got another infection "again"

Discussion in 'Malware Help (A Specialist Will Reply)' started by teddy1955, Apr 26, 2008.

  1. teddy1955

    teddy1955 Private E-2

    I may never learn:cry
    got another fection from adobe photoshop elements i got form :eek: somewhere.
    it kept me from completing your steps. it would not let me download spybot or malware. Thanks to jump drive got it from the other puter and ran the steps. Please look at the attachments and see what I got to get rid of.
     

    Attached Files:

  2. teddy1955

    teddy1955 Private E-2

    Malwarebytes created no log.
    so I will wait to hear from someone:zzz
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Please attach it.

    You need to disable Spybot's Teatimer as requested in the READ ME.

    You must always put MGtools where we ask you to put it which is C:\MGtools.exe not the below:

    C:\Documents and Settings\chris.CHRIS-D6DDAA924\Desktop\spy stuff\MGtools.exe


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 26, 2008
  4. teddy1955

    teddy1955 Private E-2

    OK here goes.
    1. I followed the run me steps to the letter except I made a file where I downloaded all the programs to. I thought I would make a disc copy of them with the instuctions and keep so I would not have to go to each download site each time. I copied and run the MGtools to see drive and run it from there. (could not make screen print small enough to show)

    2. reinstalled spybot and followed steps.

    Speaking of read me steps, I think a step is missing - in the "superantispyware" steps you say, "Now Physically unplug your cable to the internet." but it does not tell me to ever hook it back up. I did before going to spybot part. If I missed this :eek: "Never mind"

    3. here are the posts you asked for

    being as how early it is TTFN:zzz
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may be of use if you lost the ability to get to the internet since it would at least let you run something. However, it is not a good idea for normal conditions when you are going to work in the forum since all tools and even the instructions in the READ ME may be out of date. They change all the time to keep up will malware and to correct things like you mentioned below. ;)


    Thanks! Fixed it.

    You forgot to tell me how things are working. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  6. teddy1955

    teddy1955 Private E-2

    It seems to be working right now. able to watch the cubs on WMC so I m happy about that. other apps seem OK. I think the tings that spybot got rid of may have taken care of it. I was getting an auto load for reg cleaner and virus from one of the sites that it removed I think it something like "Vuon".:p

    for the record - if I get another cold, should I make a new post before completing run me? I did a search for the pop ups but found nothing close so I did run me.

    on one boot up avenger posted a bunch of errors ie "C:\Program Files\AIM6\bak". Again it seems to be working now. Iwill look for this avenger file and attach.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You should run the READ ME before bothering to post since in most cases it is the starting point anyway.

    Why are you running Avenger and what are you doing with it? You should never run this on your own. You can make your PC unbootable if you do the wrong thing. Avenger is not a scanner, it is only a tool used to do removals of files, folders, and registry keys.
     
  8. teddy1955

    teddy1955 Private E-2

    looking for print of why. Somewhere i was told to run avenger and paste a statement in it. It may have been from last time round. can't find the instuction right now. if I find them i will post why I ran it.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger is only used in special instructions given in a cleanup procedure the directly relates to the problem at hand and they only apply to the individual person they are posted for. The only place you would be running it is in this thread if requested. It is not part of the READ & RUN ME.
     
  10. teddy1955

    teddy1955 Private E-2

    found where i went a stray. I picked from the thread orginally posted "Computer acting stupid" answered by ABRI friday. I know now that was really stupid. I think I wanted to fix this so bad that I jump overboard. Have I caused more problems?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know since I don't know what you did with Avenger. Perhaps it did not delete anything at all since the thread you mentioned has nothing to do with you.
     
  12. teddy1955

    teddy1955 Private E-2

    I did just what it said to do on the stupid thread. I have attached small jpgs hope you can read them. I printed this after it poped up on the screen but can not find it by searching. so I made a copy and jpeg'd it here.

    I am not going to remove anything else unless you tell me.

    Again so far it seem to be working fine.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger did not delete anything in this case since none of thos folders had anything to do with your PC.

    You should delete Avenger and never run it again without specific instructions that were written for you.
     
  14. teddy1955

    teddy1955 Private E-2

    ok
    Thanks again for the help.:wave
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds