![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello,
I followed a link to an NSFW site the other day and soon afterwards got a popup notification along the lines of "Windows system inspection has found an error" and then my browser started randomly opening windows to "anti-virus" purchase sites and redirecting google links to them as well. I've been running through the Windows XP cleaning procedure, but seem to have gotten stuck on running combofix. I think it's because I'm not properly disabling my AV, but here's what's happening, anyway: I run combofix, it says "McAfee VirusScan Enterprise is still active, disable it". I thought I had disabled it, so doubled-checked (and found on-access scanning, and all other 'disable'-able options set to "disabled") and clicked OK. Combofix runs until it gets to this screen: http://www.bleepstatic.com/combofix/en/autoscan.jpg and then just sits there for 30 minutes at which point I manually close it. I tried running MGtools, hoping it was just something with Combofix, but MGtools also froze after about a minute of scanning through my files. Logs from Superantispyware and Malwarebytes' attached. Should I just uninstall McAfee at this point and start over, is there a better way to disable than described above, or something else? The "How to Disable your AV" section on MajorGeek doesn't seem to cover my version of AV. Thanks for your help! |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Yes, try uninstalling McAfee. Did you try running Combo and MGTools in safe mode? Have you tried renaming them?
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#3
|
||||
|
||||
|
Also I think this might help you, give it a go.
Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#4
|
|||
|
|||
|
Thanks guys. I figured out how to disable my AV to the point where combofix doesn't complain about it running and Windows security center complains about it being turned off.
However, still haven't gotten combofix or MGtools to run successfully--same issue as earlier. I tried renaming it, running it in safe mode, and re-downloading it saved as a different name, with no effect. I didn't uninstall my AV because I thought that might not be the problem, although can if you still think it may be worth doing. I did successfully run rootrepeal and TDSSKiller--logs attached. Thanks again for the help thus far, and let me know how'd you like me to proceed. |
|
#5
|
||||
|
||||
|
We could still uninstall Mcafee and then try running Combofix /MGTools again, however TDSSKiller found something that should have solved your problem. Describe to us how things are running at this point please.
But we still need to see if any malware remains, so either uninstall Mcafee and run Combofix and MGTools... or... Download OTL to your desktop.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Attach both of these logs into your next reply.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
OTL run, logs attached.
|
|
#7
|
||||
|
||||
|
Download HostsXpert and then follow the below steps.
Now try and run Combofix and MGTools (without uninstalling mcafee) Any luck? ![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#8
|
|||
|
|||
|
DL and ran HostsXpert successfully, but still error on combofix.
Also, noticed that the clock on my computer freezes during combofix running along with all icons/start menu when I try to open task manager, or use other misc. windows things. |
|
#9
|
||||
|
||||
|
Uninstall Mcafee and try again?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#10
|
|||
|
|||
|
Uninstalled, but no change on combofix
![]() |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Run OTL again as instructed in post #5 (no need to redownload of course)
Run this and attach the results. Using ESET's Online Scanner Tell me how things are running?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#12
|
|||
|
|||
|
Things are running better--the computer was noticably slower before I started with a few of these scans, but now seems to be more on par with its usual speed. Haven't had the popup windows recently and a cursory google search/link clicking doesn't redirect me to "AV" sites. Of course, I've only been online for a few minutes since the scan finished.
Logs attached--ESET did find some stuff. OTL didn't produce an Extras.txt file this time--normal? |
|
#13
|
||||
|
||||
|
OTL reports that MGTools did run so please attach this log:
C:\MGlogs.zip
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#14
|
||||
|
||||
|
It also reports that the log will be incomplete.
MGtools should be rerun since TDSSkiller likely fixed the reason why it could not run properly.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#15
|
|||
|
|||
|
Hmm. MGtools still seems to just sit there. Log attached in case it's at all useful.
|
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Yes, it only had the one log. Let's see if we can get it to run properly:
Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational. cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools> GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see. ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#17
|
|||
|
|||
|
Ran GetRunKey command, and MGtools booted up, sat there and froze the computer as it's been doing previously.
Ran ShowNew, it ran seemingly ok with no error messages and left me at the C:\MGtools> prompt. |
|
#18
|
||||
|
||||
|
Yes because you have no available free disk space. Your logs from OTL showed the below:
Code:
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.26 Gb Total Space | 1.83 Gb Free Space | 4.91% Space Free | Partition Type: NTFS Drive D: | 542.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter Last edited by chaslang; 12-18-10 at 14:51.. Reason: typo |
|
#19
|
|||
|
|||
|
I can do that--how much free space will it need to run successfully?
|
|
#20
|
||||
|
||||
|
Don't bother with any of this. The problem is free disk space as I mentioned below.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Computer Internal Cleaning Questions | Harddriver | Hardware | 9 | 07-24-09 20:27 |
| Still Infected after following cleaning steps | nyt | Malware Removal | 4 | 04-02-09 12:39 |
| Cleaning an infected Time PC desktop | 3spirit | Malware Removal | 11 | 09-06-08 13:51 |
| Water/Liquid cooling cleaning & other questions... | sehana | Cooling And Modding | 0 | 01-09-08 19:39 |
| After days of reading and cleaning I'm still infected | tracy c | Malware Removal | 13 | 08-05-06 23:11 |