Vista 2012 Antivirus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sentient0ne, Dec 18, 2011.

  1. Sentient0ne

    Sentient0ne Private E-2

    I followed the malware removal guide as intructed. I'll attach the malwarebytes file, nothing for the superspyware as it didn't detect anything, the combofix log, error message for rootrepeal and the mglogs zip file.

    My computer appears to be working fine right now after running eveything. I have internet access, no more redirects or popups.

    I'll wait to hear back from you regarding the posted logs and files.

    Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    According to your ComboFix log, your cdrom.sys file was infected and deleted. Are you able to still load, run, play CDs and DVDs is your CD/DVD Drive?

    You had a Zero Access infection that was removed. I need to look thru the rest of your logs to make sure everything was removed. However also want you to run the below.



    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said SUPERAntiSpyware did not detect anything which is not true. You have two logs. Please attach them
    Code:
    "C:\Users\Terry G\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Dec 17 2011  31151  "SUPERAntiSpyware Scan Log - 12-17-2011 - 03-52-50.log"
    Dec 17 2011  22980  "SUPERAntiSpyware Scan Log - 12-17-2011 - 11-32-21.log"

    Also delete the below files. Let me know if you are able to find and delete these!

    C:\Users\Terry G\AppData\Local\8h80dj2c38n350
    C:\Users\Terry G\AppData\Local\8h80dj2c38n350
    C:\ProgramData\8h80dj2c38n350
     
  4. Sentient0ne

    Sentient0ne Private E-2

    Here are the additional logs you requested.

    I deleted the additional files as well.

    Thank you!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Those all look fine so you should be okay now. The only other things you need to do are:

    See step 3 of the READ & RUN ME and uninstall the two old Sun Java version you have and update to the current version.

    Also see step 4 of the READ & RUN ME and stop using MSconfig to control startups.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. Sentient0ne

    Sentient0ne Private E-2

    Also, the CD/DVD drive is not working. It doesn't recognize that there is a disk. It doesn't eject from the My Computer window either.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, you should have answered the question I posted about this right away. Do not complete final steps yet. If you do, you may delete a driver you need.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      cdrom.sys
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  8. Sentient0ne

    Sentient0ne Private E-2

    Attaching the system look file.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can copy the below file

    C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_6194d4eea0e93596\cdrom.sys

    into the c:\Windows\System32\drivers\ folder so that you have the below file

    c:\Windows\System32\drivers\cdrom.sys

    If you get it copied there then reboot your PC and see if your drive works properly.
     
  10. Sentient0ne

    Sentient0ne Private E-2

    It doesn't allow me to copy and paste. How do I go about getting that file copied and pasted?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will use ComboFix to try and copy the file. You may be having permissions issues.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    After the reboot, check to make sure it was copied and also see if your CD drive is working if the file was copied.
     
  12. Sentient0ne

    Sentient0ne Private E-2

    I ran as requested. Combofix restarted my computer when it was done. I had some extra files on my desktop that are greyed out. I'll attach those along with the combofix file. My DVD drive works now. But, I can't access Mozilla Firefox from the link on my quicklaunch toolbar. It starts to open but then freezes. I'm in IE right now. I still haven't done those extra fixes since the DVD drive issue. You asked me to hold off on those until the drive was fixed.
     

    Attached Files:

  13. Sentient0ne

    Sentient0ne Private E-2

    Looks like the 3 greyed out files didn't load. There are two desktop.ini files and one ehthumbs_vista.db.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know what you are talking about but if it is Desktop.ini files, they are normal.

    Right click on it and select Properties and make sure the Target path is correct. If not then fix it. Otherwise I suggest seeing if it opens properly from All Programs. If not then uninstall it, reboot and reinstall.

    You should finish my final instructions now.
     
  15. Sentient0ne

    Sentient0ne Private E-2

    Thank you for your assistance. It appears that everything is as it should be, except the Mozilla Firefox. But I'll just do a reinstall on that.

    Appreciate the time you took.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds