Malware Problems - Logs Attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fingolfin05, Nov 8, 2013.

  1. Fingolfin05

    Fingolfin05 Private E-2

    Hello,

    I am having some problems with my computer, which I think is a result of malware. I noticed the problem around a month ago after I had trouble opening programs.

    I went through all steps but was unable to install the defogger. I've attached the logs.

    Thank you for the help!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    I am not seeing any malware in those logs. What problems are you experiencing specifically, right now?
     
  3. Fingolfin05

    Fingolfin05 Private E-2

    Thanks for the response.

    Many of my programs don't open. Most of the new programs that I have tried to install show an error message during install (Firefox 25, new private firewall update, defogger). Also, Windows Update will not install new updates.

    Let me know if you need any more information!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What error message exactly? (I may need to refer you onto the software forum)
     
  5. Fingolfin05

    Fingolfin05 Private E-2

    Here is the error message from the private firewall setup launcher:

    Problem signature:
    Problem Event Name: InPageCoFire
    Error Status Code: c0000185
    Faulting Media Type: 00000003
    Damaged file name: msacm32.dll
    OS Version: 6.1.7601.2.1.0.768.3
    Locale ID: 1033
    Additional Information 1: 4c0d
    Additional Information 2: 4c0d4d78887f76d971d5d00f1f20a433
    Additional Information 3: 4c0d
    Additional Information 4: 4c0d4d78887f76d971d5d00f1f20a433

    I then get a message saying this: "The application was unable to start correctly (0xc0000006). Click OK to close the application."

    I get a similar message with Windows Update, saying windows installer has stopped working. It says this when I click on more information:

    Problem signature:
    Problem Event Name: InPageCoFire
    Error Status Code: c0000185
    Faulting Media Type: 00000003
    Damaged file name: msacm32.dll
    OS Version: 6.1.7601.2.1.0.768.3
    Locale ID: 1033
    Additional Information 1: 4c0d
    Additional Information 2: 4c0d4d78887f76d971d5d00f1f20a433
    Additional Information 3: 4c0d
    Additional Information 4: 4c0d4d78887f76d971d5d00f1f20a433
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does it help if you run this?

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    Now can you install those programs?
     
  7. Fingolfin05

    Fingolfin05 Private E-2

    Thank you so much for the reply. I ran the scan, but I am still having the same problems.

    While running the scan I received this error message several times: "Microsoft(C) Register Server has stopped working.

    Problem signature:
    Problem Event Name: InPageCoFire
    Error Status Code: c0000185
    Faulting Media Type: 00000003
    Damaged file name: msacm32.dll
    OS Version: 6.1.7601.2.1.0.768.3
    Locale ID: 1033
    Additional Information 1: 4c0d
    Additional Information 2: 4c0d4d78887f76d971d5d00f1f20a433
    Additional Information 3: 4c0d
    Additional Information 4: 4c0d4d78887f76d971d5d00f1f20a433
    "

    I simply exed out the message and it allowed the scan to continue and finish.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It would be best if you posted about this in the software forum. :) One thing to try before you do so:

    Try the below:

    Download a fresh copy of Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop on the PC with the infection.

    • Open up this newly created folder and then open the "files" folder (...\windows repair v1.5.7\files)
    • From here, locate the fix_exe_hijack.inf file and then Right-mouse click it one time, then choose "Install".
    • Once you have done this, you should now be able to open applications again.
    • Let me know if that helped, can you now get through the rest of the read and run me first?
     
  9. Fingolfin05

    Fingolfin05 Private E-2

    Okay! Thank you for the help! Good to know I don't have to worry about the malware at least.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One last thing to try, seemy last post, after refreshing page.
     
  11. Fingolfin05

    Fingolfin05 Private E-2

    I followed the instructions but still no luck with opening applications. Thanks again for the help!
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. Hope you get it resolved. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds