![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I'm not sure if you all can help with this or not, but I wanted to check before I resort to doing a clean install and all of the associated hassles and loss of data...
Brief overview: On Monday I got the ugly FBI ransom screen, then tried to boot in safe mode and got a screen/page saying "page will load in 30 seconds", which didn't go away and I had no control over keyboard or mouse. I created an Kaspersky rescue disk to boot from and between that, Hitman pro (with control + O option), and restoring to an earlier time I was able to boot normally. I then went thru your list of items (copies attached) and everything was clean. However, I've since discovered that my Av (trend micro) won't update, and probably isn't really scanning - I ran their rescue/repair disk to no avail, then found online to manually start the "listening service" from local services, which I did - it'd start for about 3 seconds then be off again. Can't even turn on windows firewall - went thru their support for the error codes and nothing worked. Then to top it all off under the documents & settings folder (probably others too that I havent seen yet) it made folders such as application data "not available", which was easy enough to reverse, but then it has made those same folders be redirected (?) to the same folder they are in - haven't figured that out yet. Attached are the requested files that I ran on Tuesday when I thought I had everything cleared up, but I've obviously made changes to the system since then in trying to get firewall/AV working again. Any advice you can give me would be much appreciated. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options. To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Ran the scan - report is attached
|
|
#4
|
||||
|
||||
|
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Attached is fixlist.txt
Now re-enter System Recovery Options. Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (How to attach) Now attempt to boot normally. -------------------------------
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Attached are the logs. And Kestrel, thanks a lot for all that you have done so far - very much appreciated
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
I missed some malware out so let's have another stab. I'm sorry.
Fix items using RogueKiller.Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator) When it opens, press the Scan button Now click the Registry tab and locate these 3 detections:
Now press the Delete button. When it is finished, there will be a log on your desktop called: RKreport[2].txt Attach RKreport[2].txt to your next message. (How to attach) Reboot the machine. Re run RogueKiller- no fix just a scan and attach log. Re scan with HitmanPro and attach that log too please.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
Eddie F (08-09-12) | ||
|
#7
|
|||
|
|||
|
Kestrel - no apologies are needed. I very much appreciate what you are doing for me, and I'm sure it's easy to overlook or miss some code/path when you check out all of these logs to help people out, not to mention whatever your regular job is.
I followed your instructions and the logs are attached. RKiller created 2 logs when I "fixed" so I'm attaching both of them, as well as the later scan only. |
|
#8
|
||||
|
||||
|
Thanks for understanding.
How is everything running at this point?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#9
|
|||
|
|||
|
Unfortunately no good news at all - still having all of the same problems.
As I was checking everything out I did notice that the Trend Micro "listener" now stays started for about 5 minutes after a reboot, which allows it to update (or me manually update). After that time though something causes it to stop, and when I try to re-start it it just stops again after a few seconds. I rebooted a few times and it always does the same. |
|
#10
|
||||
|
||||
|
You mean you still have the ransom screen coming up?
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Nope - I managed to get rid of that and after running all of the things in the "read me" list I thought everything was fine.
Quote:
These are the problems/issues I'm having now, which is what I had originally inquired/asked for help about: Quote:
|
|
#12
|
||||
|
||||
|
Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
After reboot, check to see if your firewall is working. Are you able to uninstall and reinstall your antivirus?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
Eddie F (08-10-12) | ||
|
#13
|
|||
|
|||
|
I ran it - with mixed results.....
The windows firewall is now functional ![]() My file "access" issue is worse: If I try to access c:/documents and settings I get "access denied", where before I could get into that folder, but the folders I needed to get into were re-directed to the same folder. I didn't bother to check other folders that were restricted/denied as this one is worse now. When I try to open Trend Micro it now says "activation required". and that I'm not protected at all. Click on the link and I get an "about:blank" page. The rescue disk that came with the computer gives options to repair or remove - I tried repair and it wouldn't do anything. If I remove it do you know if it would then give an option to reinstall? |
|
#14
|
||||
|
||||
|
Quote:
![]() Quote:
Quote:
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#15
|
|||
|
|||
|
Quote:
....I still can't access the folder I needed to in order to repair Autocad (instructions said to delete a couple of files before repairing), but I decided to uninstall & reinstall - which is an P.I.A. to re-setup everything in the program - but it's done & fixed now ![]() Quote:
Quote:
![]() Do you want/need to see any further logs now, or do I go thru the program removal process now? Thanks again for all of the help and assistance you have given me - I really do appreciate it very much! |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
You are most welcome.
Glad everything else is sorted. Safe surfing!If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
Eddie F (08-12-12) | ||
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Ransom Virus | wazmoz | Malware Removal | 1 | 06-14-11 08:21 |
| AVG uninstall remnants | coolboot | Software | 4 | 03-02-09 10:46 |
| Hackers Lock Files, Demand Ransom | SportsNut | Interesting Website Links | 2 | 05-26-05 01:10 |