Read and run completed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ynot, Jun 4, 2008.

  1. ynot

    ynot Private First Class

    Hi,
    My pc was slow and having trouble playing a game online because of 'ping'.
    Also occasionally the screen would sort of vibrate most noticeably down the sides ( a bit like a wave running down with jagged edges).
    I've gone through the 'read and run malware guide'.
    sun java : I could not find anything like this in my add/remove list.
    SAS did not detect anything hence no log.
    I could not get combofix to run as it could not be found after i renamed it as per instruction.
    The pc seems to be running better but i'm not totally convinced so if one of you good people could take a look at the submitted logs i would be most grateful.
    Thankyou
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not name it cf.exe. You named it cf.exe.exe You probably did this because you had not followed earlier instructions on viewing hidden files and externsions. Please rename it to cf.exe and then see if you can run it.

    You also did not save MGtools.exe where we requested. You saved and ran it from here:
    C:\Documents and Settings\Tony and Micheal\My Documents\MGtools.exe

    However do note that your problems may not be due to malware. Your logs are basically clean. Your problems may just be related to what you are running. Or they could have been temporary internet issues. Did problems begin after your recent update to SP3?

    Uninstall SUPERAntispyware now since it did not find anything, we do not need it anymore.

    Did you knowingly aloow the below junk to be installed?
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe

    Are you still having problems? If yes, get rid of Kontiki and any other unnecessary software and toolbars and if that does not help, I suggest that you post in the Game Forum.
     
  3. ynot

    ynot Private First Class

    Hi
    combofix log attached.
    shall i run mgtools again in the correct place ?
    SP3 does not seem to have made a difference.
    I have uninstalled SAS.
    I think the kontiki thing came from a british TV station for viewing their programs online. It went wrong after a while so i uninstalled the main program. I could not work out how to uninstall the kontiki program , it does not show in the add/remove programs list.
    Thankyou for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No this is not necessary and you do not have any malware to work on.


    The below will remove this.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to KService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all

    After clicking Fix, exit HJT.

    Now reboot your PC.

    After reboot, delete the below folder:
    C:\Program Files\Kontiki
     
  5. ynot

    ynot Private First Class

    Chaslang i have completed the last lot of instructions.
    Thankyou very much for your help. Your a star ;)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds