After Removing Spyware Fix etc. Problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by susieq29, Dec 3, 2011.

  1. susieq29

    susieq29 Private First Class

    Good morning. Yes to all questions. Running mg tools now.
     
  2. susieq29

    susieq29 Private First Class

    Thanks for all the help and staying with me on this.:wave
    Attached is log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay that looks better as far as the infected partition goes. It is gone now. ;)

    Now we just need to figure out what is stopping the BFE service from running which in turn disable firewall capabilities.

    I'm looking through your most recent logs to see I find anything else wrong. This BFE issue is troubling right now and is happening to many user's coming here with infections now. It is a plague with no easy fix. At least not yet.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay your registry entries are missing for the BFE and MpsSvc services.

    Now run the C:\MGtools\FixWFW.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). This will run very fast.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  5. susieq29

    susieq29 Private First Class

    I do not have MgTools fix file?
     
  6. susieq29

    susieq29 Private First Class

    Never mind found it.
     
  7. susieq29

    susieq29 Private First Class

    Here you go.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That did not work. The registry keys did not get imported. They may be locked.

    With Windows Explorer, navigate to the C:\MGtools\fixW7BFE.reg file and right click on it and select Merge. Allow it to be added to the registry. Does this seem to work or do you get an error message?
     
  9. susieq29

    susieq29 Private First Class

    Cannot import C:/MGtools/fixSBM.reg. Not all data was successfully written to the registry. Some keys are open by the system or other processes.
     
  10. susieq29

    susieq29 Private First Class

    Just did it again and it worked said it was successful.
     
  11. susieq29

    susieq29 Private First Class

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not the file I asked you to merge in.
     
  13. susieq29

    susieq29 Private First Class

    I know I hit the wrong file got an error. Then I hit the right file you told me to hit and it worked. Sorry
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so it said it worked. Then let's see.

    Now run the C:\MGtools\GetNetInf.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log which should get updated:
    • C:\MGlogs.zip
     
  15. susieq29

    susieq29 Private First Class

    Here you go
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that added in part of what we wanted. Now do the below. Be careful of the filenames!!!!!

    With Windows Explorer, navigate to the C:\MGtools\fixW7FW.reg file and right click on it and select Merge. Allow it to be added to the registry. Does this seem to work or do you get an error message?


    With Windows Explorer, navigate to the C:\MGtools\fixW7FWdrv.reg file and right click on it and select Merge. Allow it to be added to the registry. Does this seem to work or do you get an error message?


    If the above worked without any errors, run the C:\MGtools\GetNetInf.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log which should get updated:
    • C:\MGlogs.zip
     
  17. susieq29

    susieq29 Private First Class

    Here it is. They both worked
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes they did now we have more to add.

    Download the below file and save it to your Desktop

    fixlegacy.reg

    Then double click on it and allow it to be added to your registry. I'm betting there may be error messages this time! If you received an error, stop here and tell me.

    If no error messages occured, then reboot your PC.


    After reboot, download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. susieq29

    susieq29 Private First Class

    error accessing the registry
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I expected that. Hangon a few minutes. I working on something to help.
     
  21. susieq29

    susieq29 Private First Class

    Ok I am hanging on this long what's a few more minutes:drool
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I want you to download and save the below to your Desktop
    Then double click on it to install the RegistrarLite program.

    Now run the RegistrarLite Program and copy and paste the below into the address bar line and hit enter

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root

    It will look like the below

    http://forums.majorgeeks.com/attachment.php?attachmentid=170228&thumb=1&d=1323728408

    • Then click on Security on the top menu and select Take Ownership
    • Then click on Security on the top menu and select Edit Permissions
    • On the next form, in the Group or user names: section, make sure Everyone is selected. Then in the bottom pane where it says Permissions for Everyone, put a check in the Full Control box and make sure it changes. It should look like the below when done correctly
    http://forums.majorgeeks.com/attachment.php?attachmentid=170229&thumb=1&d=1323728408

    Now repeat the same to Take Ownership and Edit Permissions after pasting the below into the address bar and hit enter

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE

    http://forums.majorgeeks.com/attachment.php?attachmentid=170230&thumb=1&d=1323728408

    Let me know if you are able to get the above completed.
     
    Last edited: Dec 12, 2011
  23. susieq29

    susieq29 Private First Class

    The secuirty take ownership is not available. Also when I opened the the page does not show the files. It shows my registry list and the under name it is the closed files. Which registry do you want me to choose to get to root
    like the picture.
     
  24. susieq29

    susieq29 Private First Class

    I pasted the address do I have to press go first them do the security tab?
     
  25. susieq29

    susieq29 Private First Class

    I can't get past pasteing the address in.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry if that was not clear. After pasting in the address, you have to either hit enter or click the green go button so that it navigates to the line in the registry. Sort of like using your bowser. When you enter a URL, you have to hit enter or go.
     
  27. susieq29

    susieq29 Private First Class

    I did hit enter and nothing happened and I hit go and the address disappeared
     
  28. susieq29

    susieq29 Private First Class

    Ok when i hit enter here's what I see
    I see under the HKEY LOCAL Machine
    RED FOLDER BCD00000000
    HARDWARE
    SAM
    RED FOLDER SECURITY
    +SOFTWARE
    SYSTEM FOLDER (WITH NO + OR - CLOSED)
    HKEY_USERS

    oN LEFT SIDE IS ALL HKEY FOLDERS CLOSED
     
  29. susieq29

    susieq29 Private First Class

    correction of last line. I mean on right side is all HKEY folders
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you copy and paste in the line to avoid typing mistakes. You must paste in EXACTLY the below

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root

    then hit enter. The snapshot I gave you shows how it should look. It should come up in the left window pane with the Root folder selected and expanded.

    Your other choice is to manually naviagte to the folder yourself and once you have the Root folder properly selected, it will show the full path in the address bar too.

    If this does not work, it could be that Registrar Lite is not compatible with Win 7
     
  31. susieq29

    susieq29 Private First Class

    I have tried navigating to the folder and it is empty there is nothing there.
     
  32. susieq29

    susieq29 Private First Class

    I can select system and press ownership
     
  33. susieq29

    susieq29 Private First Class

    I tried selecting just system and pressing ownership got message a device attached to the system is not functioning.

    I pasted and copied the address three times this is not working.
    When I try and open folders nothing show's below them and to the right it just says default
     
  34. susieq29

    susieq29 Private First Class

    I also tried typing in address that does not work either.
     
  35. susieq29

    susieq29 Private First Class

    I can see the keys in my registry on my computer. This software for some reason is not letting me open the files.
     
  36. susieq29

    susieq29 Private First Class

    Registry Lite does not seem compatible with window 7 64. I can go to my registry if we can work from there and change permissions.
     
  37. susieq29

    susieq29 Private First Class

    I see on line registrar registry manager 7.00 says it compatiable with windows 7 lite version. The other one you gave me is definetly not compatible with windows 7. It says it on the about page.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are you running????? This is not what I asked you to install. The link I gave you is to Registrar Lite version 2.0 not Registry Manager 7.00. I don't know what you are running.

    And we double checked. Registrar Lite 2.0 work on Win 7. It may not be 100% compatible but it works well enough to follow the directions I gave. The only thing that may be missing is the "Everyone" user account since some people do not have this by default.
     
  39. susieq29

    susieq29 Private First Class

    I am not running anything else. I am running what you gave me it is not compatible with windows 7 and does not work. I was looking on line to see if I could find one that was compatible with windows 7.
     
  40. susieq29

    susieq29 Private First Class

    Well I read your e-mail and it is not working.
     
  41. susieq29

    susieq29 Private First Class

    I have windows 7 64. I don't know it is just not letting me do anything.
    I am pretty good with computers and I can tell you the problem is with the software on my computer.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We tried it on Win 7 x64 and it ran, but the compter obviously did not have the infection you have. Whether that is the problem or not I don't know.

    Would you like to try a remote access program named TeamViewer? Perhaps I can get in and see what is going on
     
  43. susieq29

    susieq29 Private First Class

    I would love remote access. I am away from my computer now. Tomorrow my electric will be off till late in the day about 3 oclk my time. I can go on with you then. Will that work?
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. I'll be at work still. I just happened to be home today. ;) I don't get home until 9 pm or so my time ( about 6 pm your time ). So we would have to wait until then or later.
     
  45. susieq29

    susieq29 Private First Class

    I will get on tonight my time around 7:30. If your on fine if not I will be on tomorrow when you are home.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PHP:
    Okay. I'm hoping to try this with another person now so we can find out what is going on with this infection.
     
  47. susieq29

    susieq29 Private First Class

    I am on my way home,I just want you to know I did try another software that opened all the files and would have allowed me to select what you wanted. But it needed to pay for it to get it to accept the selection. Page showed all the files you were looking for.
    When I copied your address it opened all the files
    It might have something to do with the version of 7 I am using.
     
  48. susieq29

    susieq29 Private First Class

    I am home if you are still available
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just finished up TeamViewer with another person.

    You need to download and install the below

    TeamViewer

    Select personal account because that is free for non-businesses. Once you get it setup. PM me your TeamViewer ID and Password and I'll try to connect to you.

    Keep checking messages here until we get connected.
     
  50. susieq29

    susieq29 Private First Class

    Ok will do
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds