Ummmm Help?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Shell31, Sep 29, 2008.

  1. Shell31

    Shell31 Private E-2

    Hi There,

    Please forgive my lack of expertise in advance. I'm hoping somebody out there can help me with my computer which is soon to end up in the bin.

    If this type of question has been asked elsewhere on the forum I'm sorry. I've searched for help with this problem for the last 2 days non stop with no luck & i'm kinda over it.. I thought I'd just ask for help..

    So a couple of days ago my computer just started rebooting for no reason. There is no particular times that it does it.. Sometimes it will stay on & running for up to 2hrs.. sometimes only 15mins.. Sometimes with an error message sometimes without.. The message I seem to be getting is the NT AUTHORITY/System message something about the Remote Procedure Server terminated unexpectedly. It then gives me 60 seconds to save my work & get out then it reboots.

    I've looked for weird process's running in the task manager but I'll admit right here that I'm blonde & umm well Im no expert. I've read to look for MSblast or something of that name but there is nothing in there of that name. I've run Reg Mechanic, Adaware & spybot all of which find problems. & remove them but the problem still remains..

    I'm not sure what information anyone may need to be of assistance but please let me know & I'll post back as best I can with any info you request from me..

    Thanks again..
     
  2. Lev

    Lev MajorGeek

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. Shell31

    Shell31 Private E-2

    Hi there,

    Took me awhile to work through the process as suggested but here goes.. Fingers crossed.
    The computer didnt shutdown & reboot once whilst going through the process & all scans ran without any problems so I'm hoping the problem is fixed but who knows. Thought I would upload these anyway incase anyone has anything else to offer.

    Thank you
    Rachelle
     

    Attached Files:

  4. Shell31

    Shell31 Private E-2

    And here is the 4th log file.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We have some more to do.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 16
    J2SE Runtime Environment 5.0 Update 7
    Symantec Network Drivers Update

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKUS\S-1-5-21-3713499041-3996320157-487975717-500\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User 'Administrator')

    After clicking Fix, exit HJT.



    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Oct 5, 2008
  6. Shell31

    Shell31 Private E-2

    Hi Again,

    Thanks for your reply. I've had a go tonight with your instructions.. I swear it amazes me to think you understand all this stuff lol...

    Disabled the windows messenger, no problems.

    Removed the 2 x J2Se runtime entries no problems.

    I was unable to find the Symantec Network Drivers Update in add remove programs???

    ComboFix wouldnt run. Kept telling me the CFscript was spelt incorrectly or something of that nature..

    When running C:\MGtools\analyse.exe I was unable to select the below entry as it just wasnt there.. There were other HKUS entries but they were not the same so I left them be & kept on with the steps. Hope this is ok.

    O4 - HKUS\S-1-5-21-3713499041-3996320157-487975717-500\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User 'Administrator')


    I did get a message when adding that notepad file to the registry. The message I received said it could not import the file as the specified file is not a registry script. You can only import binary reg files from within the registry editor.

    So I've attached the one file for MGtools but as ComboFix wouldnt run I obviously cant attach that file.

    Not sure if Ive done it all correctly but your instructions are great. Thanks heaps for your help with this.

    Cheers Rachelle
     

    Attached Files:

    Last edited: Oct 5, 2008
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I will add it to the previous fixME.reg patch that you need to create again.

    Are you sure you are saving the file properly as CFScript.txt using notepad? Did you save it to your Desktop??? I do not see it in the log you attached.

    This means you did not create the file properly. The REGEDIT4 line must be the first line in the file. Nothing can be above it, not even a blank like. Create it again since I just added the Symantec stuff to it.

    This is not the log I asked for.
     
  8. Shell31

    Shell31 Private E-2

    Wow.. Didnt do very well did I.. Sorry for mucking you around. I'm trying. I'll have another go this morning from scratch & if what I do still isnt what your after I won't waste your time again.

    Fingers crossed.

    Ta Rachelle
     
  9. Shell31

    Shell31 Private E-2

    Ok see how I go this time..


    Oh goody.. one of the files exceeds the limit size & I can't upload it. :eek:

    Ta
    Rachelle
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay. I can see what I need in the MGlogs.zip contents and everything looks fine now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. Shell31

    Shell31 Private E-2

    Thank you so very much for all your help. Can't thank you enough. I'll run through the next steps & read up on protecting the pc from Malware.
    Thank you again

    Cheers
    Rachelle
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds