Had Windows recovery rogue and more

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Guy Newton, May 11, 2011.

  1. Guy Newton

    Guy Newton Private E-2

    I believe I had windows recovery rogue anti-spyware

    I completed all steps on READ & RUN ME FIRST Malware Removal Guide on about April 23rd

    after running all the steps, (Malwarebytes Anti-Malware did not run, could not install it)

    I had a lot of files that were hidden, windows Internet explorer did not have any favorites, Start>programs> had no programs
    Windows update does not work, System restore does not work

    I have 4 logs attached

    Thank You!...Guy
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Let's have you do an online scan:
    eSet Online Scan.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now run the C:\MGtools\FixAttr.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Guy Newton

    Guy Newton Private E-2

    First, thank you guys for your help!

    I ran Eset online scanner, found virus, and removed it, attached log

    Ran Mgtools, got Hijack this Message! : write access was denied the location specified. try a different location please.
    Also got this message "System information access denied" attached log

    Can't run windows update, I get this message, I check the settings and they are already set right.
    Please change your Internet Explorer security settings
    To save changes to your settings for this website, you need to enable userdata persistence for Internet Explorer. Complete the steps below, and then click Change settings to the left and try saving your changes again.
    In Internet Explorer, on the Tools menu, click Internet Options.
    Click the Security tab, click the Internet security zone icon, and then click Custom Level.
    In the Settings dialog box, scroll to the Miscellaneous section.
    Under Userdata persistence , select Enable.
    Click OK and when the security warning dialog box appears, click Yes.


    I can't load the new version of Microsoft outlook hotmail connector, > Insatllation of this package failed

    I can't sign in to Hotmail, I get this message
    Cookies must be allowed
    Your browser is currently set to block cookies. Your browser must allow cookies before you can use Windows Live ID.
    Cookies are small text files stored on your computer that tell Windows Live ID sites and services when you're signed in. To learn how to allow cookies, see online help in your web browser

    I check my settings, it is set to "allow all cookies"

    thanks again for your help...Guy
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run FixAttr.bat as requested? If not, please do so and tell me if it helped to unhide things.

    If you did run it already, again tell me if it helped to unhide things that were hidden in your Start Menu. You likely have many other folders on your drive that were hidden to and you may not have noticed yet.



    If you cannot find FixAttr.bat then this would mean you had a problem getting the new MGtools.exe to properly extract its files which could also mean the C:\MGtools folder permissions were changed by your malware.
     
    Last edited: May 13, 2011
  6. Guy Newton

    Guy Newton Private E-2

    My bad, I missed this part on your instructions. fixattr.bat is not in the c:\mgtools folder, so I cannot run it....:(
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try just downloading the new MGtools from the link given and save it to your Desktop.

    Can you do this?
     
  8. Guy Newton

    Guy Newton Private E-2

    Yes, done, do you want me to run it?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but I want you to run it a different way.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple & brown are merely informational.

    cd desktop <-- this changes to the prompt to your Desktop which should be C:\Documents and Settings\Guy\Desktop>
    MGtools <-- this will try to run the MGtools program. Tell me what error messages, if any, you see. Allow it to finish running before continuing.
    C:\MGtools\FixAttr.bat <-- this will try to run the FixAttr.bat fix that is part of MGtoos. Tell me what error messages, if any, you see. Be patient as it can take a long time to run because it has to loop thru all files and folders on your harddisk twice.



    Attach the C:\MGlogs.zip file that exists now. Also tell me if there is any change to the hidden status of your Start Menu programs.
     
    Last edited: May 14, 2011
  10. Guy Newton

    Guy Newton Private E-2

    I got 2 error messages while running MGtools:

    hijackthis:"write access was denied to location you specified. try a different location"
    System information "Access Denied"

    there is no file "C:\MGtools\FixAttr.bat" I also did a search on my c:\ drive for "fixattr.bat" there is no file.

    mglogs.zip is attached

    Thanks, Guy
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running an old version of MGTools!! That is why you cant find the fixAttr.bat.

    Download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and attach the new log.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!!!! Already requested multiple times!
     
  13. Guy Newton

    Guy Newton Private E-2

    working much better!

    all problems reported earlier are working. Also coudn't load new version of outlook connector, now loaded fine.

    attached mglogs.zip

    thanks for all your help

    Guy
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it helps when you use the correct versions of software. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Guy Newton

    Guy Newton Private E-2

    All done and working proper!

    Thank you!!:)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds