infected cleaned with your process But won't boot??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ericbg, Mar 30, 2012.

  1. ericbg

    ericbg Private E-2

    no now i can't boot .. only in safe mode: what do i should i do? when i try a regular boot i get to personal settings loading then i get windows desktop image but no icons and hour glass disappears and the hdd light is steady (lit up) but after 12 minutes still no icons??
    i had following errors when booted in safe mode..
    Bingbar\7.1.360 muex\7.1.360\BingBarSetup-partner
    and after sending mail from outlook..[shell Notify icon] failed to perform desired action.
     

    Attached Files:

  2. ericbg

    ericbg Private E-2

    i can't find the log for super spy. can u tell me where is and what its called. oh yea they're in notepad.i'll access and upload
     
  3. ericbg

    ericbg Private E-2

    here are the missing two files. i hope you can help. i may get a new hd as this one is major messed up.
    thank you for any help and advice
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Hello ericbg,

    There's not any malware in these logs but you still need to attach C:\MGlogs.zip (from running MGtools.exe)

    Also tell me what problems remain. Constant hard drive activity is not necessarily a symptom of malware. Usually it's a sign of hard drive corruption / failure or you simply running too many applications at once.
     
  5. ericbg

    ericbg Private E-2

    now i'm booting quicker: fastest yet:but my ftm (family tree maker) seems to be a little messed up. will check later today .. have an appointment soon. thanks for your reply.
    my hdd is messed up/corrupt. i seem to have two desktops .. one in root then one in docs and settings .. don't know if this is normal?
    Eric
    will send mgtools scan later today.
     
  6. ericbg

    ericbg Private E-2

    here's the mgclogs.zip file. i hope that this proves useful.
    thanks for any help,
    Eric
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the MGlogs.zip file that is located at C:\MGlogs.zip The one you attached is incomplete. The below two files which are in the MGtools folder were missing from the log
    Code:
    31/03/2012  08:22 AM           120,145 newfiles.txt
    31/03/2012  08:19 AM            68,489 runkeys.txt
    If it does not allow you too attach the MGlogs.zip file, then just attach the above newfiles.txt and runkeys.txt logs as there may have been a failure to ZIP them into MGlogs.zip
     
  8. ericbg

    ericbg Private E-2

    here are the other files .. i downloaded mgtools and ran again but it didn't create the MGlogs.zip.

    thanks for all your help. should i set a restore point now?
     

    Attached Files:

  9. thisisu

    thisisu Malware Consultant

    Not sure what you mean but your logs look fine. I don't see any desktop folders in the root of C: - which is good.

    You have some very light traces of malware.
    Do you know what this is file is for? C:\bst2E.tmp

    You can answer after you complete the below set of instructions

    __________

    http://img196.imageshack.us/img196/3557/tdsskiller.gif I want you to read and follow these instructions: TDSSKiller - How to run


    http://img684.imageshack.us/img684/6489/aswmbr.gif Please download aswMBR to your desktop.
    • Double-click aswMBR.exe to run (Vista/7 right-click and select Run as Administrator)
    • Select No when asked "Would you like to download latest Avast! virus definitions?"
    • Click the [Scan] button.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach)

    __

    http://img823.imageshack.us/img823/2039/msnmsg.gif Please download Disable/Remove Windows Messenger to your desktop.
    • Double-click MessengerDisable.exe to run it.
    • Place checkmarks in "Uninstall Windows Messenger" and "Hide Messenger from Outlook Express"
    • Click Apply
    • Click Exit

    http://img194.imageshack.us/img194/4930/combofix.gif Fixing items using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]ClearJavaCache::[/COLOR]
    [COLOR="DarkRed"]File::[/COLOR]
    C:\Documents and Settings\Eric\Local Settings\temp\BIT4CF.tmp
    C:\Documents and Settings\Eric\Local Settings\temp\BIT2.tmp
    [COLOR="DarkRed"]FileLook::[/COLOR]
    C:\bst2E.tmp
    [COLOR="DarkRed"]Folder::[/COLOR]
    C:\Documents and Settings\All Users\Application Data\{484395D8-1F9B-4C71-9DA9-A64CBD0E8DE2}
    C:\Documents and Settings\All Users\Uniblue
    C:\Documents and Settings\Eric\Local Settings\temp\BE5BA47218A64BA9BE144747CC598F62
    C:\Documents and Settings\Eric\Local Settings\temp\DFBB64AD3FA746A18571EFA59C541DDC
    [COLOR="DarkRed"]Registry::[/COLOR]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}]
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    http://softvisia.com/users/Night_Raven/Security/cfsdnd2.gif
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\ComboFix.txt
    Attach this log to your next message. (How to attach)

    http://img254.imageshack.us/img254/945/baticonxp.gif Now run C:\MGtools\GetLogs.bat by double-clicking it.
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  10. ericbg

    ericbg Private E-2

    don't know what that temp file u said i have is bst2E.tmp. i see it's pretty big.
    here are my scan files.
    during one scan most of my Family Tree maker files were deleted .. does that mean whatever i had infected them all or ancestry.com sent me a family tree file of one of my descendant trees was it infected? should i not run FTM?
     

    Attached Files:

    Last edited by a moderator: Apr 1, 2012
  11. thisisu

    thisisu Malware Consultant

    That was my fault. They are fine. Follow these steps to restore those files.

    http://img194.imageshack.us/img194/4930/combofix.gif Dequarantine using ComboFix
    Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it.
    If it is not on your desktop, the below will not work.
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    DeQuarantine::
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{484395D8-1F9B-4C71-9DA9-A64CBD0E8DE2}
    Quit::
    
    Save this file as CFScript.txt to your desktop. So now you should have both CFScript.txt and ComboFix.exe on your desktop.
    Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release.
    http://softvisia.com/users/Night_Raven/Security/cfsdnd2.gif
    This will launch ComboFix.
    Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    Allow ComboFix to update itself if prompted.
    When ComboFix finishes, a log will be produced at C:\DeQuarantine.txt
    Attach this log to your next message. (How to attach)
     
  12. ericbg

    ericbg Private E-2

    here's the file and thanks. when i just loaded Chrome it wouldn't connect so i de selected settings>predict. and now i have a connection as you can tell.
    i'm off to bed now.
    Eric:)
     

    Attached Files:

    Last edited by a moderator: Apr 2, 2012
  13. thisisu

    thisisu Malware Consultant

    Good job.
    The rest of your logs are clean.
    If you are still having a malware related issue, let me know - otherwise, you may proceed with the below:

    __

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Be safe :)
     
  14. ericbg

    ericbg Private E-2

    thanks for all of your help!
    but ... i can't run the code to uninstall Combofix. most likely 'cause i have a couple of Desktops. one where it should be .. another under docs and settings in folder housecalls6.6 and a blank one in docs and settings.
    i guess now is the time to format my drive and start with a clean new one.
    off hand do you know a program that will spit out my serial numbers of installed software?
    Eric thanks so much for all of your help!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That problem with uninstalling is because you put combofix.exe in the below location which is not your Desktop:

    c:\documents and settings\Eric\.housecall6.6\Desktop\ComboFix.exe

    The below is where it should have been:

    c:\documents and settings\Eric\Desktop\ComboFix.exe

    Move it to this folder and the run the uninstall.
     
  16. ericbg

    ericbg Private E-2

    yes, i know., but u may have overlooked part of one of my posts saying I have Two DESKTOP folders. one where it should be the other in docs and settings which i can't delete 'cause it says its a system file. i don't know how it got there or how to remove it other than formatting disk.
    any suggestions?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No, I did not overlook it. The folder I gave you is still what your Desktop folder should be. Put ComboFix.exe in that folder and then run the uninstall.

    Then do the below. Click Start, Run, and copy and paste the below into the Run box and click OK .

    cmd /s dir /s "c:\documents and settings\Eric\.housecall6.6\Desktop\*.*" > c:\flist.txt


    Then attach the C:\flist.txt file which should have been created.
     
  18. ericbg

    ericbg Private E-2

    ok, i didn't want to start an argument i was just making a statement that i thought might help .. i guess i didn't look at the code carefully.
    so, i tried to uninstall combofix.exe from the desktop but when i click o.k.an error window comes up saying "can't find the file in Docs and settings even though i didn't copy that path into run.??:confused
    so what now?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please just finish what I requested in my last message!

    - Run the command I asked you to run and attach the file.

    Also you said you retried uninstalling ComboFix. Does the below file exist?

    c:\documents and settings\Eric\Desktop\ComboFix.exe
     
  20. ericbg

    ericbg Private E-2

    thank you.
    i didn't put the combo.exe in the above folder ..it just went there. it seems i have a mirrored desktop.
    i tried with the command to uninstall combo fix from desktop but it says that it can't find the file in doc and settings even though that's not the path i used!:confused! there is a file combofix in the docs and settings (C:\Documents and Settings\Eric\.housecall6.6\Desktop) desktop folder. i'm stymied as to what to do??
     
  21. thisisu

    thisisu Malware Consultant

    Hi,

    I attached a .zip file to my post: uninstall.zip
    • Inside of it is uninstall.bat
    • Copy/extract uninstall.bat into whichever folder ComboFix.exe is in
    • Then double-click uninstall.bat to run the batch (.bat) file.
    • This should launch ComboFix (acts like it wants to run), but it will uninstall ComboFix instead.
     

    Attached Files:

  22. ericbg

    ericbg Private E-2

    alllright! at last i unzipped and ran uninstall ..something flashed by in a fraction of a second but Combofix was still there. restarted xp then right clicked combofix in housecalls6.6 folder saw terminate listed in drop down .clicked it and it uninstalled both combofixes from both desktops.
    do you know how i can now uninstall the desktop from the folder housecalls?
    thanks for your tenacity and solving this issue.
    ericbg :)
     
  23. thisisu

    thisisu Malware Consultant

    Double-check that uninstall.bat and ComboFix.exe are in the SAME folder/directory.

    If they are in the same directory, both ComboFix and a dos command prompt will launch.
     
  24. ericbg

    ericbg Private E-2

    here's the file i was requested to send a few days ago by chaslang.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but no that is not what would be in the flist.txt file. You need attch the actual c:\flist.txt file.
     
  26. ericbg

    ericbg Private E-2

    Ran the script again and it gives back a blank txt file. perhaps something more major is going on?
    Ericbg
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not attaching the C:\flist.txt file. You are just attach a copy of what is in the command prompt window which is not what we want. You appear to be making the flist.txt file yourself by copying and pasting what is on your screen.

    Download and save the below anywhere that you can easily find it. Then double click it to run it.

    List.bat

    Once it finishes, it will open the c:\flist.txt file in notepad. Attach this log.
     
    Last edited: Apr 7, 2012
  28. ericbg

    ericbg Private E-2

    i am trying to run it. but nothing happens. with the new file it captured the contents and here's the file. btw i didn't create or the file by copying and pasting. i now hope we can get some where.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like you some how managed to change where your desktop is located and you have moved your Desktop folder into the .housecall6.6 folder

    Just move it back where it belongs. That is move everything from here:

    c:\documents and settings\Eric\.housecall6.6\Desktop

    Back to here:

    c:\documents and settings\Eric\Desktop

    And then to fix the Desktop folder path, do the below. After a reboot it should be okay if the patch runs properly


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
    Last edited: Apr 8, 2012
  30. ericbg

    ericbg Private E-2

    ok it worked But i didn't see all of your message until after i renamed doc desktop to desktop1 then moved desktop to that folder. omg did i mess things up? i'm in to much of a rush.
     
  31. thisisu

    thisisu Malware Consultant

    Not sure if you messed up anything or not without a new set of logs but were you ever able to place both ComboFix.exe and uninstall.bat in the same directory/folder?
     
  32. ericbg

    ericbg Private E-2

    yup, and it got rid of ComboFix by right clicked icon and selecting terminate.
    :)
     
  33. thisisu

    thisisu Malware Consultant

  34. ericbg

    ericbg Private E-2

    Thank you.
    now it seems to boot for 13-14 minutes before i can open an application.
    Should i start a new thread and scans?:cry
     
  35. thisisu

    thisisu Malware Consultant

    I do not see the point in doing that since your latest logs were clean.

    It sounds like you have an intermittent hardware problem to me.

    We have a couple of forums that would be better suited with your remaining issues: Hardware and/or Software.

    Good luck :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds