Cannot open Major Geeks site, Could Not complete Cleaning Steps, Got ONLY MGTools Log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by monalisa, Nov 12, 2008.

  1. monalisa

    monalisa Private E-2

    Hello,
    My laptop got affected with some malwares following which I first did a full scan with Symantec Antivirus. It detected some rootkit, bleep (dont remember all) which it apparently deleted permanently after reboot.

    After using CCleaner, Used Spybot Seach & Destroy - it found some threats which it fixed.

    I scanned with SuperAnti-Spyware - which detected some items and deleted them after a reboot.

    I later realised I should have run the spybot after SAS, so I ran the spybot one more time now - it did NOT find any threat this time.

    Things got bad after this - following is whats happening now:

    1. SInce I forgot to get the log for SAS scan, I tried to open it - I am getting a msg " SAS encountered a problem, it need to close down".

    2. When connected to the internet, if I google "Major Geeks", the search results are showing the Major geeks website link, but when I click on it, its saying "page not found", whereas I can evidently access the sites from other computers!!

    3. I had MABM installed from the past - but the program is NOT opening!! So I thought I will email myself the MABM, COMBOFIX & MGTools applications, downloaded them to the infected computer. Tried to install MABM - the program stopped in the middle, so couldnt finish the installation.
    Tried to uninstall old MABM, that program stopped too.

    3. Since Major Geeks webpages were inaccessible from the infected laptop, I tried to type in the actual web-address from where COMBOFIX could be downloaded, - it took me to weird clearly-bad sites.

    4. After downloading the COMBOFIX application from email, I double-clicked it - The program will NOT Open.

    5. The only thing that ran now was the MGTools. I am attaching that log.

    Could you pls review the log and help me clean the computer?

    Thanks.

    Monalisa
     

    Attached Files:

  2. monalisa

    monalisa Private E-2

    Re: Cannot open Major Geeks site, Could Not complete Cleaning Steps, Got ONLY MGTools

    I forgot to mention - my homepage settings in firefox is not affected or altered, other sites that I commonly visit are also working ok.
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re: Cannot open Major Geeks site, Could Not complete Cleaning Steps, Got ONLY MGTools

    Hello, monalisa

    First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix. Print out these instructions or save them to a text file so as All Browser Windows must be CLOSED.

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 2:
    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Step 3:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\Avenger.txt
    • C:\MGlogs.zip
    * Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now. Also - let me know if you now can connect to the internet on the infected machine.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds