Lot of Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by lamilucy, Sep 24, 2010.

  1. lamilucy

    lamilucy Private E-2

    I am using Vista and these are the problems I have been haveing. My web pages load, but most of the time it says "with problems on page" I keep losing my web connection, although the moden, 2Wire, is working fine. Also, in my e-mail, Outlook, can't seem to empty my deleted folder.

    I have attached the logs from Cleaning Vista. However, when I ran MGTools, it ran automaticly, and when I right clicked on GetLogs.bat file and run as administrator, it runs exactly the same thing again. Cannot find MGlogs.zip file, did find HiJackThislog, have included it. Do have a zip.exe file in folder. Don't know what's up, ran MGTools as instructed. Anyway, your help would be greatly appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where did you find the HJT log? It indicates it was from the C:\MGLogs.zip. We really need you to attach that log.

    We also need the log from running MBAM.
     
  3. lamilucy

    lamilucy Private E-2

    OK, here is the mbam log. Sorry I missed this one. What I was saying about MGTools is that it did not run the way the instructions said it would. I got the HiJackThis agreement before I clicked on the GetLogs.bat file and I could not find the MGLogs.zip file in the MGTools folder. I did find the HiJackThis log in the MGTools folder. Ran MBam and here are the logs. Thanks for your help.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGLogs.zip is not in the MGTools folder, it is located in the root folder of your C drive > C:\MGLogs.zip.
     
    Last edited by a moderator: Sep 25, 2010
  5. lamilucy

    lamilucy Private E-2

    OK, sorry, I misunderstood. Here is the MGTools.zip, I found it.
     
  6. lamilucy

    lamilucy Private E-2

    Couldn't get it to attach, trying again.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. However, do you really need these:
    I suggest that you post in the software forum for the issues you are having.
     
  8. lamilucy

    lamilucy Private E-2

    I don't know enough to know if I need these, I have no idea what they are. You tell me if I need them. Think my problem may be in the registry, but don't know enough to tell. Thanks for your help.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then let's remove them.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\ProgramData\SPL146A.tmp
    C:\ProgramData\SPL15A2.tmp
    C:\ProgramData\SPL2A69.tmp
    C:\ProgramData\SPL2DF7.tmp
    C:\ProgramData\SPL334F.tmp
    C:\ProgramData\SPL3793.tmp
    C:\ProgramData\SPL3A73.tmp
    C:\ProgramData\SPL3BDB.tmp
    C:\ProgramData\SPL3E95.tmp
    C:\ProgramData\SPL4191.tmp
    C:\ProgramData\SPL424.tmp
    C:\ProgramData\SPL4568.tmp
    C:\ProgramData\SPL45F4.tmp
    C:\ProgramData\SPL51F6.tmp
    C:\ProgramData\SPL5BE9.tmp
    C:\ProgramData\SPL610.tmp
    C:\ProgramData\SPL8C0B.tmp
    C:\ProgramData\SPL9D19.tmp
    C:\ProgramData\SPLA2B6.tmp
    C:\ProgramData\SPLA630.tmp
    C:\ProgramData\SPLAAB1.tmp
    C:\ProgramData\SPLC43E.tmp
    C:\ProgramData\SPLE744.tmp
    C:\ProgramData\SPLF3D2.tmp
    C:\ProgramData\SPLFBA1.tmp
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now! What issues are going on that makes you think there is a problem with your registry?
     
  10. lamilucy

    lamilucy Private E-2

    It seems to be working better, certainly faster. Reason I thought it might be registry is, along with losing connection, a couple of times, logged on and would not take my password for my desktop, rebooted and then not a problem. When I first started to lose my connection, called ISP, couldn't figure out was was up, tech support told me it was in the registry, but of course, he wanted $99.00 to check it out and fix it. So when you guys said didn't look like malware or spyware, thought that must be it. Havn't been on long enought this time to determine if still losing connection, but will let you know. Let me know how logs look, and if anything else I need to remove. While looking at Windows Explorer, looked like I have a lot of duplicate files from Windows updates, but not sure.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will give it a few days to let you check that all is ok. :major

    Once you are sure it is fine, then:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  12. lamilucy

    lamilucy Private E-2

    Ok, apparently, I did not disable Disk Emulation Software, before I started all this, don't know how I missed that step. Will that make any difference? Here are the problems I'm still having. My mouse is set for single click, but having to double click on things to get it to open. Also, when I turned my firewall back on, cannot use my printer. Thinking of getting rid of McCafee and using AVG, any recommendations? Someone told me that McCafee sees Adobe as a trojan and causes problems. Anyway, will wait till you tell me if we need to start over before doing above. Thank you for your paitience and help. I have started doing a lot of reading and tutorial to learn to do this myself. You guys ROCK!!!!!!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The issues you mentioned all belong in the software forum. I can't tell you why your mouse is acting up, nor can I tell you how to have your firewall make an exception for the printer. Both topics need separate threads started in the software section. ;)
     
  14. lamilucy

    lamilucy Private E-2

    Ok, thanks so much for your help.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds