Log Files

Discussion in 'Malware Help (A Specialist Will Reply)' started by marquella, Aug 16, 2010.

  1. marquella

    marquella Private E-2

    I'm working on a friends computer and she doesn't run any AV, egads! She's running Vista 32 bit version. I can't find the log file for MG Tools, I can only find the executable file in C:\Users\Customer, there's no file folder with the log file in it. It's probably somewhere, I just don't know where. The SAS couldn't run, I kept getting the blue screen of death even after unchecking the kernel files. I'd appreciate it a bunch if y'all could help!! Thanks!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The log file for MGtools is created where the instructions stated. And that is in the root folder of the Windows boot drive. For you, this would be C:\MGlogs.zip

    What malware problems is this PC having..... if any?
     
    Last edited: Aug 17, 2010
  3. marquella

    marquella Private E-2

    Thanks for your help. Not trying to bump this but I did find the MG Tools log file to attach. There doesn't seem to be any glaring issues now but during the processes, I did get the blue screen a few times. I just wanted to ensure that the PC is clean. Thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not the log file. You should not be looking inside of the C:\MGtools folder for anything unless we ask you to do so. The log you need to attach is C:\MGlogs.zip and nothing else. This was specified in the instructions.;)
     
  5. marquella

    marquella Private E-2

    Yes, I'd even read that in the instructions and then got overly excited at finding it that I attached the wrong file, my bad and apologies. Here's the right file!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs basically free of malware. We just have some miscellaneous cleanup to do.

    Okay then we will cleanup what it tried to install. Uninstall it if you still have it installed.

    Also Trend Micro AntiVirus shows in your Uninstall Programs list but it is not properly installed. Uninstall this if you see it in Add/Remove Programs.


    Also uninstall the below outdated Sun Java versions as requested in step 3 of the READ & RUN ME:
    Java(TM) 6 Update 11
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6


    You need to put ComboFix.exe directly on the Desktop as instructed. You have it in the below location and will not be able to follow my next steps until it is on the Desktop.
    c:\users\Customer\Downloads\ComboFix.exe
    Also delete MGtools.exe from the below location since this is also not the location we specified for it to be saved nor run from.
    C:\Users\Customer\Downloads\MGtools(2).exe


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. marquella

    marquella Private E-2

    When I try to save to the desktop, it's putting the downloads here:

    C:\Users\Customer\Desktop

    It shows up on the desktop but will this be a problem since it's not going to C:\Desktop?

    Thanks.
     
  8. marquella

    marquella Private E-2

    Here are the logs, I hope I did this correctly, I followed the instructions as best I could except where it saved to the desktop (see post below). My apologies if I did this incorrectly. Thanks again!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is your Desktop.

    This is not the Desktop. This is a subfolder you created in the root folder of drive C and is not your Windows Desktop. The Desktop is where you see your icons and your Start bar....etc.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future, you should not rename programs like SuperAntiSpyware to names like Super Antivirus First this is not the name of the program, second it is not an antivirus program, and third the folder looked like malware since Super Antivirus would be a malware program name. And fourth because of the name you gave it, my last instructions broke SUPERAntiSpyware because I had ComboFix delete the suspected malware folder name you gave it. ;)

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds