problem removing trojan. MGtools log attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aleks9000, Jun 23, 2012.

  1. aleks9000

    aleks9000 Private E-2

    hello MG!

    i have major problems with several computers at home, i have detected virtual disks, several modules loaded in kernel etc

    i have attached a mgtools log in hope that i can get some help.

    if you see i dont have SP! installed. its because the trojan just messes up my computer even more with updates.

    nothing really works, shredding of HDD, any tools ive tried doesnt work.

    please have a look at the logs and help a brother out :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to run all of our cleaning procedure. MGtools is only one small piece and it is the last thing to run.

    Please follow the instructions in the below link, including running MGtools again at the end where requested:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. aleks9000

    aleks9000 Private E-2

    ok, i have followed your instructions to perfection.

    the new logs are from a fresh win 7 64 bit installation. (on my desktop computer this time) no SP packs (i have experienced it just getting worse if do win updates.)

    logs attached.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the logs you have attached, you don't have any malware to remove. Your problems may stem from the fact that you have some how managed to break/stop a bunch of Windows services from running. I can see the below in one of the logs from MGtools.
    Code:
    Checking DHCP, AFD, NetBT, tdx, TCP/IP, NSI and nsiproxy Service States 
       Dynamic Host Control Protocol -DHCP-     is NOT running  
            C:\Windows\System32\dhcpcsvc.dll exists  
       AFD Networking Support Environment -AFD- is NOT running  
            C:\Windows\System32\drivers\afd.sys exists  
       NetBios over Tcpip -NetBT-               is NOT running  
            C:\Windows\System32\drivers\netbt.sys exists  
       NetIO Legacy TDI support driver  -tdx-   is NOT running  
            C:\Windows\system32\drivers\tdx.sys exists  
       TCP/IP Protocol Driver -TCP/IP-          is NOT running  
            C:\Windows\system32\drivers\tcpip.sys exists  
       Network Store Interface Service -nsi-    is NOT running  
            C:\Windows\system32\nsisvc.dll exists  
       NSI Proxy Service  -nsiproxy-            is NOT running  
            C:\Windows\system32\drivers\nsiproxy.sys exists  
    =====================================================================================  
    Checking Base Filtering Engine Service State and Dependencies 
       Base Filtering Service               is NOT running  
            C:\Windows\system32\bfe.dll exists  
       Remote Procedure Call {RPC} is NOT running  
       DCOM Server Process Launcher Service is NOT running  
    =====================================================================================  
    Checking Windows Firewall Service -MpsSvc- State 
    .
       Windows Firewall Service is NOT running  
            C:\Windows\system32\FirewallAPI.dll exists  
    =====================================================================================  
    Checking Windows Firewall Authorization Driver Service -mpsdrv- State 
    .
       Windows Firewall Authorization Driver Service is NOT running  
            C:\Windows\system32drivers\mpsdrv.sys exists  
    
    However there are conflicting reports because in your first MGlogs.zip file these were all okay. Now they are broken which would seem to mean this new install you performed did not work too well. You may want to work your problems with Windows in the Software Forum. But you can give the below a quick try to see if it helps.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds