![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I have followed your instructions as per thread: READ & RUN ME FIRST Malware Removal Guide (incl. spyware, virus, trojan, hijacker) by chaslang. Last edited by chaslang; 09-23-11 at 22:56
http://forums.majorgeeks.com/showthread.php?t=35407 Let me congratulate with the clarity of expression and the methodical approach to problem solving showed by chaslang. I found the guideline very useful and easy to read. This is what I have done. I have followed step 1 to 7 (however I missed out step 6 by mistake), so I had to start all over again from scratch after I ran Combofix. For the records: 1. SUPERAntiSpyware took a staggering 3hrs to run first time. Second time it took only just over 40minutes; 2. Malware Anti-malware took nearly 2hrs the first time. just over 30 minutes the second time. 3. Combofix deleted some .dll the first time. Unfortunately I have no log file as I had realised i DID NOT DISBALED CD emulator then...so I started all over again. Results: Nothing was found by the various removal tools. I have attached log files to this thread for your consideration. Current status: - apparently cleaned laptop (windows xp sp3) - AVG 2012 re-installed with firewall. - Defogger still disabled - Settings.dat file has appeared on my desktop (I think this was created by Combofix) - When rebooting system the screen shows black screen with three option - Normal - safe mode - (cant remember the third option). Sorry. The system reboot OK. Normal mode. - Malware Anti-malware shows the following message even though I have removed the software from my machine using add/remove programmes. - I get a warning window saying: [Open Event], Failed to perform desired action. Error code 2. - no problem connecting to wi-fi and the internet after running all removal tools. Anyway, I would be grateful if you could look at the log files and let me know whther you have spotted any concerns that I should look into with your support. Appreciate your help in advance. Thank you and keep up with the very good work. A. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
Please do no make your own ZIP files. Attach the logs as requested. Please attach the original C:\MGlogs.zip file as is. What you attach does not have the MGlogs.zip file required.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
bzarro76 (11-24-11) | ||
|
#3
|
||||
|
||||
|
Quote:
![]() Not requested and should not have been done if you are posting here for help. You should only be doing what is requested and nothing more as stated at the beginning of the instructions.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
bzarro76 (11-24-11) | ||
|
#4
|
|||
|
|||
|
Thank you for your reply. What do you suggest me to do?
Thank you. A. |
|
#5
|
|||
|
|||
|
MGTools attached. as requested
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Now we need to use ComboFix by sUBs
Code:
KILLALL::
DirLook::
c:\documents and settings\Andrea\Application Data\No Company Name
Folder::
c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
File::
c:\windows\system32\oleacc(2).dll
c:\windows\system32\oleaccrc(2).dll
c:\windows\system32\crypt32(2).dll
c:\windows\system32\win32k(2).sys
c:\windows\system32\wininet(2).dll
c:\windows\system32\urlmon(2).dll
c:\windows\system32\url(2).dll
c:\windows\system32\shdocvw(2).dll
C:\WINDOWS\pchealth\helpctr\binaries\pchsvc(2).dll
Registry::
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. I want you to run TDSSKiller so refer to the below for how to do so. TDSSkiller - How to run Please also download MBRCheck to your desktop
Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Tags |
| malware, procedures, removal tools |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware Removal Guide (incl. spyware, virus, trojan, hijacker) | Ranklin | Malware Removal | 2 | 04-03-11 14:37 |
| READ & RUN ME FIRST Malware Removal Guide (incl. spyware, virus, trojan, hijacker) | chaslang | Malware Removal | 1 | 10-09-05 01:49 |
| Re: DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal | MDangerW | Malware Removal | 1 | 07-29-05 19:39 |
| Malware/Spyware/virus help - already done How to removal guide... | bmontana | Malware Removal | 46 | 03-23-05 23:41 |