Having a lot of problems....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jimfettig, Dec 26, 2011.

  1. jimfettig

    jimfettig Private E-2

    This started about two weeks ago.

    Ran all the scans and still having issue.

    I ran the scans twice once and and it removed a lot of cookies and stuff. Then everything seemed normal so I never proceeded.

    Then then I ran the scans again and it found the SAME issue the second time around. Supper Antispyware still finds tons of cookies after CCleaner has already done scans.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please attach the MGlogs.zip from running MGTools.exe. Thanks.
     
  3. jimfettig

    jimfettig Private E-2

    I am sorry. I forgot to add that it wont go through the mgtools scan. Just stops.

    I have tried every possible way suggested and it never continues. I left it over night and nothing.

    UAC is turned off and I have tried running this scan multiple times.

    I even tried using DisableUAC.reg to insure that UAC was off an still no luck.

    If you have any other suggestions I will try.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.

    If that does not produce a C:\MGlogs.zip then please run the below.

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. jimfettig

    jimfettig Private E-2

    It seems to do be doing the same thing again.

    Just hangs up but never progresses.

    Here are the errors....

    When running NWKTST...

    Access Denied....

    NWK is not recognized as a internal or external command, operated program or batch file

    Could not find runkeys.txt

    I am also getting all sorts of virus alerts from Vista Home Security 2012....
    Security Breach alert...

    I have never seen anything like this till the problems started.
     
  6. jimfettig

    jimfettig Private E-2

    OTL Results....
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    From your MalwareBytes log, you need to fix this if you have not already.
    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    Code:
    :files
    C:\ProgramData\o6h0o33a6217egbvi2
    C:\Users\Jim\AppData\Local\o6h0o33a6217egbvi2
    C:\Users\Jim\AppData\Local\k1br65e4mg5xxg
    C:\ProgramData\k1br65e4mg5xxg
    C:\ProgramData\6m55df0j81e776
    C:\Users\Jim\AppData\Local\6m55df0j81e776
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now run OTL again like you did in post number 4 and attach the log from that too.

    Run this please Check your hard disk for errors

    Now tell me if you can run MGTools now. Also let me know how things are running for you at this point.
     
  8. jimfettig

    jimfettig Private E-2

    Still have the windows vista 2012 virus alerts issue.

    Removed ....backdoor.bot

    Ran OTL and it never gives me an extras.txt file.

    Tried twice and no go.

    MGtools still hangs...

    Here are the scans.
     

    Attached Files:

  9. jimfettig

    jimfettig Private E-2

    The computer will not longer let me on the internet.

    It says that there is a threat. I am sure it all related to this Windows Virus 2012 and after doing some research turns out a lot of people are having this virus go through there system.

    My version of the virus may not be allowing me to delete stuff.

    When I run CCleaner again it says I have cookies. If I cannot get on the internet then how could I be getting cookies.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these files.

    C:\Users\Jim\AppData\Local\o6h0o33a6217egbvi2
    C:\ProgramData\o6h0o33a6217egbvi2

    Reboot and check they are still gone.

    Are you now able to connect? :confused
     
  11. jimfettig

    jimfettig Private E-2

    Removed in Safe Mode.

    Reboot and still there.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Users\Jim\AppData\Local\o6h0o33a6217egbvi2
    C:\ProgramData\o6h0o33a6217egbvi2
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Are the files gone or still there. Can you connect to the internet now?
     
  13. jimfettig

    jimfettig Private E-2

    Here is log.

    Yes now I can log in.

    I tried manually removing the files again as you suggested previously. Worked that time.

    I still went through the OTM process you suggested anyways.
     

    Attached Files:

  14. jimfettig

    jimfettig Private E-2

    Did the same procedure you recommended before and it worked the fourth time around.

    The only thing I did was turn off my WIFI. I guess I was still connected to the internet but Firefox and Explorer would not let me on.

    I still went through the OTM process.

    Here is the log.

    Btw...not getting the virus alerts by window right now.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run OTL again like you did in post number 4 and attach the log.
     
  16. jimfettig

    jimfettig Private E-2

    There you go.
     

    Attached Files:

    • OTL.Txt
      File size:
      48.6 KB
      Views:
      2
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. jimfettig

    jimfettig Private E-2

    Thank you

    I will go through the process and if anything pops up I will let you know.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing!
     
  20. jimfettig

    jimfettig Private E-2

    OK....went through all the steps and I think I found the cause of all my problems.

    I have never been able to install Vista Service Pack 2. It still will not allow me to do it no matter how I try.

    First I tried updating and then I tried downloading service pack 2 and installing manually. Still no luck.

    If I ignore this I will continue to have issues.

    Any idea how I can fix this?
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is topic for the software forum. You should let them know of the exact error message when that update fails you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds