start up probs after malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheTick, Jun 1, 2008.

  1. TheTick

    TheTick Corporal

    HI everyone

    I currently got infeste with Adware or malware dont really know which one.

    Erm as i began to follow your instructions on malware removal my PC broke.

    I uninstalled Java as requested and as i went to restart up my PC it would not boot up in normal mode.

    It will only boot up in safe mode, i think that it might be the malware/adware.

    I am now typing this in safemode

    any suggestions?

    Win XP service pack 2
    Pentinum 2.93Ghz
    512 MB Ram
    160 gig HD
    Avast virus protection
    I think i have spybot as well

    HELP ME PLEASE
    Cheers
    Adam
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to see logs in order to help you. You need to complete the procedures even if from safe mode and then attach the logs.
     
  3. TheTick

    TheTick Corporal

    Ok cheers

    I will try and get them asap, might be tues night now tho.

    Erm i uninstalled jave as requested by the help you guys gave me.

    I cannot install it in safe mode obviously, will that matter with getting the logs?

    Cheers for the help guys

    Adam :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it will not matter. Anything that you run into an issue with while in safe mode should just be written down so you can explain it to us later, but you need to keep moving on thru ALL steps. The final step is attaching the logs if still having problems.
     
  5. TheTick

    TheTick Corporal

    Malware/Adware

    Hey guys

    I recently posted that my PC did not start up in normal mode after an attack of malware and spayware.

    Well it seemed to fix itself so i was able to complete the reccommended cleaning that you guy suggest.

    How do i know if it worked?
    My PC seems to be working fine again at the min, but what happens if it happens again will i have to do the same thing again?
    I would appreciate any input you have on this situation.

    Anyway i wil post the log files that you requested will you be able to spot any potential problems with these logs?

    Cheers for taking the time to look at mt problem

    Adam

    Pentinum 2.93 Ghz
    Win XP Service pack 2
    512 MB ram
    160 Gig HD
     

    Attached Files:

  6. TheTick

    TheTick Corporal

    Re: Malware/Adware

    Here are the rest
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Malware/Adware

    I merged you back to your original thread. Please remember to stay in one thread for your current malware problems.

    You need to go back to the READ & RUN ME and disable Spybot's Teatimer as requested. This must be done before continuing or it will get in the way of the below fix.

    Then please delete this:
    C:\Documents and Settings\virusErasers\MGtools.exe

    That is not where the READ & RUN ME specified to download MGtools to. You must be careful and follow instructions exactly as written.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5AD44A00-1238-4895-BAC4-C7DEE76D1F83} - C:\WINDOWS\system32\awtqQiiI.dll (file missing)
    O21 - SSODL: SrvAvp - {83ab93a2-f43e-407c-9a61-0c5bb741b6db} - C:\WINDOWS\Resources\SrvAvp.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. TheTick

    TheTick Corporal

    Hey

    U I cant find MGtools\analyse

    I can find MGTools but no analyse

    I have installed it to the C: drive as told but i cant follow the rest of your instructions such as do a system scan and not clicking fix because as soon as i click on MDTools it performs the scan and then sez press any key to finish there are no other options

    Soz for being an annoying person but i am stumped

    Any help would be appreciated

    Cheers

    Adam
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to go into the C:\MGtools folder. It is on your C drive because it was created when you first ran MGtools.exe and the C:\MGtools folder is in your logs. You are not looking properly. If you open up your C drive with Windows Explorer among all the entries on your C drive you should see:

    • C:\MGtools <--- which is the folder created when you ran MGtools.exe
    • C:\MGtools.exe <-- which is where we requested you download the file to but you did not do this as I stated in message # 7. You put it here: C:\Documents and Settings\virusErasers\MGtools.exe Thus you will not have C:\MGtools.exe unless you have redownloaded and saved it properly but that is not necessary since it once it is run the first time, you don't need MGtools.exe anymore.
    • C:\MGlogs.zip <-- which is the log file created from running MGtools.exe or when you run GetLogs.bat
    Thus make sure you are looking at FOLDERS when looking for the MGtools folder.
     
  10. TheTick

    TheTick Corporal

    Hi chaslang

    Soz for being such a pain in the arse and a retard

    I am not very good at this stuff

    Well since i have completed the cleaning process (hopefully right this time) My comp has stopped acting funny, there seems to be no spyware/adware issues, but then they could be hidden deep in my system couldnt they.

    My comp is running fine and as quick as i know it can, and there are no more popups coming on to my screen

    I did recieve that the Fixme.reg file had been successfully merged into the system so thats good

    SO i hopefully followed your instructions enough to be free of this menace called spyware and addware.

    I hope that the MGlogs.zip files and combofix.txt files are the only ones you need.

    Well i again thank you for your help on this matter

    Adam
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. TheTick

    TheTick Corporal

    Hi chaslang

    I have followed your last steps but have a few questions if you dont mind

    My first one is i am using avast antivirus, i disabled it to clean my computer.
    I think it is still running but it as disappeared from the tray in the corner, is there a way i can find out if it protecting me?

    I also could not find this to delete it. Delete the C:\cf folder from combofix

    I also did not download Fixme or fixWLK.reg you gave me the instructions to do this manually. Should they still be deleted?

    I followed the cleaning steps, but most of it was already completed i.e. the removal of problems from quarantine and vaults. The only thing i did was the Ccleaner

    Will this be ok to have my computer free from malware/spyware?

    Just want to say cheers for all you help

    You guys are legends here at MajorGeeks

    Thanks
    Adam
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you stop it from running? Undo whatever you did. Otherwise I suggest that you reinstall it now.

    Then you don't have one to worry about.

    Yes you did. See my fix in msg # 7 where you made the fixme.reg patch and in msg # 10 where you said it worked. Also your logs showed it was on your Desktop.


    I'm not sure what steps you are referring to. It sounds like you are referring to the READ & RUN ME and my final instructions did not ask you to run the READ ME again nor did they say to run CCleaner.

     
  14. TheTick

    TheTick Corporal

    Hi

    I have read you last message and the last point you made is still a little unclear.

    In message 11 you mantion at point 8 this:

    If you are running Vista, Windows XP or Windows ME, do the below:

    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.

    This i thought you were refering to the READ & RUN ME FIRST. Malware Removal Guide: written by major attitude am i wrong about this?

    IS there another i should be checking?

    Anyway like you said i am clean so i am will do the how to protect myself from malware/spyware

    Cheers
    Adam
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was written by me not Major Attitude. He posted the original thread. You will notice that my name is on the procedure.

    Yes the instructions I'm referring to are part of your cleaning procedure for Windows XP. It stated the below (quoted from theWindows XP Cleaning Procedure ):
     
  16. TheTick

    TheTick Corporal

    Cheers chaslang


    I never knew you name was on the malware removal so i do apologise, suppose i was not looking tho

    I have now completed all that you have asked including the system restore and my computer is running well.

    I have also followed the protecting yourself from malware link as well. I no have online armour (i hope thats what it is called) and a squared free. Will this clash with malwarebytes? my comp is running a little slow since i installed armour and squared could this be the reason?

    Other than that cheers for your help and patience with me
    Again you guys rock

    Adam
    :wave
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The free Malwarebytes is only an after the fact scanner so there is no clash.

    Yes these will slow things down somewhat. Especially on a PC like yours that is low on the amount of installed RAM. Uninstall A-Squared and see if things improve. If not, uninstall Online Armor and try a different firewall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds