929f2519e} - {e9152f92-9fdd-498f-abcb-42011d705ad5} - (no file)
    O8 - Extra context menu item: &Search - ?p=ZKxdm021YYAU
    O17 - HKLM\System\CCS\Services\Tcpip\..\{73C2C4EC-4920-48E1-B2E1-BA0135F86488}: NameServer = 85.255.114.45,85.255.112.112
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DFF77980-ACE0-4445-94B7-F93BFDC38E94}: NameServer = 85.255.114.45,85.255.112.112
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.45 85.255.112.112
    O17 - HKLM\System\CS1\Services\Tcpip\..\{73C2C4EC-4920-48E1-B2E1-BA0135F86488}: NameServer = 85.255.114.45,85.255.112.112
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.45 85.255.112.112

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. bodybag219

    bodybag219 Private E-2

    Hi Chaslang

    Seem to have a problem with what you listed below to be selected in hijackthis and what actually is appearing.

    Consequently I have not gone ahead and done any fixes as only one item correlated between the two lists.

    I did see a save log button so with great trepidation i clicked that and saved the log showing what i have. (Which was quicker than what i had started doing > typing it out)

    The log is attached.

    Thank you for answering my other questions and the info about where and how best to save downloaded items was excellent and very useful (I will spread the word about that to my friends and family).

    I await your response

    Regards bodybag
     

    Attached Files:

    Last edited: Jul 23, 2008
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since ComboFix was really run out of normal order, it removed things that showed in your previous MGlogs.zip file which includes the HijackThis items. Thus those items in my fix no longer exist. Just ignore that part and continue.
     
  12. bodybag219

    bodybag219 Private E-2

    Hi chaslang

    In accordance with your last reply, I have ignored that section of your last set of instructions and proceeded with ComboFix.

    The combofix part went smoothly and the expected log was produced (attached)

    The fixme.reg also went well and I received a "fixme.reg has been successfully entered into the registry" message. :)

    CCleaner was run and all seemed fine.
    *In one of the ealier sections pertaining to CCleaner after the initial run, it mentioned using the registry section. I was unsure if i was intended to do this part as well, so erring on the side of caution I did NOT use the registry part of the cleaner.

    The MGtools bat file process went smoothly and a log was produced (attached)

    Since completing the above steps, I have NOT run any sort of anti virus/spyware/malware scan. So as far as that aspect of how my pc is going now, I am uncertain.

    Internet Explorer appears to be working fine with my homepage choice still loading as required. I did notice that upon completion of the above steps that i now have a second IE shortcut on my desktop.

    All shortcuts that i had pre malware attack are on my desktop and i am not receiving any odd error messages or virus warnings popping up on my desktop or from my task bar.

    So from my not all seeing eyes, things seem good.

    Thank you for your time chaslang and i shall await further instructions or an all clear from you before i proceed with an anti "everything" scan :)

    Kind regards

    bodybag
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is what we requested. The below is a quote from the READ & RUN ME
    Your logs are clean but what is in the below new folder?
    Code:
    2008-07-23 09:48 . 2008-07-23 09:50 <DIR> d-------- C:\WINDOWS\NV36761604.TMP
    

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  14. bodybag219

    bodybag219 Private E-2

    Hi chaslang

    1)In relation to CCleaner, I was referring to the section "Basic comptuer maintenance everyone should do" which was the first reference to CCleaner in the Malware removal guide. My mistake for not being clear enough in my query to you.

    2) 2008-07-23 09:48 . 2008-07-23 09:50 <DIR> d-------- C:\WINDOWS\NV36761604.TMP

    When I checked, they are "Compiled HTML help files" relating to the nvidia control panel which I recently had open.

    3) Have followed and removed software as mentioned in your instructions.

    4) When i did the restore point it said that it would need to reboot but it did not do it automatically as expected and i had to manually reboot the PC.

    The same thing occurred after I downloaded the aSquared software. Said it had to reboot and then didnt > I had to manually reboot again.

    Another "strange to me" thing I noticed yesterday and again today, is that Online Armor is telling me in a red box that a suspicious program wants to run and its indicating its within the Avast4 program. I have a screen shot of the box that i will attach. It makes mention of how "some dangerous programs replace trusted programs by themselves to trick you into running them".

    I have not been running the AV software nor is it open (not in task bar) while i have been getting these warning messages.

    5) How to protect yourself malware:

    This is what i now have installed on my PC

    Antivirus: Avast Home Edition
    Anti ?: a - squared (Out of curiosity, what type of "anti" software is this?)
    Firewall: Online Armor

    Realtime blocker: Spyware Terminator
    After the fact scanner: Spybot - search & destroy
    Non realtime protection: Spyware Blaster

    Have set up folders for saving downloaded software as per your suggestion.

    6) Active X: Some items that you mentioned did not appear in my Active X list >

    Installation of desktop items
    Launching programs and files in an IFRAME
    Navigate sub-frames across different domains
    Allow paste operations via script

    The first 3 items in your list were.

    Thank you chaslang for ALL of your time spent helping me with my malware problems. Your help and advice has been very much appreciated and i admire your dedication to your speciality area. Clicking on the "Thank you" button seems so inadequate compared to all that you have done, but i will gladly do that.

    Cheers and warm regards

    bodybag
     

    Attached Files:

    Last edited: Jul 24, 2008
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but as stated in the READ & RUN ME. That procedure is not really part of the READ & RUN ME nor is it required for malware removal.

    This is just part of Avast Antivirus.

    The best way to describe it is in the description on the download page:
    You're welcome. Surf safely!
     
  16. bodybag219

    bodybag219 Private E-2

    Hi chaslang and thank you for your replies.

    I woke up this morning and turned my pc on and when I came back to it all that was showing was a naked desktop.

    No icons, no task bar, absolutely nothing!!

    I had the thought that i might be able to get something happening by running in safe mode and when i restarted and pressed F8 I was not given a listed option for safe mode all that appeared on my screen was:

    BOOT
    Select a Boot first device
    Removable
    - Floppy Disk
    Hard Disk
    - SATA3 :ST 3250410AS
    CDROM
    - 1st Master Pioneer DVD-RW DVR-112

    I am not sure if this is still relating to any sort of malware problem or not. Maybe its software or hardware.

    Any suggestions as to where I go from here or what i should do would be greatly appreciated. Thank you.

    Regards bodybag
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not malware. You have basically been clean since running ComboFix in message # 8. Everything after that was just followup incase something was missed by ComboFix and removal of some unnecessary registry keys that ComboFix adds to the registry when it is run.

    You may need to post in the Software Forum but answer a question first. When you attempt to boot normally, do you get to the Welcome screen where you login (assuming you had you PC set to start that way to begin with)? Basically I want to know how far the boot process goes.
     
  18. bodybag219

    bodybag219 Private E-2

    Hi chaslang

    In answer to your question about the Welcome screen:

    In normal mode I get to the welcome screen and then after about 20 secs it goes to my desktop minus any icons, task bar or start button.

    In safe mode I get to the windows click username page > Administrator and Owner.

    When i click on Owner I end up with all of my original desk icons and positions, task bar and start button.

    When i click on Administrator I only get about 70 - 80% of my desktop icons and the positions have changed.

    I note what you have stated about my malware problem being clean however, when carrying out scans i am still detecting malware.

    Also with Avast, when it does its memory scan and picks up a rootkit type malware, I can put it in the chest only delete it.

    I have attached some reports for you.

    I did think that i would have been able to use the new restore point that i last created as per your instructions but that was unsuccessful. I also noted that spybot had created its own restore point as well. I must admit i am currently somewhat uncertain about spybot as Avast is unable to perform a full scan due to a lot of files being password protected by spybot.

    I did read a post in this malware section where you helped a guy who had a similar problem with his desktop and it turned out to be something to do with a non MS product (gozilla?) located in the service section of msconfig.

    I will go post something in the software/hardware section. I did find a thread in my search earlier today in the HW section pertaining to my problem but there was no real answer/conclusion to the thread or problem.

    If you do have any other suggestions etc in relation to what may be happening i would love to hear them.

    Thanks once again for all that you have done for me.

    Kind regards

    bodybag
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The detection by a-squared is false. That is a Microsoft file. It is GDIEXT Client DLL. In this particular case it is a version of the file used by Windows Live Messenger.

    I also suspect that the Avast detections are false detections. Do you still have any of those tmp files in the folder indicated?

    Are you actually having any real malware problems? System Restore failing to succeed is typically a problem within the Windows operating system itself. Also the error file from Avast is not a malware problem. It may be a problem with your installation. Where did you download Avast from. What is the full name of the installation file?


    This will not stop Avast from scanning all of your files. It only stops Avast from looking at these files protected by Spybot to block malware from corrupting them. The same thing is true for many Windows files which are protected and cannot be scanned.

    I don't know what you are referring to. You will have to be more specific and give a thread ID and make sure you are referring to proper names of programs. Did you mean Stopzilla?

    What problems are you referring to? Are you referring to the fact that Windows had no Desktop as mentioned in msg #16? I thought you had this fixed now.
     
  20. bodybag219

    bodybag219 Private E-2

    Hi Chaslang

    Thanks for your reply

    Im pleased to hear about the detections being false.

    "Do you still have any of those tmp files in the folder indicated?"
    I believe I do > c:\windows\temp\mc21.tmp, mc22.tmp, mc23.tmp, mc25.tmp, mc26.tmp & mc27.tmp. mc24.tmp is missing but I imagine thats because its been deleted.

    As far as i can tell in relation to what was happening in the beginning, I am not currently having any malware problems.

    You mention that the system restore may be a problem with the windows operating system, so I will ask about that in the Software section.

    With regard to Avast i cannot be 100% certain that it was downloaded from MG or not. I was having probs with some of the MG download pages opening and I may have googled the software and downloaded from elsewhere eg the Avast site. I will delete Avast later sometime and download from MG to be sure.

    "This will not stop Avast from scanning all of your files. It only stops Avast from looking at these files protected by Spybot to block malware from corrupting them. The same thing is true for many Windows files which are protected and cannot be scanned."

    Thats reassuring! (Im quite enjoying this learning curve)

    Yes I did mean Stopzilla, I tried to find the thread again but couldnt. I was just trying to find similar accounts of my situation when i was initially researching the problem.

    "What problems are you referring to? Are you referring to the fact that Windows had no Desktop as mentioned in msg #16? I thought you had this fixed now."

    I am referring to the no desktop icons, no taskbar and no start button problem. No it has not been fixed. I have posted in the hardware section http://forums.majorgeeks.com/showthread.php?t=165399 and has been viewed 50 times but it doesnt seem as though anyone knows how to fix it.
    Does not bumping threads only apply to the malware section? lol

    I have found a solution to my F8 > boot menu prob and now know how to access the Windows Advanced Options menu which is great. I did make reference to my other problem, a sly bump perhaps? lol

    http://forums.majorgeeks.com/showthread.php?t=165458

    Regards bodybag
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Put a couple of these into a ZIP file and attach the ZIP file here. Then see if you can delete all of the files yourself.

    It is not a hardware problem. It is a software problem which means the Software Forum would have been more appropriate. This kind of problem often happens when explorer.exe (the Windows shell) is not getting properly loaded at started. This can happen for many reasons. Some malware and some not malware. Attach a new log from MGtools so I can check a few things out. Try to run it in normal boot mode from Task Manager.

    The procedures we mentioned only apply to the Malware Forum. If a thread is unanswered in other forums, you could try a polite bump after a couple days, but if you still don't get an answer it means no one that has read your post has one for you.

    I have found a solution to my F8 > boot menu prob and now know how to access the Windows Advanced Options menu which is great. I did make reference to my other problem, a sly bump perhaps? lol
     
  22. bodybag219

    bodybag219 Private E-2

    Hi chaslang

    Thanks once again for your reply and answers/comments etc.

    I have put a couple of the mc files into a zip (hope its right as i have never done a zip file before:eek: )
    Yes i was able to delete the remaining mc files and after a reboot they had not returned.

    In relation to the placement of my thread in the hardware section, would the best action be contacting a moderator and asking them to move the thread to the software section or just copy and paste it into the software section myself?

    I was able to run MGtools in normal mode by using the task manager as instructed. Log attached

    In relation to bumping, I will remember that for the future. I had planned to pm someone if i hadnt had a reply on it soon to see what to do.

    Thanks again

    Regards bodybag

    ADDIT: It would seem i have stuffed up the mc file zip. Will keep trying to get it added
     

    Attached Files:

    Last edited: Jul 28, 2008
  23. bodybag219

    bodybag219 Private E-2

    mc zip files as requested

    Hi chaslang

    here are the zip files for you of the mc.tmp files. I couldnt get back in time before the edit time ran out. I did learn how to create a zip file from my peazip software though :)

    Cheers bodybag
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: mc zip files as requested

    I ran these files thru over 30 scanners (one of which is also Avast) and there are no problems other than1 of them mentioning Tool.Madtol.c (Not a Virus) and another mentioning MadCodeHook which is the same as Madtol.c and is not a virus. My guess is that these files are due to some copy protection (maybe gameguard) which is probably employed by the games you have installed.

    There is still no malware in your logs. And explorer.exe is showing as running in your procdll.txt log inside of the MGlogs.zip file. Therefore it is not a problem that explorer is not being loaded. I'm not sure what is causing this problem and why it is only occurring in normal boot mode. This would imply that something that runs in normal boot mode but not in safe boot mode could be the problem. I suggest that you one by one uninstall each of the below in the order given (with a reboot in between) to see if any of them (or any combination of them) are possibly causing the problem.
    • Online Armor 2.1
    • avast! Antivirus
    • Spyware Terminator
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I can move it for you when we finish with steps being tried here.
     
  26. bodybag219

    bodybag219 Private E-2

    :celebrate

    Hi chaslang

    I guess you know there is good news coming!!

    I deleted online armor 2 and rebooted after changing to normal mode and it loaded as it should with all icons etc.

    The System Configuration Utility msg box came up saying there had been changes and to select Normal mode and adjust any other changes made.

    So I did that and then when it asked to reboot I did and it started back in safe mode!? So i kept doing what the msg box asked and the same thing kept happening. In the end I thought that I would delete Avast as well, which i did.

    I then went through the above procedure again and once again i had the pc starting in safe mode. I ended up checking the box on that msg box to not appear again and since then once in normal mode it has stayed that way.

    At that point I decided that I should run another MGtools scan to attach with this just in case there is something in the log that may be of use to you in perhaps determining why Online Armor and possibly Avast caused this desktop problem. If there is any other information that you would like me to glean from the pc then you only have to ask.

    Currently I have installed Malwarebytes, Spyware Terminator, SpywareBlaster, A squared & CCleaner.

    My PC is not currently connected to the internet. I will use the windows firewall for the time being while I have another look at the firewalls on offer here, along with a different AntiVirus.

    I have thanked you before but I must say it again, "Thank you chaslang", I really do appreciate your help and patience. Here's to you :wine

    Kind regards

    bodybag
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to see a new MGlogs.zip file so I can check to make sure all of Avast and Online Armor were properly removed. The log will not tell me why you had the problems you had. All I can do is guess that there was a problem with the installations or there was some other kind of software conflict.
     
  28. bodybag219

    bodybag219 Private E-2

    Hi chaslang

    Please find attached the requested log.

    Also, I have installed via MajorGeeks (Prior to this scan):

    Comodo Firewall

    PC Tools AntiVirus (Its initial scan came up clean)

    Regards

    bodybag
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are fine now. Just delete the below left over folders:

    C:\Documents and Settings\All Users\Application Data\Avg8
    C:\Program Files\Alwil Software
    C:\Program Files\AVG
    C:\$AVG8.VAULT$

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  30. bodybag219

    bodybag219 Private E-2

    Hi chaslang

    Thats great news, thank you. :highfive

    I have deleted the folders as instructed.

    I am going to update my post in the hardware section with the outcome of your "problem fix". Would you be able to move it into the software section seeing as thats where it should be, please.

    Kind regards


    bodybag
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!

    It has been moved.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds