PLease help-Still having malware issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by foghornleghorn, Jul 6, 2010.

  1. foghornleghorn

    foghornleghorn Private E-2

    I performed all the steps that I could from read&run me first and I still am unable to operate my computer in normal mode. The trouble started about 1 week ago. The desktop appears to load in normal mode but the screen is frozen and I am unable to access any applications. I have been using safe mode.
    I have attached logs from my initial SAS and MAMB scans. I have since rescanned using both applications with nothing found. I also attempted to do a complete scan using my Kaspersky. The scan did not finish-my computer blue screened and now I am unable to access Kaspersky.
    Hopefully, I am following protocol here-I am no computer guru. Let me know if there is any other info I need to give.

    I decided to appeal to your expertise. Thanks for your help and your patience!
     

    Attached Files:

    • mbam.log
      File size:
      584 bytes
      Views:
      5
    • SAS.log
      File size:
      584 bytes
      Views:
      3
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Yes you need to attach logs from the below that were requested.

    • Malwarebytes ( you attach the same log twice from SUPERAntiSpyware that you renamed )
    • ComboFix
    • RootRepeal
    • MGtools
    Also you should not be rescanning with anything as stated in the READ & RUN ME. You should only be doing what we request and nothing else once you start this process.
     
  3. foghornleghorn

    foghornleghorn Private E-2

    Thanks for your response.

    I have a 64 bit computer so I did not run ComboFix or Rootrepeal--per the instructions.

    I also was unable to uninstall old Java updates.

    "Windows installer service could not be accessed. This can occur if the Windows installer is not correctly installed."

    But I had no difficulty uninstalling a computer game.

    Ok here are the correct logs this time. I realized that I attached SAS twice later but didn't want to bump--sorry about that.

    Duh! I now realize that the reason Kaspersky won't work now is because it was off.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs, it does not appear that your problems are due to any remaining malware and the cleaning procedure only removed a couple of remnants. You should however delete the below folder:

    C:\Users\User\AppData\Local\lacfkgdbh

    You may want to try using System Restore to go back to a restore point from before your problem started.
     
  5. foghornleghorn

    foghornleghorn Private E-2

    Thank you ChasLang for your responses-hopefully my inexperience isn't testing your patience too terribly much.

    I deleted the file as per your instructions.

    Unfortunately, a lesson learned too late--I have NO saved restore points.

    Does this mean I'll have to do a full system recovery???

    So my questions are...

    Did whatever malware I had in the computer cause the normal startup mode
    to freeze up? Or do you think it's a hardware issue? And because I can start up in safe mode- does that mean whatever driver is the issue is being bypassed?

    I REALLY appreciate all your help!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Potentially or perhaps a repair will work. You will have to post in the Software Forum about this.

    Based on the logs you attached here, it does not appear to be malware related but I don't know if you had removed or fixed anything else with any other tools before coming here.

    Yes there is always a chance that some software that loads in normal boot mode but not in safe mode is the problem. This is also something you can try to debug in the Software Forum and it is where the MSconfig progam comes in handy to debug issues like this by enabling/disabling various startups/service/drivers...etc until you hopefully find the issue.
     
  7. foghornleghorn

    foghornleghorn Private E-2

    I'll try posting in the software forum.

    Ya'll are awesome ;) Thanks so much again for all your help!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds