![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
May have other issues have attached hijackthis log for suggestions
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.
For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive. For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Option1: Enter System Recovery Options from the Advanced Boot Options:
Option2: Enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options: Quote:
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#3
|
|||
|
|||
|
Tim
I appreciate your reply Farbar Recovery Scan Tool Log File Attached |
|
#4
|
|||
|
|||
|
Tim I also noticed that this laptop has not had a windows update since 4/13/12. When I went to the window update program, it would not update because:
Windows update cannot currently check for updates, because the the service is not running. You may need to restart your computer. Windows updates are set to install automatically. I cannot view update history. |
|
#5
|
||||
|
||||
|
Save fixlist.txt to your flash drive.
Now reboot back into the System Recovery Options as you did previously. Run FRST and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (See how to attach) Now boot into normal Windows can continue with the below. Running MGTools.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Tim:
I was able to complete the fix with Farbar Recovery Tool and attached the Fixlog.txt as requested. I installed MGTools.exe and ran the program successfully. I attached the MGlogs.zip as requested. |
|
#7
|
||||
|
||||
|
Logs did not attach.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#8
|
|||
|
|||
|
Apologies
Logs attached |
|
#9
|
||||
|
||||
|
Please run CCleaner and clean out your temp folders.
Tell me what issues you may still have, if any.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#10
|
|||
|
|||
|
Tim
I ran ccleaner, the laptop has been running much better, no more malware alerts Installing the full versions of malwarebytes and superantispyware I has helped alot. I appreciate your help. I attached a rkill.txt file after running rkill.exe today that indicates ZEROACCESS rootkit symptoms found! However when I checked the address in the registry the entry was not there. Please advise |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Extract bfe.reg to your desktop.
Double-click BFE.reg and allow it to merge into the registry. If you get a "successfully merged into registry" type of message, reboot your PC and see if you can turn on BFE, or if it is already turned on. You can run these commands from the command prompt.
Now re-run RogueKiller and attach the log.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
| The Following User Says Thank You to TimW For This Useful Post: | ||
safetydave (09-01-12) | ||
|
#12
|
|||
|
|||
|
Tim
Thank you for your reply I got a "successfully merged into registry" type of message, rebooted PC, but was not able to turn on BFE after running the following from the command prompt: net start bfe sc qc bfe I attached screen shots of two different errors messages I received while trying to start BFE. Safetydave |
|
#13
|
||||
|
||||
|
Delete the BFE.reg file that exists on your desktop. Download this one to the same location.
BFE.reg Now, boot into safe mode please to carry out the next set of instructions.
Back into normal mode now - Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
After reboot, check to see if your firewall is working. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter Last edited by Kestrel13!; 09-02-12 at 14:49.. |
|
#14
|
|||
|
|||
|
Tim
Thank you Ran regedit.exe as admin was able to import BFE.reg BFE never would start in safe or normal mode Windows repair went ok - mglogs.zip attached Ran rkill64 log attached - * ALERT: ZEROACCESS rootkit symptoms found! * HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 [ZA Reg Hijack] Safetydave |
|
#15
|
||||
|
||||
|
Your logs look good. All the services are now running. Use RogueKiller to remove that last item. Then tell me how things are running for you.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
| The Following User Says Thank You to TimW For This Useful Post: | ||
safetydave (09-03-12) | ||
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Thanks Tim
Not sure how to use Roguekiller to remove ZEROACCESS rootkit symptoms found! When I run Roguekiller it does not seem to remove it I deleted the item using regedit not sure if I should have done that |
|
#17
|
||||
|
||||
|
Quote:
![]()
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
| The Following User Says Thank You to TimW For This Useful Post: | ||
safetydave (09-03-12) | ||
|
#18
|
|||
|
|||
|
Tim
Thank you I see no change in the roguekiller log I attached it along with a screen shot of the registry location in question. Is it possible that roguekiller is mistaken? Gratefully Safetydave |
|
#19
|
||||
|
||||
|
Hello there. This is looking quite a mess. According to the rkill log you have lots of missing services. Then when I check other logs, it says some of those services are ok, so let's do this for now please.
Quote:
SystemLook Please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” Last edited by Kestrel13!; 09-04-12 at 05:52.. |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
safetydave (09-04-12) | ||
|
#20
|
|||
|
|||
|
Kestrel13!
I appreciate your attention to the details that I missed and for trying to help. I am not as well versed as I should with Malware removal. I followed your instructions hope I used the correct software this time! Safetydave |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Zeroaccess Trojan | gingerhead40 | Malware Removal | 11 | 07-17-12 23:24 |
| Trojan.Zeroaccess!inf | oldsch00l | Malware Removal | 1 | 03-15-12 20:48 |
| Over 50 attempts of a trojan virus ... | xllxdawnxllx | Malware Removal | 1 | 05-02-10 20:48 |
| Adware Popups & Trojan Attempts to Access the Net | OminousThunder | Malware Removal | 5 | 12-09-08 00:13 |
| Jacko Attempts Suicide, Trojan Marches In | Shadow_Puter_Dude | Interesting Website Links | 0 | 06-10-05 17:56 |