not sure if infection is gone

Discussion in 'Malware Help (A Specialist Will Reply)' started by angeldust21, Oct 21, 2009.

  1. angeldust21

    angeldust21 Private E-2

    ******************************************************************************
    MGtools installation folder and files at Start of Scans


    Inline log deleted!
     
    Last edited by a moderator: Oct 31, 2009
  2. angeldust21

    angeldust21 Private E-2

    Inline log deleted!


    Zipping GetUnKey.txt
     
    Last edited by a moderator: Oct 31, 2009
  3. angeldust21

    angeldust21 Private E-2

    now its not letting me post the rest.
     
  4. evilfantasy

    evilfantasy Malware Fighter

    That's OK. Try this please.

    Upload the file to File Dropper

    Click Upload
    Locate the file and double click it.
    Copy the link under Share This Link: and post it back here.
     
  5. angeldust21

    angeldust21 Private E-2

    Attached Files:

    Last edited by a moderator: Oct 31, 2009
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post anymore logs inline. It should not be necessary. If you can upload to filedropper then you should be able to upload here.


    While I read thru some of this thread and look at your most recent logs, please download the following & save to your Desktop


    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. angeldust21

    angeldust21 Private E-2

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to stop doing this! We want all logs attached.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You need to attach it here at MGs. If you can upload it there, you can upload it here.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not so sure how much of your problems are a corrupted Windows OS and how much is malware. You have a lot of system files which are the wrong size. When you were doing your Windows Updates, did you have problems?

    Does ComboFix run properly for you? We are going to need to use it and Avenger.
     
  12. angeldust21

    angeldust21 Private E-2


    no, i had no problems downloading the windows updates. combofix is another story, everytime i download the file, i try to open it and it says it can't open because the file is corrupted and then it list a long number and freezes my desktop so i have to reboot. i tried in safe mode, even renaming it, and i still get the same message.

    i tried gmer in normal and safe mode and it starts scanning for a little bit then it says gmer encountered a problem and needs to close and freezes the window.

    :cry this is incredibly frustrating, but thanks to you and evilfantasy for your time and patience.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah!!!! This may be what I'm noticing. Does it say anything about a Virut infection? If you don't remember, try dowloading the current version of ComboFix right now to your Desktop and then double click on it. Tell me exactly what it says.

    combofix.exe

    I have more to give you but it will be a waste of time to post it until I know the answer to the above.

    However on the outside chance that it is not a Virut infection, I want you to do the below to get prepared for what my next steps may be.

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp3bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    Now uninstall AVG9 and reboot. Then continue with the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now download and install Mozilla FireFox and use it for your browser instead of Internet Explorer which may have some corrupted files associated with it.
     
    Last edited: Nov 1, 2009
  14. angeldust21

    angeldust21 Private E-2

    i downloaded combofix, double clicked the link and it starts to load when i get this message: Windows cannot find 32788R221FWJFW\iexplorer exe. Make sure you typed the name correctly, and then try again. To search for a file, click the start button, and then click search.

    i try to close that message but it keeps changing the file names where the numbers are, and it won't let me close the message, so i have to reboot.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then just do what the rest of my message gave you as long as it did not say anything about a Virut infection.
     
  16. angeldust21

    angeldust21 Private E-2

    i followed all instructions and downloaded mozilla which i'm currently using.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good! Hopefully it will work better.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    FileCopy.bat


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    After getting this log, I will be able to complete a procedure that I'm working on. DO NOT SHUTDOWN OR REBOOT YOUR PC. You need to keep it running until you start this next fix and it reboots your PC itself.
     
    Last edited: Nov 1, 2009
  18. angeldust21

    angeldust21 Private E-2

    i clicked on the filecopy.bat link and it takes me to new window that says error 404, file not found.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it now. I just fixed the link.
     
  20. angeldust21

    angeldust21 Private E-2

    i click on the link and it asks me to save but it doesn't give me an option where to save?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that's the stupid default of FireFox but it should be defaulting to the Desktop. Give it a shot and let me know. If it does not goto the Desktop, I will tell you have to change FireFox to prompt you.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In fact, here is what the READ & RUN ME gave you (in the downloading of MGtools area) about setting FireFox up properly.
     
  23. angeldust21

    angeldust21 Private E-2

    ok,i was able to save and run it and the black screen showed up quickly and i got the internet error message afterwards. is this normal?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What internet error?

    You need to just move on to running GetLogs.bat as requested and attach the new MGlogs.zip file.
     
  25. angeldust21

    angeldust21 Private E-2

    i got the internet encountered a problem and needs to close on my last post. i tried the mgtools/getlogbat and here are the results. let me know if i did it correctly. thanks
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    GetLogs.bat ran properly but it shows that FileCopy.bat did not. Where do you have FileCopy.bat? Is it on your Desktop?
     
  27. angeldust21

    angeldust21 Private E-2

    yes i saved it on my desktop but right after it ran i got the internet encountered a problem and needs to close popup. could that have messed it up? should i try it again?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see why FileCopy.bat did not work. Download the below new version and overwrite the old version with it:


    FileCopy.bat


    Now run it. Then rerun C:\MGtools\GetLogs.bat and attach the new MGlogs.zip file again. Hopefully this is more successful so we can move on to the next steps. Don't worry about any internet errors if you get any of them.
     
  29. angeldust21

    angeldust21 Private E-2

    here is the new log:
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is still not copying the files we want to copy. Let's do something else and then move on to my next fix which is all below.



    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now download The Avenger by Swandog46, and

    save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you
    delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Lorraine\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note:
    if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the Win32kDiag log
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  31. angeldust21

    angeldust21 Private E-2

    please let me know if i did anything wrong, i wasn't able to delete a file on avenger, it says it was currently in use. here are the logs

    when i first downloaded win32kdiag and ran it something went wrong and i got a debugger error message and i had to reboot cause it froze my desktop. let me know if that affected anything. thanks
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay somethings worked and some did not. We may have to boot to the Recovery Console to fix some files since Avenger will not do it and you cannot get ComboFix to run.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    After clicking Fix, exit HJT.


    Now download and run the new FileCopy.bat program below. Overwrite the old version with it:


    FileCopy.bat


    Now run it. Then rerun C:\MGtools\GetLogs.bat and attach the new MGlogs.zip file again.
     
  33. angeldust21

    angeldust21 Private E-2

    here is the new log
     

    Attached Files:

  34. angeldust21

    angeldust21 Private E-2

    hi, i was wondering if all my files came out ok on my last post? i'm able to run combofix now, i ran a scan yesterday. if you want me to post my log or a new log let me know. thanks.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you read and understand this sticky: Don't Bump! It Only Hurts You!!!

    Yes we need to see this log from ComboFix. The FileCopy finally did what I wanted it to do but we have more to do. You need to attach the ComboFix log first though before we can continue.

    Also tell me how your PC is currently operating.
     
  36. angeldust21

    angeldust21 Private E-2

    well i have a new problem, a couple of days ago i downloaded the new microsoft updates and turned off my computer. the next day when i turned on my computer, nothing loaded and i got this message: Explorer.EXE, unable to locate component. This application has failed to start because Normaliz.dll was not found. Re-installing the application may fix this problem. the only thing i can access on my desktop is the task manager. i tried in safe mode and i got the same message. before this happened all my scans were coming out clean, except malwarebytes and my antivirus found a trojan and i deleted them successfully. the only problem i was having was my clock was still changing on its own. can you tell me what was going on with my logs. also how can i get rid of this error so i can run combofix again? thanks.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was not what I asked you to do. Did you read the below at the very beginning of the READ & RUN ME? See the last bullet item.
    You will now have to attempt working in the Software Forum to see if you can make your PC bootable. If you cannot do that, you will possibly be reinstalling which may have been a good idea anyway since many of your problems appeared to be Windows related and not malware.
     
  38. angeldust21

    angeldust21 Private E-2

    hi, i got my moms coworker to reinstall windows for me. the problem now is i can't connect to the internet at all. the only programs running on my desktop are the recycle bin. avast antivirus, and internet explorer link. i aclick on that and it won't connect at all. i'm also back to service pack 2. my laptop is directly connected to a modem and the modem is working ok, because i'm using my brothers laptop currently which uses the same modem. do you know what may be causing this? :confused
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you post in the Software Forum to get help. This is not a malware problem. It is a problem with your reinstall and getting the proper drivers for your hardware installed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds