Can't run SAS, Combofix, or Malwarebytes for READ and RUN Me FIRST

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by noclue124, May 23, 2009.

  1. noclue124

    noclue124 Private E-2

    I am having trouble with my pc, google searches take me to unwanted sites and I can't run any of my anti-spyware programs. I tried to do all the steps in READ ME sticky but can't run Combofix, MB, or SAS. I was able to run CCleaner and MG tools. I've attached the MG log. Any help would be greatly appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the following:

    Remove all of your browser toolbars and extensions.

    Download and Install Registrar Lite.
    Now run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\SYSTEM

    Then click the Security pull down on the top menu and choose Take Ownership. Click OK in the next window to approve it. Now navigate to the following keys and take ownership of them (explained further down):

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService\Enum]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CMDSERVICE\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService\Enum]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDSERVICE]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_CMDSERVICE\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\cmdService]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NETWORK_MONITOR\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NETWORK_MONITOR\0000]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NETWORK_MONITOR\0000]

    o take ownership of the key do the following:

    * Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    * Click-on Security in the Menu
    * Select Take Ownership
    * Now right click on the registry key and select delete
    * Repeat for all registry keys
    * Tell me the results. Any errors?

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now see if you can run the other scans and attach the logs if you can. Let me know what happens

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
    Last edited: May 24, 2009
  3. noclue124

    noclue124 Private E-2

    Thanks Tim,

    When I am copying and pasting the registry keys from the list you gave me into Registrar Lite and I right click to delete them after taking ownership, am I doing this from the address bar or from down below in the list that shows up? The reg keys are not in the address bar anymore after I hit enter and take ownership and I can't seem to find them listed below.

    Thanks in advance for your help
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy & Paste one registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    * Click-on Security in the Menu
    * Select Take Ownership
    * Now right click on the registry key and select delete


    Does that help?
     
  5. noclue124

    noclue124 Private E-2

    Thanks, that did help. This key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CRYPTSVC
    gave me an error message saying "access denied" I was able to remove all the others. Should I continue and see if I can run the other scans I was not able to run?

    Thank you again!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes and attach the logs if you can.
     
  7. noclue124

    noclue124 Private E-2

    Tim,

    I was able to run all the scans. I have attached the logs. I hope that I am in better shape than before. I can't thank you enough for your help!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet......your logs are clean. :)

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    I would suggest you create a new user account with limited privileges and use that account for web surfing. Leave the Admin account for system changes and downloads or uninstall chores.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds