On step 3 of Read & Run Me First & now I am STUCK!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ladyharley99, Jun 19, 2009.

Thread Status:
Not open for further replies.
  1. ladyharley99

    ladyharley99 Private First Class

    Hi. I'm new to this forum. I am trying to do the Read & Run Me 1st steps... but I'm stuck on the 3rd step (Vista Cleaning Procedure)...

    Because I can NOT get the SuperAntiSpyware to fun. (each time I click to install says program has stopped working... etc...)

    Then I tried to go to download The Malwarebytes AntiMalware & it's say page can't be found. (I do NOT have $$$ to pay for this.)

    So, now I'm going to try the combofix.exe... & wanted to post a note before I start, because I have a feeling I may have done something wrong before this.

    Here's the deal... I know what I did to get the virus... Yeah... I did the Keygen thing... BIG MISTAKE!! That was the 1st and LAST time I ever do that!! Anyway, I thought I got it all... but it seems I haven't... because my searches are getting redirected & sending me to ads & etc.

    At least I don't have the annoying audio advertisement that kept popping up.

    I have ran my AVG (which is a paid subscription) & it found nothing but tracking cookies.

    Well, while it was running I found the .tmp file that was running the annoying audio ad & did a shell scan of it & another similar .tmp file... & that's where it found a Trojan Fake Alert. I sent it to the vault & emptied my vault.

    Now, the audio ad does not pop up... but my Google search is still messed up.

    I'm afraid to sign into anything using this computer... So, now that I've ran the CCleaner... all my automatic login are gone, because those cookies are gone.

    SO... to end this long story... I need your help... PLEASE!!!

    What do I need to do now? & How can I give you logs from stuff that I can't even get to run or install??

    I guess I'll give the ComboFix a try...

    Oh... yeah... I went through bleepingcomputers.com & did their autorun program search... & found & deleted a few things that they said were Trojans... but I still am having problems.

    AND... make matters worse... I can't get a HiJackThis application to install either!!!

    SO, I'M AT A LOSS... HELP ME PLEASE!! :cry

    P.S.... I'm a fairly tech savvy & if you give me some stuff to look at or whatever... I should be able to do it.

    I hope you can help me! Thanks, LH!
    (P.P.S. I used my hubby's computer to register to this forum... in case you're wondering.)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to keep going. The below is a direct quote from the first page of the READ & RUN ME
    We don't ask you to install this. Just follow our instructions from beginning to end. ;)
     
  3. ladyharley99

    ladyharley99 Private First Class

    I am... just a little scared at the moment about ComboFix...

    As for the SuperAntiSpyware... That's the one that won't run at all. Says program stopped working.

    So... ComboFix... here I come... (Oh... I am running AVG's AntiRootKit at the moment & it did find one... (never had that happen.) Just waiting for it to finish.

    My next question is... my hubby thinks I just need to run a different AntiVirus scan... Something like Avast.... Do you recommend this???

    Or should I continue onto the ComboFix????

    (Oh golly... If you can help me ... You'll have major kudos coming from me!!!)

    I'm so at a loss without being able to sign into stuff... Ok, better stop now before I start rambling again!! (FYI... the name of my blog is: The Rambling Train... so, I have to stop myself a LOT!!) :-D
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below is also a direct quote from the instructions:
    We did not ask you to run AVG's AntiRootKit. You need to stop doing anything but what we have asked you to do.

    Note: You will not hear from me again until after you finish the instructions and attach some logs and until we can get back to you. I just wanted to keep you going. We work in a priority queue order as stated here: Don't Bump! It Only Hurts You!!!
     
  5. ladyharley99

    ladyharley99 Private First Class

    okie dokie (Not typing this to bump... just to let you know I got your message.)

    I will go run ComboFix right now... If it works. I sure hope I can get you a log! I will be back soon as I have been able to go through ALL the steps. Thank you much Chaslang.
     
  6. ladyharley99

    ladyharley99 Private First Class

    Re: (Logs ATTACHED) On step 3 of Read & Run Me First & now I am STUCK!!!

    Ok, I finally have been able to get something to work!! The only one of the tools that I could get to work was the MGTools... I am attaching it & the errors I received from the RootRepeal.

    Again, as for the SuperAnti-Spyware & the Malwarebytes..., please see my other replies below, for it is late & I'm not recalling all the details. (But they are below!!)

    The ComboFix would not run either...

    brb... I just clicked on it again to get you the error... & now it's acting like it wants to work...
    (oh, says my AVG is running... hmmm...)

    In the meantime, I'll attach the MGTools log.

    Hope you all can find something out with it! Thanks :)
     

    Attached Files:

  7. ladyharley99

    ladyharley99 Private First Class

    Attaching a NEW MGTools log... Is my system clean now?

    I tried to edit my prior message (On step 3 but...)... but I don't see that option...

    Anyway... I'm attaching a new log from MGTools... because I realized I may have messed up the prior one.

    So, please if you haven't already looked at the previous log (in my previous thread)... Please ignore. Because, some things have changed since that last log & the old one may now be incorrect. (Long story.)

    Short of it is... I have a new log... is attached.

    Please let me know if my system is clean.

    Thank you, LH
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Admin Note: Please keep all your posts in this thread!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Attaching a NEW MGTools log... Is my system clean now?

    You mean because you previously had multiple antivirus programs installed which you should not have had!!!! However now you have no antivirus programs installed.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Please run this Running RootRepeal and attach the requested log.

    Double check now also to see if you can get SUPERAntiSpyware, Malwarebytes or ComboFix to run. If you get any of them to run, attach the logs.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
    Last edited: Jun 23, 2009
  10. ladyharley99

    ladyharley99 Private First Class

    Re: Attaching a NEW MGTools log... Is my system clean now?

    WOOT!! (Just excited that now I have some instructions from you to follow... Yes, Sir... I will be FOLLOWING them to the letter!!)

    I'll brb with some explanations & some new logs for ya in a few... got to go read exactly what you've said!! :)
     
  11. ladyharley99

    ladyharley99 Private First Class


    Ok, here's the deal... I have been using AVG 8.5 (have a paid version via a Trial Pay) for a while now...

    Then at Hubby's insisting I downloaded Avast & thought I had disabled AVG while doing that... But promptly uninstalled Avast (so I thought!) when it was done scanning. However, when I tried to run ComboFix the 2nd time, it said AVG was still running. So I uninstalled AVG. That must have been when I ran the 2nd MGTools log as well.

    I have since reinstalled AVG & I had found that MalwareBytes had a free version of their program. So, I have that too now!

    Oh... btw... when all this started. AVG did not find on anything during the FULL scan... but I found a Trojan Fake Alert. something, when I did a shell extension of 2 tmp files that I found was part of the audio popup ads. I thought I had gotten rid of it... but then AVAST found some virus (don't remember what) & I thought I had put that in their vault & yet when I ran AVG after reinstalling (& after uninstalling AVAST)... it found the same virus & it's now in the AVG vault. (Do you need to know the name of it??)

    However, things don't end there!! Because I was so anxious to get things running AND because Hubby kept saying I wasn't doing what he told me to do... I started researching again... & that's when I found that MB had a free version... & so, I installed that & ran it & it found the Trojan.Vundo ...

    Then I was really worried... & that's when I came back to the forums & started trying to find out what I was doing wrong.

    Well, 1st thing I did wrong was I did NOT follow the R&R instructions correctly the 1st time. (Please forgive me... I claim it's Adult ADD, along with a nagging spouse!) LOL

    (I don't know if you've been reading any of my other posts... if so, some of this may be duplicated from it.)

    Anyway... 2nd thing I did wrong is that I was being impatient! 3rd thing is I was listening to too many people giving advice of what to do... when I should have just stuck it out here!!

    Well... there's more (I KNOW) but this has gone on long enough. What I'm trying to say is... I'M LISTENING TO YOU NOW!!! ;) :major

    With that said... let me get to what else you said...

    CRUD... I was going to try to do this all in one reply for ya... but now I see I'm going to have to submit this nice long story of what I've done so far... so that I can follow your instructions carefully! Sorry... I'll brb again! :)
     
  12. ladyharley99

    ladyharley99 Private First Class

    (NEW LOGS) Re: On step 3 of Read & Run Me First & now I am STUCK!!!

    (See below replies!!) ;)

    COMPLETED!! :)

    Tried to run, but it crashed (Gave 2 Error reports, I put in one log, attached)

    All ran fine... MBAM & ComboFix Logs attached... No log from SAS, though... received a pop up to say: "No harmful software detected." :cool


    Done & attached!! ;o)


    Well, I can't really tell a difference at the moment.

    Now I am going to enable AVG again (had disabled for the SAS to run.) & I'm going to restart my system... I should be able to tell when I restart... because I kept getting a slower restart & it was odd when all this started.

    I only wonder if I had some of this stuff long before I got the Trojans. (I still am in shock I had 2 different ones.)

    Ok... Now before I leave you... I have a few questions that have been on my mind (some since this started & others for some time even before.)

    1. In all the logs did you see anything that looked like a Key Stroke generator?? (I am concerned, & because of such, I've not opened my emails & would like to know if it's safe to open now??)

    2. Once you give me an "all clean"... do you think my system will run more efficiently if I were to use the recovery / reformat disc that came with the computer when I bought it? (Meaning starting from fresh?) (Yes, my files are already backed up!) ;)

    3. Can you tell if all this was from just the one problem? Or did it look like I had multiple problems & possibly had been there for a while??

    4. What about the files I saved to my external drive? Hubby scanned it the other day (from his computer using Avast AND MBAM) & it turned up nothing... Does this mean we're safe on that one?

    5. Speaking of... should I do a R&R of my hubby's computer... even though AVAST & MBAM showed nothing? Or maybe just run the MGTools & submit them to the forum for a look over?? (If so, I have to wait until Hubby is not in need of the computer.... & I want to wait to see if you want me to do the R&R completely before I do anything!!

    6. Here's one that's been bugging me for quite some time... Should I be concerned there are multiple "svchost.exe" running in the background (seeing them in my task manager.)

    7. Now what do I do with all the stuff I downloaded for this? I am thinking I'll keep the MBAM free (& later when we have the $$$ get the paid version.)... & I know I'll be keeping AVG 8.5 until Jan 2010, that's when my license for it expires.... I really like AVG, but if you can tell me it's downfalls & why I should switch (if you think I should)... It would be much appreciated.

    8. When uninstalling programs via their icon to uninstall and / or via the add / remove program tool... Shouldn't the programs be completely removed?? I ask, because I still think there's traces of AVAST on my system. (Along with a couple other files I saw in one of the logs.)

    Ok, that does it for all the questions I had written down... I'm sure I'll have more & if I do, I'll wait until you reply again... so as not to "bump" this!!

    I'm heading to attach my logs now... but before I do... Thank you again & I do apologize for the impatience that I had during this time!!!

    P.S. Could you do me a favor, please... when you get this & you start to review my new logs... will you please post a quick note (either here or in a PM, because I have that ability now!) ;) to let me know you're working on it... Just to give me reassurance that I had not been overlooked. (Sorry, I tend to be a little paranoid when it comes to things like this.)

    Thank you again!! :major :cool
    Oh... sorry, I just thought of one other question that I've had for a long time... I have a scrolling mouse... & after awhile when I'm reading something on a page... the page will jump down as if I hit page down or something. It's like the the scroll was settling in or something? Does that make sense? It's only a minor annoyance... & only wondered if it was normal or not.
    Thanks :)

     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since were doing things that we did not request and the READ & RUN ME specifically asks you not to do this, you will now have to reinstall AVG again since my last fix removed what was a left over according to your previous logs. But since you had reinstalled AVG unknown to me, my fix removed and important part of AVG.


    The free version of Malwarebytes is what we had you install while running the READ & RUN ME.


    In the future, please do not cross post in multiple forums or start additional malware forum threads. Only post in one forum and one thread for a problem and simply wait for an answer.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: (NEW LOGS) Re: On step 3 of Read & Run Me First & now I am STUCK!!!

    Your logs were all clean.

    You don't need to be clean to format. If you wish to format and reinstall that is your decision but no malware was shown in your logs.

    Your logs were all clean.


    Your logs were all clean.


    If you want to verify that it is clean, the complete procedure must be run and logs must be posted in a new thread.

    No. It's normal.

    Yes they should but that is not what happens. Very few (if any at all) programs properly cleanup after themselves.

    No! Once we get it, it is when we are working on it. We work in queue order as stated and will not see your posts until we get to it in the queue which is why I'm answering it now. Remember in the future, the more you keep posting in a thread in the Malware Forum, the longer it will take to get an answer.

    Not normal but not malware.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Jun 27, 2009
  15. ladyharley99

    ladyharley99 Private First Class

    I may have to run the R&R on my computer again... or should I just run the MW & SAS 1st to see if anything is found? It's just acting strange.

    I didn't go to any sites or download anything I shouldn't have. It just could be user error. LOL

    If I do go through the R&R again... should I just post the logs in this thread again?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In 12 days a lot can change. If you believe you are having malware problems, you will have to start at the beginning and should start a new thread, but perhaps you should post in the Software Forum and be much more descriptive on your problem. "Acting strange" has no meaning to us.

    Did you ever finsh doing 100% of my final instructions? You should have.
     
  17. ladyharley99

    ladyharley99 Private First Class

    You're probably right, software issues. I think it's to do with upgrading from SP1 to SP2 on Vista. If so, I'll post in the software forum.
    Yes, I did finish the final 100%.

    I don't think I have any further malware issues at this time. If I do, I'll post a new thread, as per your request.

    Thanks much! :cool
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds