Working thru Read & Run, logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jacknscoob, Mar 2, 2012.

  1. jacknscoob

    jacknscoob Corporal

    Hi Guys

    I have worked through Read & Run.

    Results:

    - SAS log attached

    - MG log attached

    - Malwarebytes - 'No malicious items were detected'

    - RootRepeal - I was unable to open a 'rar' file, it asked me to chose a program to open it with, wasnt sure which one. I could try the 'zip' file, however I could not find this to download

    - Combofix.exe - said 'Installer integrity check has failed. Common causes include incomplete download & damaged media.' (However, visually the file looked like it had downloaded OK)

    I await for your instructions.

    Thankfully, Kipfeet has reminded me not to 'try and fix things on my own' :). However, I guess just using the web (no downloading etc) is OK. Plus I have put my firewall back on & Trend is back running.

    Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What malware issues are you having.

    Do you know what this is:
    C:\ProgramData\4308

    You need to clean out this folder:
    C:\Users\Froglet\AppData\Local\Temp\
     
  3. jacknscoob

    jacknscoob Corporal

    Hiya

    C:\ProgramData\4308 - I dont know what this is.

    The problems I have had are at: http://forums.majorgeeks.com/showthread.php?p=1718222#post1718222

    Summary
    IE & internet crashed. SAS found lots of threats. Threats successfully removed. Internet working via Safari. After unwise DVD Flick download. Another threat downloaded. SAS removed. IE still not working. Unable to download a new IE (to repair). Itunes error 'connection timed out' (cannot download apps) continues to exist. Apparently, IE assists iTunes in downloading. iTunes said error cant be repaired, go to computer shop as they think Windows is corupted.

    Await next instructions :)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you should be safe to delete it.

    No, it only found two cookies.

    Are you still missing your desktop icons? If so, please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?
     
  5. jacknscoob

    jacknscoob Corporal

    Hi Guys

    Whatever I have been doing to my computer, great progress has been made. My recent SAS scans show no threats (only tracking cookies), however earlier scans showed about 70 threats which I believe that CCleaner deleted before I could save and publish it (prior to Read & Run).

    However, iTunes now works (no connection timed out error):)

    I have downloaded Firefox as a back-up browser.

    Internet works great.

    I can see my desktop icons and they work however they are greyed out.:confused Should I do the 'grinler' download still ?

    I have learnt soooooooo much from this forum. Thankyou all.

    Where do I stand now re CCleaner? Or deleting any 'temp' files to have a clean up?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run Unhide to be on the safe side. Do not run any cleaning programs such as CCLeaner yet.

    After running Unhide, tell me if the icons are still greyed out.
     
  7. jacknscoob

    jacknscoob Corporal

    Hi Guys

    For info. When I did my initial 1st-ever SAS full scan 19 Feb, I had about 70 threats, but the file log was deleted somehow. I cannot recollect the kind they were as I thought I would be seeing the file again. After SAS, I did a mbam full scan (I tried to attach to here), it is at http://forums.majorgeeks.com/showthread.php?t=253637&page=2 #29

    Somehow things have got back to normal.

    Only outstanding issues are:

    1. Desktop icons have disappeared after 'hide hidden files' (except recycle bin)
    2. On re-starting computer error msg: Catalyst Control Centre : Host application has stopped working

    I know u guys are busy and the above arnt really a problem, however let me know if there is anything else you would like me to do or not if thats the case.

    Thanks Guys
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  9. jacknscoob

    jacknscoob Corporal

    C:\MGlogs.zip attached
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not seeing much. You may just have to put the shortcuts back on your desktop.

    But let's remove some junk:

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  11. jacknscoob

    jacknscoob Corporal

    Avenger & MGLogs attached.

    Internet working absolutely fine.

    On re-starting computer error msg: Catalyst Control Centre : Host application has stopped working is still there.

    Re my desktop icons, should I delete all the greyed out ones 1st and start again?

    Thankyou:)
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you post in the software forum for assistance with that issue.
    You can first try just right clicking your programs and see if you can send them to the desktop. Then you will know if you need to remove the greyed out ones.

    And you are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  13. jacknscoob

    jacknscoob Corporal

    Hi Tim, Hi Guys

    My internet is working great now + downloads. All good.

    During my interaction with geeks I was advised to not use CCleaner because of my then problems. I have a 320GB hard drive and it is 'in the red', only a few GBs free on each drive (I have a split HD, 3 GBs free on 'C' and 4 GBs on 'D').

    I have deleted any unwanted software and have deleted temp internet files and some other files.

    Looking at my drives I see folders and files I do not recognise, some files eg. K51AC.BIN is 1MG and so on. I think I need a clean up but want to keep all my passwords / favs etc.

    Also, is there an easy way to delete duplicate files (eg photos & movies), without going wrong?

    Sorry to bother you guys again. I am happy to repost these queries elsewhere if that is appropriate.

    Thankyou :)
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest you post those questions in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds