I have Ramnit - please help reduce risk of reinfection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Cadmus, Oct 8, 2010.

  1. Cadmus

    Cadmus Private E-2

    I have Ramnit. Yes, it's like having computer AIDS. I have done my research (including the work done here in respect of Ramnit) and have been positevely diagnosed with Ramnit via a different malware support forum. I myself suspected it from the moment I saw desktoplayer.exe being reported by MBAM.

    I am doing a total wipe out of my hard disk.

    However, I needed to backup some files first. None are .exe or .dll files, but there will is at least one .html file - the exported bookmarks from Firefox. I could not afford to lose this. I needed other .doc, .pdf, .jpeg, .mp3 and video files backed up too.

    Therefore I would like your advice on which tools to use to scan the backed-up files before I attempt to put them back on the computer.

    I am not attaching any logs because it is a waste of everybody's time.

    Could you please just advise on how to minimise the risk of reinfection? I need reliable tools.

    Thank you
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could either go thru the trouble of backing up and reinstalling or just start running eSet online scans back to back until you get a clean report.
    eSet Online Scan.

    Then you could do the Read and Run First instructions to be sure it is all gone.
     
  3. Cadmus

    Cadmus Private E-2

    Thank you TimW.

    I'm running Eset scans now. The first one came back with just a bit under 2000 infected files. rolleyes

    Do you think it's worth it? Is it "cureable"? If you think it is I will do the other scans and post back when it's done. Otherwise, I don't want to waste people's time.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    eSet has been very good at fixing these. Just keep running the scans back to back, save the logs and attach them to your next reply. You may need to run it more than 3 times. I will want to see the later logs as often the only thing left to fix is in your system restore folder, which no scan can fix. It then is just a matter of toggling system restore.

    But once we finish with eSet, I will want to see theother requested logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip --> from running the C:\MGTools.exe
    All from doing the Read and Run FIrst instructions.

    We can fix this!! :)
     
  5. Cadmus

    Cadmus Private E-2

    You are so optimistic. :) And I have already taken out my OS disks...

    OK, I will post back in about...at least 4 hrs, I reckon. I know all about the other tools, no need to explain - it's not my first cocktail solution. :)

    Just one final question - what if ESET keeps coming up with the same number of infections over and over again? I'm running the second scan now and things are not looking much prettier.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It will eventually remove all of it. Have faith. We have done this numerous times before. Save the next two logs and attach them to your next reply so I can see what all is being found. We may need to manually remove some items.

    Please read this:
    How to attach items to your post.
     
  7. Cadmus

    Cadmus Private E-2

    I will finish the third scan soon, the number has decreased somewhat but it's still big.

    Do you want me to keep running ESET scans while you will be reviewing the logs, shall I proceed to running other scans (MBAM, SAS, Combofix, etc) or should I just wait?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just wait on running the other scans ( it will slow down the eSet scan ). Continue on with the back to back eSet scans. Attach this up coming result so I can see what is being found.
     
  9. Cadmus

    Cadmus Private E-2

    Let me then provide you with the first two logs, third coming in about 20 minutes.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I realize it is slow, but it is progress. :)
     
  11. Cadmus

    Cadmus Private E-2

    A bit of a time underestimate above - sorry. :)

    Here is the third log.

    Fourth scan commencing...

    P.S. Some lack of progress might be due to me forgetting to tick all the right options in the advanced settings in the last two scans. Idiot!
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In the meantime, do this:

    Now I need you to click Start, Run, and enter cmd and click OK to open a command prompt window.

    * Now hight the below bold text with your mouse and hit CTRL-C to copy it into the Windows clipboard

    %systemdrive%\MGtools\vfind.exe -ltf -s 57344 "%systemdrive%\*Srv.exe" > %systemdrive%\findsrv.txt

    * Now right click in command prompt window and select Paste to copy in the above copied text and then hit enter to run the command.
    * This will take awhile to run thru all files and folders on your PC so just wait for it to finish. When it finishes, your command prompt line will return.
    * Now attach C:\findsrv.txt log
     
  13. Cadmus

    Cadmus Private E-2

    Done it, only took a split second and no log on the system drive! I had an error reported when I installed MG Tools.
     
    Last edited: Oct 8, 2010
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What error message did you get with MGTools?
     
  15. Cadmus

    Cadmus Private E-2

    Something about a .bak file, can't remember sorry. Can I just delete the folder it created on C and do it again to catch the error?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have this:
    C:\MGTools folder? Is it populated? Do you have within the folder: C:\MGTools\FindRN.bat? If so, run it and attach the log.

    Are you still running the eSet scan?
     
  17. Cadmus

    Cadmus Private E-2

    Yes, folder is there, populated. FindRN.bat scan took a second, log attached.

    ESET is still running.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should also have a C:\MGLogs.zip. Please attach that. :)
     
  19. Cadmus

    Cadmus Private E-2

    Yup :).

    Here it is.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That doesn't have all the logs. Let's try it again. Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip
     
  21. Cadmus

    Cadmus Private E-2

    Makes much more sense now.

    Here it is. :)
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\lsassSrv.exe
    C:\WINDOWS\explorerSrv.exe
    c:\program files\microsoft\desktoplayer.exe
    c:\documents and settings\Tihomir\Application Data\Mopyqy\puydk.exe
    Folder::
    c:\documents and settings\Tihomir\Application Data\Mopyqy
    c:\documents and settings\Tihomir\Application Data\Iqiriw
    C:\documents and settings\Tihomir\LocalSettings\Temp\tmp067ed2a0
    C:\Documents and Settings\Tihomir\Application Data\Qoibx
    C:\Documents and Settings\Tihomir\Application Data\Poanef
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "{9E17D16E-828D-82F6-6AB2-FDFD92EC8CBE}"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "nonep"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Now see if you can run SAS and MBAM and attach those logs. Continue running the eSet scans.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am about to log off for the evening. Attach the logs when you are ready and continue the eSet scans until they hopefully stop reporting infections. I will be back tomorrow to see what else is left to do. :)
     
  24. Cadmus

    Cadmus Private E-2

    Before I ran HJT I closed my Firefox session. However, I noticed there were three IEXPLORE sessions in Task manager. Did not do anything about them though.

    Also, ComboFix sent a file for analysis to somewhere. :)

    Here are the logs.

    Thank you for your help today, have some rest. More scans on the way...

    See ya!
     

    Attached Files:

  25. Cadmus

    Cadmus Private E-2

    Minor update:

    ESET scans are not reducing the number of files found to be infected, it seems to be stuck at around 1150. I have uninstalled some of the software which was found to be infected (HTML files mostly) to reduce the number.

    One thing that I noticed in the ESET logs was that MGTools was infected! :eek

    C:\MGtools\analyse.exe Win32/Ramnit.A virus
    C:\MGtools\Process.exe Win32/PrcView application
    C:\MGtools\swreg.exe Win32/Ramnit.A virus
    C:\MGtools\swwhoami.exe Win32/Ramnit.A virus
    C:\MGtools\vfind.exe Win32/Ramnit.A virus
    C:\MGtools\zip.exe Win32/Ramnit.A virus

    Good news is that desktoplayer.exe seems to be gone and not appearing again - for now! rolleyes

    Two new Eset logs for you to consider are attached. I am going to bed now and will run the other scans in the morning.
     

    Attached Files:

  26. Cadmus

    Cadmus Private E-2

    Havng said that - it's back today again, sitting in C:/Program Files/Micrsoft, as usual...rolleyes
     
  27. Cadmus

    Cadmus Private E-2

    I am posting my MBAM and SAS logs and continuing ESET scans.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like MBAM got rid of the desktoplayer.exe. We still have things to remove and I want you to continue with the eSet scans. ( I also will ask Chasling to have a look as we have not had to run so many scans to remove this infection as you have been doing. )

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\rundll32SrvSrv.exe
    C:\WINDOWS\system32\rundll32Srv.exe
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe,"
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
    * eSet logs.
     
  29. Cadmus

    Cadmus Private E-2

    No ordinary Ramnit infection

    This is no ordinary infection. MBAM removed dektoplayer many times before but it keeps coming back.

    I had some serious issues now. Combofix refused to run because it was compromised i.e. infected and instructed a new download. Combofix deleted itself and two versions of Combofix with srv and srvs suffixes were created on the desktop.

    I deleted them.

    After doing the scans and rebooting, while creating the report Combofix reported that the process cannot access the file because it is being used by another process. It did eventually create the log.

    Windows security alert popped up saying it was blocking Windows Explorer. I responded with pressing the "Ask me later".

    Logs coming in next post.

    ESCAN scan keep coming up with around 900 files, no great reduction. What has been reduced is due to me uninstalling some software which was infected.
     
  30. Cadmus

    Cadmus Private E-2

    Logs

    ESET logs were created prior to doing the last Combofix scan.

    P.S. Desktoplayer is back, even after Combofix tried to delete it.
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sigh......never had one being this stubborn.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\program files\microsoft\desktoplayersrv.exe
    c:\windows\ExplorerSrvSrv.exe
    
    Folder::
    c:\documents and settings\Tihomir\Application Data\Hane
    c:\documents and settings\Tihomir\Application Data\Zoyv
    c:\documents and settings\Tihomir\Application Data\Qifu
    C:\Documents and Settings\Tihomir\Application Data\Abpyu
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe,"
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "{9E17D16E-828D-82F6-6AB2-FDFD92EC8CBE}"=-
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
    * next eSet log.
     
  32. Cadmus

    Cadmus Private E-2

    During the Combofix scan it was unable to create a restore point.

    Each reboot seems to bring the infection back. Is the fact that AVG starts on start-up (although without the shield being active) disrupting Combofix on reboot?

    Logs attached.

    Does it make sense to keep running ESET?
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's remove the folders that keep coming up ( You will have to reinstall some of them ):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotraysrvSrv.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotraysrvSrv.exe
    C\WINDOWS\ExplorerSrv.exe.    
    c:\windows\system32\rundll32Srv.exe
    c:\windows\system32\rundll32SrvSrv.exe
    c:\program files\microsoft\desktoplayer.exe
    
    Folder::
    C:\Program Files\Real\RealPlayer
    C:\Program Files\Microsoft Office
    C:\Program Files\epson\TPMANUAL
    C:\Program Files\Common Files\Microsoft Shared\Stationery
    C:\Program Files\CaseSoft\CaseMap 6
    C:\Program Files\AviSynth 2.5
    C:\Documents and Settings\Tihomir\My Documents\Tehno Emails
    C:\Documents and Settings\Tihomir\My Documents\Media
    C:\Documents and Settings\Tihomir\My Documents\Pollitika
    C:\Program Files\Adobe\Acrobat 7.0
    C:\Documents and Settings\Tihomir\Local Settings\temp\Acrobat Distiller 7
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Then run eSet one more time.
     
  34. Cadmus

    Cadmus Private E-2

    Can I keep the non-html files from the folders

    My Documents\Tehno Emails
    My Documents\Media
    My Documents\Pollitika

    ?
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....move them to a separate folder.
     
  36. Cadmus

    Cadmus Private E-2

    I have another question while this is being deleted (am typing from another PC): since a few applications will now have been deleted, instead of uninstalled, will I have problems removing them?
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to just reinstall them when we are done. Anything that is broken, we will either remove the remnants or just have you install it again.

    We want to get you down to just having system restore items left in the eSet logs.
     
  38. Cadmus

    Cadmus Private E-2

    While Combofix was preparing the report after the reboot Windows installer started. I cancelled it. I happened again before running MGTools. It was Acrobat desperately trying to survive.

    Windows explorer was again reported as being blocked by Windows and I continued to block it.

    A file was submitted for analysis by ComboFix.

    Logs attached, proceeding to ESET scan.

    P.S. As ever, desktoplayer.exe is back upon reboot.
     

    Attached Files:

    Last edited: Oct 9, 2010
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are making progress considering the new logs. I will wait on the latest eSet log to give you the next fix.
     
  40. Cadmus

    Cadmus Private E-2

    Well, so far the number of infections detected by ESET has gone up, over 1050 now...will be done in some 20 minutes.
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you rebooting after each scan? Depending on how long this infection has been on your system, the harder it is to remove. But I still have faith. :)
     
  42. Cadmus

    Cadmus Private E-2

    ESET log

    Should I be rebooting after a scan? I am not at the moment.

    I started without faith, remember? :)

    ESET log attached.
     

    Attached Files:

  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, let's try rebooting after the scan. Then run MBAM and start a new eSet scan. Get me the log from eSet so we can see what else needs to be removed.
     
  44. Cadmus

    Cadmus Private E-2

    ESET log is in the post above, that one is before the reboot. Rebooting now.
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OKay!! Progress. Almost all of this is the Combo quarantine folders. Let's uninstall COmbo.
    If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "%userprofile%\Desktop\combofix" /uninstall

    • Notes: The space between the combofix" and the /uninstall, it must be there.
    • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    Now, toggle system restore.

    Now redownload ComboFix to your desktop, but don't run it yet.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\program files\microsoft\desktoplayer.exe
    Folder::
    C:\Documents and Settings\Tihomir\Application Data\Ufasl
    C:\Program Files\AVG
    C:\Program Files\Common Files\Real
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "{9E17D16E-828D-82F6-6AB2-FDFD92EC8CBE}"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe,"
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and reinstall AVG.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * New MBAM log
    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  46. Cadmus

    Cadmus Private E-2

    One question - "download and reinstall AVG"? I have not uninstalled it, just disabled it.

    Here is the MBAM Log
     

    Attached Files:

    Last edited: Oct 9, 2010
  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The fix I gave you is going to delete the C:\Program Files\AVG. If you want, try uninstalling it first before you run the fix.
     
  48. Cadmus

    Cadmus Private E-2

    I just realised that my System restore was actually off.

    I actually ticked, without looking, and actually turned it on and rebooted!!!

    Turned it off again now and rebooted...oh bollocks.
     
  49. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL.....some days are better than others.
     
  50. Cadmus

    Cadmus Private E-2

    I feel like my brain itself is full of Ramnit!!!

    Acrobrat keeps trying to reinstall upon startup. How disruptive is for Combofix, doing the report, when I click on cancel to stop Acrobat trying to install?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds