MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.

Reply
 
Thread Tools Display Modes
  #21  
Old 10-19-09, 17:32
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Attached, thanks.

Things seem to be running okay. Desktop picture dissapeared, went to customize and cannot.

These are little things, but just sharing what I am seeing.
Attached Files
File Type: zip MGlogs.zip (80.2 KB, 0 views)
Reply With Quote
  #22  
Old 10-19-09, 22:50
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Not sure why your last post did not show up, but here are the logs. the fixme.reg did not work. I am getting message again that registry editing is not allowed.

Here are the logs.
Attached Files
File Type: zip MGlogs.zip (80.1 KB, 2 views)
File Type: txt avenger.txt (4.8 KB, 2 views)
File Type: txt Win32kDiag.txt (281 Bytes, 2 views)
Reply With Quote
  #23  
Old 10-22-09, 14:57
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Please download and install on your desktop combofix.exe

Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

* Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
If it is not on your Desktop, the below will not work.
* Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
* If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
* Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
Code:
KILLALL::

File::
C:\WINDOWS\system32\sdra64.exe
C:\WINDOWS\wp3.dat
C:\WINDOWS\wp4.dat      
C:\WINDOWS\system32\wwp.htm
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\3639913142.exe
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\dio5.tmp      
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\dio6.tmp   
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\dio8.tmp    
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\dio9.tmp      
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\dioa.tmp    
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\diob.tmp    
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\jisfije9fjoiee.tmp
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mar4.tmp    
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mar8.tmp     
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon000~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon001~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon002~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon003~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon004~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon005~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon006~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\mon007~1.log 
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\nvsvc32.exe  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\setup.exe     
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\setupa~1.log  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\system.exe  
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\WPDNSE
C:\Documents and Settings\All Users\Application Data\53841930
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
C:\DOCUMENTS AND SETTINGS\Jason and Pat\LOCAL Settings\Temp\nvsvc32.exe
Folder::
C:\Documents and Settings\Jason and Pat\Local Settings\Temp\WPDNSE
C:\Documents and Settings\All Users\Application Data\53841930
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Yjafosi8kdf98winmdkmnkmfnwe"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wopojehow"=-
* Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
* You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
If it asks you to overide the prvevious file with the same name, click YES.
* Now use your mouse to drag CFscript.txt on top of ComboFix.exe

* Follow the prompts.
* When it finishes, a log will be produced named c:\combofix.txt
* I will ask for this log below

Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:

* C:\ComboFix.txt
* C:\MGlogs.zip
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #24  
Old 10-23-09, 23:37
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Thank you.

Here are the logs:
Attached Files
File Type: txt ComboFix.txt (19.7 KB, 2 views)
File Type: zip MGlogs.zip (101.8 KB, 1 views)
Reply With Quote
  #25  
Old 10-26-09, 11:06
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Juntion.exe is not in the C:\Windows folder and Inherit.exe is nowhere to be found on your desktop.

Please correct that now.

* Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
If it is not on your Desktop, the below will not work.
* Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
* If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
* Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
Code:
KILLALL::

Driver::
WDefend

File::
C:\WINDOWS\Ewahine.dat
C:\WINDOWS\Hlupuqiyaloqe.bin
c:\windows\uwafigor.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ynonajazeti"=-
* Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
* You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
If it asks you to overide the prvevious file with the same name, click YES.
* Now use your mouse to drag CFscript.txt on top of ComboFix.exe

* Follow the prompts.
* When it finishes, a log will be produced named c:\combofix.txt
* I will ask for this log below

Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.

Now if you have put juntion.exe in the C:\Windows folder and Inherit.exe is on you desktop, then double click the C:\MGTools\FixPerm.bat

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:

* C:\ComboFix.txt
* C:\MGlogs.zip

Make sure you tell me how things are working now!
__________________
Its not what you use its how you use it that matters!
Reply With Quote
Sponsored links
  #26  
Old 10-30-09, 16:15
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Sorry, IE is down again, working now, not sure for how long.
Attached Files
File Type: txt ComboFix.txt (13.8 KB, 1 views)
File Type: zip MGlogs.zip (101.6 KB, 2 views)
Reply With Quote
  #27  
Old 10-30-09, 16:24
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Use windows explorer to find and delete:
c:\windows\ulilobomagif.dll


Now double click on C:\MGTools\analyse.exe and telll me what happens.

Are you having difficulty putting junction.exe in the C:\Windows folder???
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #28  
Old 10-30-09, 16:44
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Deleted the file.

When I try to run analyse.exe, I get a message that windows cannot find the specified file, path or device.

Junction was there right before I ran Combofix, and it is in the directory now.
Reply With Quote
  #29  
Old 10-30-09, 16:50
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

It was not there in your latest MGLogs.zip. So now if everything is where it should be, run the C:\MGTools\Fixperm.bat.

Tell me what problems you still have and also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:

* C:\MGlogs.zip
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #30  
Old 10-30-09, 16:53
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Edit: Please drag the analyse.exe on top of inherit.exe. THEN run the getlogs.bat!
__________________
Its not what you use its how you use it that matters!
Reply With Quote
Sponsored links
  #31  
Old 11-04-09, 19:18
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Here are the logs
Attached Files
File Type: zip MGlogs.zip (101.6 KB, 1 views)
Reply With Quote
  #32  
Old 11-08-09, 12:19
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Please use windows explorer to find and delete:
C:\Program Files\AVG
C:\Documents and Settings\All Users\Application Data\AVG8
C:\Documents and Settings\Jason and Pat\Application Data\AVG8

If you are having difficulties doing that, you can use the AVG Removal Tool.

Again you log indicates that junction.exe is not here: C:\Window\junction.exe.

What issues are you still having?
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #33  
Old 11-08-09, 14:49
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Thanks, deleted those files.

Can't explain the junction.exe issue. I look in the Windows directory and it is there.

Everytime I open a window in IE, my task manager opens and I see a second or third IE open under processes, even if I only have one open.

Norton keeps finding viruses. Itunes will not download.
Reply With Quote
  #34  
Old 11-08-09, 15:19
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Tell me what Norton is finding. The exact path.
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #35  
Old 11-08-09, 19:54
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

C:Windows\mgctrd.dll
Reply With Quote
Sponsored links
  #36  
Old 11-10-09, 16:07
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Are you unable to delete it?

If not, then:
Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

* Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
If it is not on your Desktop, the below will not work.
* Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
* If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
* Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
Code:
KILLALL::

File::
C:Windows\mgctrd.dll
* Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
* You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
If it asks you to overide the prvevious file with the same name, click YES.
* Now use your mouse to drag CFscript.txt on top of ComboFix.exe

* Follow the prompts.
* When it finishes, a log will be produced named c:\combofix.txt
* I will ask for this log below

Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:

* C:\ComboFix.txt
* C:\MGlogs.zip

Is it still reporting anything?
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #37  
Old 11-11-09, 06:57
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Here are the logs. Why when I open IE are there one or two other IE processes running? I had not seen that before this thing originally hit.
Attached Files
File Type: zip MGlogs.zip (102.2 KB, 2 views)
File Type: txt ComboFix.txt (12.3 KB, 2 views)
Reply With Quote
  #38  
Old 11-13-09, 13:06
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Please download the latest version of ComboFix. And I want you to make sure you have updated your Norton program.

Once you have downloaded Combo to your desktop, and have shut down your AV and AS programs:

* Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
Code:
KILLALL::

File::
c:\windows\mgctrd.dll
c:\windows\Hlupuqiyaloqe.bin
c:\windows\Ewahine.dat
c:\windows\owozizazi.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ynonajazeti"=-
* Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
* You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
If it asks you to overide the prvevious file with the same name, click YES.
* Now use your mouse to drag CFscript.txt on top of ComboFix.exe

* Follow the prompts.
* When it finishes, a log will be produced named c:\combofix.txt
* I will ask for this log below

Note:

Do not mouseclick combofix's window while it is running. That may cause it to stall.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below logs:

* C:\ComboFix.txt
* C:\MGlogs.zip
__________________
Its not what you use its how you use it that matters!
Reply With Quote
  #39  
Old 11-14-09, 09:40
Wendigo X Wendigo X is offline
Private E-2
 
Join Date: Aug 2009
Posts: 21   (View Stats)
Thanks: 0
Thanked 0 Times in 0 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

Here are the logs. The Combofix icon is no longer on the desktop, and it did not seem to run, or froze once it got to the creating log file point.

There does not seem to be a log for that, but here is the MG log.

Thank you multiple times over for continuing to help.
Attached Files
File Type: zip MGlogs.zip (102.9 KB, 2 views)
Reply With Quote
  #40  
Old 11-16-09, 14:15
TimW's Avatar
TimW TimW is offline
MajorGeeks Admin - Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 24,761   (View Stats)
Thanks: 14
Thanked 1,247 Times in 1,211 Posts
Not Ranked  0 score     
Default Re: Help please, Cannot run logs following FAQ

The files and the registry key are gone. The only remaining file is C:\WINDOWS\Hlupuqiyaloqe.bin which is empty. You may as well delete the C:\ComboFix folder. I am not seeing any other issues in those logs. Tell me what issues you are still having.
__________________
Its not what you use its how you use it that matters!
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows XP logs on then logs off Leetkezzer Software 1 03-14-09 15:03
My logs astriff Malware Removal 4 10-03-08 19:51
Hi can someone please look at my logs? babyturk Malware Removal 3 03-17-08 16:59
Windows logs in, logs out, flashing aTa Software 15 07-30-05 14:41
Xp Logs On And Immediately Logs Off RightGirl Software 5 04-04-05 11:29


All times are GMT -5. The time now is 18:16.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Ad Management by RedTyger