can't run Mbytes or Combofix but i have SAS and Mg logs....

Discussion in 'Malware Help (A Specialist Will Reply)' started by AlwaysInfected, Sep 1, 2009.

  1. AlwaysInfected

    AlwaysInfected Private First Class

    I'm annoyed as hell, I ignorantly made an attempt to install this fake PS Cs4 program n the result was my first infection in like 3 years. I keep getting that BS windows defender prompt on startup and it seems to be blocking Combofix from operating but especially Malwarebytes even if renamed (Which I know will get rid of most of the malware related to this nonsense)

    Blah!
    heres my logs.

    P.S. Great! now i cant even reopen SAS to get the logs!!! :cry I ran SAS last night and it scanned right from install but now when i go manually open it to go get logs I can't, it says that whole not a specified path blahabittyblooblah etc...

    Any and all help is greatly appreciated!
     

    Attached Files:

  2. AlwaysInfected

    AlwaysInfected Private First Class

    (this is not a bump) I just can't seem to fiind the edit button. I just wanted to add that my firefox crashes alot since this happened and 90% of my google searches get redirected! shit is annoying as hell....
    Thanks...
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Were you unable to run RootRepeal? You did not allow MGTools to run to completion. You need to wait until it tells you to hit any key. Please run it again and tell me if you get the pop up to the HJT license. You need to agree to that!
     
  4. AlwaysInfected

    AlwaysInfected Private First Class

    This sucks i dont think i can run Mgtools either then. Because whenever I try to run it, that little black box where the scan runs in, pops up n then disapears instantly as if something doesn't want it to run....


    heres the RootRepeal log
     

    Attached Files:

  5. AlwaysInfected

    AlwaysInfected Private First Class

    This section is pretty busy, i feel for yall, virus's and lack of knowledge seem pretty bad. All ya'lls help is underappreciated!

    Basically, I dunno what to do. Nothing seems to be scanning, I don't even know how SuperAnti scanned but it did off of the initial install but like everything else now i can't get it to open to get the log from it. I can't run scans with any program, manually. I do get the daily auto scans from my AVG but thats it.

    Whatever i have is annoying as hell! All my google links get redirected atleast 3 times before it goes to the real one. My firefox wants to crash now periodically, I haven't gotten the Windows defender pop up in a while now but im sure its still lingering around

    I wish i could run Combofix, or Malwarebytes or MGtools... Nothing is fulling executing...
     
  6. AlwaysInfected

    AlwaysInfected Private First Class

    TimW? anyone please?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sigh..you were almost at my next reply. With this bump, you would have been waiting another 3 or 4 days.

    HOwever, I suspect you have one of the newer infections that is becoming very difficult to deal with. We can start by trying this:

     
  8. AlwaysInfected

    AlwaysInfected Private First Class

    Im so sorry, my intent is not to add or put pressure on any of you. I think what you guys do is fantastic and highly appreciated. I just assumed since i was replied to that maybe once you are replied to the interaction is handled until things are worked out. I was unaware and again, I apologize!!! :cry

    I will follow through these steps!

    I never ever get infections, I basically brought it upon myself due to stubborness and impatience. It will not happen again!

    Thanks and i will return with some more info sir.

    AI,
     
  9. AlwaysInfected

    AlwaysInfected Private First Class

    this is insane... Im worried. Mgtools initial attempt does like it's been doing, the lil black box pops up n then just gets shut down or rather pops right off the screen... I then went to fixAVP n the same thing happened with FixAVP's box only faster.. You think it's really the infection blocking all these antimalware scanning apps?

    :(
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You are infected with one of the new nasty forms of malware that blocks many applications from running. And those that will run, will run once and then not again as you saw with SUPERAntiSpyware.


    I will be sending you a Private Message with some instructions to follow. We are doing this privately to keep the info out of the hands of the malware creators. Please do not mention the name of utility we will be giving you or where you are getting it from. Just try to do what we ask you to do and then post back here with any problems you had. Again in mentioning your problems, please don't refer to the program by name. Just call it "the utility" or "the program". For example, you response could be:
    The program ran OK. Or the program would not run, I received the following error message...(put your error message here).
     
  11. AlwaysInfected

    AlwaysInfected Private First Class

    Chas my old friend. You are the man, and i got you! Thanks for the lookout.. N yea i won't mention ish...

    It's funny, whenever id'e have problems before id'e be in awe at how easy ya'll made it look to wipe the BS malware away. Almost like the hand of god. :-D
    Only makes sense for these clowns to lurk on these forums and try to get smart to what's destroying their ego.... Foolish folks i tell you... all that talent put to foolish use...

    Anyhow! I'll get to it and let you know! thanks sirs!
     
  12. AlwaysInfected

    AlwaysInfected Private First Class

    k here we go, i got the utility log and renamed it aswell...:-D

    I tried running all the other stuff, MB, MG, etc...still a no go...

    hope this log can help so we can weed through this complex mess... :cool

    Thanks again...
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. AlwaysInfected

    AlwaysInfected Private First Class

    Here you go...
     

    Attached Files:

  15. AlwaysInfected

    AlwaysInfected Private First Class

    wait a second... disregard this log... it is premature...
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I noticed that. Please attach the full log if you have it. We can see the cngaudit.dll file is part of your infection and will need to be replaced with a valid copy of the file.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just in case WIn32kDiag does not finish. Please do the below.

    Open up notepad and copy and paste all of the below text in the quote box into it. Then save the file as "find.bat" (you need to use the quotes as shown to avoid having a .txt appended to it) and save it to your Desktop. The double click the find.bat file to run it. When it is finished, attach the c:\flist.log file that will be created. While it is running, a command prompt window will show. It will closed when it is finished.

     
  18. AlwaysInfected

    AlwaysInfected Private First Class

    How do i run the find.bat file? is that in Mgtools?

    Also how do i know when win32kdiag has finished? will that black box dissapear when done? I noticed it just sits there n then eventually after a while it's gone through more stuff... (Im playing ps3) so i noticed when i go back to look at it it's at a different point.
    Will it just close when it's done? Im asking so i can give u the proper completed log.

    Thanks!
     
  19. AlwaysInfected

    AlwaysInfected Private First Class

    it finished!!!
     

    Attached Files:

  20. AlwaysInfected

    AlwaysInfected Private First Class

    (not a bump)
    :major

    I don't know why the edit option is not available. Anyhow i need to post this because it's crucial to my activities online and im guessing any malfunction from here forth is a result of whatever infection i have... (It seems to be taking its toll)

    While other sites still seem to be working fine, it seems all search engines went from re-directing the links i clicked to now not working at all... Whenever i type in something in the google search space on the main page it now just goes blank n says "done" down on the browser bar... I figured maybe it was just google, but I'm having the same problem with yahoo search aswell....:confused

    I wanted to just edit a post but can't n then i decided maybe i should post this in the "software" section but didn't want anyone there to not be aware of my malware issues.

    Anyhow, sorry and thanks.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Saying it is not a bump does not change the fact that the effect is still a bump. It cost you at least 2 days.


    Here is what I want you to do....

    Please copy C:\Windows\System32\logevent.dll to your C:\ drive so you now have:
    C:\logevent.dll

    Now:

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now go to start / run / type:
    "%userprofile%\desktop\win32kdiag.exe" -f -r

    Attach the new win32kdiag log.
     
    Last edited by a moderator: Sep 20, 2009
  22. AlwaysInfected

    AlwaysInfected Private First Class

    I dont understand what that means? copy words to Cdrive? Like open "run" and type that in it? :confused
    also it then says "files to move" how and where?

    by the way sorry about the bump thing... I got my google back so thats working. Its still redirecting search links 3 times before i can actually get to the link and sometimes the redirect just crashes my firefox. :(
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me be more specific:

    Please do the below to make a copy of the good system file into the root folder of your hard disk so that we can use it to fix your problem.

    1. Click on the Start button, then click on Run...
    2. In the empty "Open:" box provided, type cmdand press Enter
      • This will launch a Command Prompt window (looks like DOS).
    3. Copy the entire blue text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
      copy C:\Windows\System32\logevent.dll C:\ /y
    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
    5. Press Enter.
      • When successfully, you should get this message within the Command Prompt: "1 file(s) copied"
        NOTE: If you didn't get this message, stop and tell me first. Executing The Avenger script below will not work if the file copy was not successful.
    6. Exit the Command Prompt window.

    Now download The Avenger by Swandog46, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now do the following (make sure you redownload the file. Do not use the old copy.):

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:

    • C:\avenger.txt
    • the new log from Win32kDiag
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  24. AlwaysInfected

    AlwaysInfected Private First Class

    Cool, I'm pretty sure all the scans went well... here are all the logs, one thing i have noticed is that Google searches are very prestine again, doesn't seem to be any more redirecting....

    Should i run Malware Bytes? I couldn't run it before but since everything else has run so far, I'm itching to use it. :-D love that program.. :p
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes to running MBAM and you should also run SAS.

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Then use windows explorer to find and delete:
    C:\Windows\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
    C:\Windows\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * SAS
    * MBAM
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  26. AlwaysInfected

    AlwaysInfected Private First Class

    real quick. i have a bunch of hidden files unhidden since i ran MGtools i believe... Once i run it again how do i re-hide everything and then how do i properly uninstall Mgtools?

    Also i dont know how to find those files you spoke of... with windows explorer
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will deal with re-hiding your system files when you are all clean.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now continue on.
     
  28. AlwaysInfected

    AlwaysInfected Private First Class

    Thank you sir, will be back in a few with your logs.. :cool
     
  29. AlwaysInfected

    AlwaysInfected Private First Class

    Im back sir, hope all is looking good!

    here you go...
     

    Attached Files:

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. Tell me what issues you may still have.
     
  31. AlwaysInfected

    AlwaysInfected Private First Class

    I can't think of anything right now, I think I'm pretty good ever since we were able to infilitrate the original issue with an app, scan n clean things. So Thank you both! Yourself and Mr. Chas for all the patience and follow ups!!!!

    You guys are the bestest, greatestest! :cool
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  33. AlwaysInfected

    AlwaysInfected Private First Class

    One prob, i had deleted the combofix icon about 2 weeks back when i couldn't use it. How i can officially uninstall it tho? It says in the removal procedure that once it is uninstall all my unhidden files will be hidden again so I'm not sure what to do now... :confused
    Thanks again.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you will need to manually delete the rest of Combo. You can do a windows search for the combofix remaining folders.

    To re-hide your system files, you can go to the control panel, double click the Folders icon. There click on view and click the "Do not show hidden files.....", apply and ok out.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running MGClean.bat should take care of all of this automatically. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds