almost completed read me perfectly...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by babbaroni, Jun 3, 2011.

  1. babbaroni

    babbaroni Private E-2

    Thanks for being here, and providing everything you do!!!

    I have followed all of the directions in the READ ME AND RUN THIS FIRST. I've disabled all of the security programs, etc. I could find, and do not have any AV program installed. Everything has worked the way the forum said it would except fot MG Tools. I did put it in C:\ and ran it as administrator, and it did make itself a folder... and a command prompt window appeared for a split second. When I right click the GetLogs.bat file and click run as administrator, the same thing happens... a command prompt appears so briefly I can hardly even tell what it is, then, nothing. I also tried running it, after doing that a few times, from the desktop, as administrator. Same thing.

    My original problem was clicking OK on a request to run a flash add-on. That apparently gave me Windows Recovery, which soon revealed itself in a series of false warnings, which I ignored, and finally found and deleted the program. but it had apparently invited some friends over, and soon my computer was visiting random web sites (I've used IE for many, many years, and I think it's working through that... I'll explain further soon...). Oddly, it also rearranged the shortcuts in my task bar. I ran MalwareBytes, and something else, and they cleaned about 11 things but then it started accessing the sound, only, of random sites (I kept some records of which ones, etc.) and logging the sites in IE's history. It deleted all of my bookmarks (favorites).

    Now it has mutated to running IE invisibly (I find it running in Task Manager), and not logging the sites visited. Sometimes there is sound, usually not.

    It also deleted the URL's in all of the internet links I had saved on my computer (even in folders within folders).

    OK, now I'll see if I can figure out how to attach the logs from the programs that DID run... there, hope that worked. My (very computer literate, adult) son ran a few things last week and made at least one log... let's see... catchme.log. Do you want that?

    Thanks again! -- bab
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.

    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  3. babbaroni

    babbaroni Private E-2

    Thanks, TImW.

    My command prompt is just the cursor, and no matter what I type, I still just get a blinking cursor. No indication of what drive it is, etc.

    And I forgot to mention that I can't get email, now. :-/

    My son will be here in a few minutes and may be able to help me with the command prompt... it's been a long time since I've used that.

    WAIT ... I'm managing to use it without the regular prompt. BRB

    OK --- "the system cannot find the path specified", with either command you suggested.
     
    Last edited: Jun 3, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where you able to open the Administrator command prompt? Did you download MGTools to your C: drive ( assuming that is the root folder )? Did the directory change to C:MGTools?
     
  5. babbaroni

    babbaroni Private E-2

    Thanks for your quick response. Yes, I opened the command prompt as admin, and it said so at the top, and I found out which drive/directory/folder I was in by using dir, and I got into the one that MGtools had created when I ran it, right in C:. The getrunkey.bat and shownew.bat files were in there, but the computer ignored the commands. We were mystified. Still no normal prompts, but I could tell which drive I was in by using dir.
     
  6. babbaroni

    babbaroni Private E-2

    Omigoodness, all of my favorites/bookmarks are back, and when I save a link to my dektop it's no longer "empty". Also, IE has not started running on its own, invisibly, since at least early yesterday. I think, MAYBE, one of the steps in READ ME AND RUN THIS FIRST got rid of "my" malware! Thank you!

    How can I be sure? Should I just assume it's gone if nothing else weird happens, or can you tell frm one of the logs?

    Oh... and what about that Command Prompt problem? Let me see if it's still happening, since I shut down over night and turned it on this morning... WOO-HOO!!! I have a normal command prompt! By cracky, I think you guys have done it!!! Thanks for posting all of that. God bless you all.
    "Pastor Barb"
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'd still like to check things. Please download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  8. babbaroni

    babbaroni Private E-2

    Will do. Sorry, tied up most of today. Thanks for your patience.

    I wonder if I can even run MGtools now. I'll give that a try, too.
     
  9. babbaroni

    babbaroni Private E-2

    Here are the results of the OTL scan, done as you directed. Also, I was able to run that getrunkey batch file in MGtools from my now-normal C prompt, and am attaching those results as well. Should I run anything else from MGtools?

    Thanks for your help -- I see there is still some kind of problem -- with the event log or something like that.

    --Babbaroni
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware issues in those logs. Can you try getting a full MGLogs.zip by running the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    What issues are you still having?
     
  11. babbaroni

    babbaroni Private E-2

    I haven't noticed anything misbehaving for over 24 hours, now.

    OK, I ran getlogs.bat, and have attached MGlogs.zip.

    HiJack reported an error; asked me to report it, and I clicked OK; then Trendsure customer help window opened in IE. AFter a few minutes, I closed that, but not the command prompt window. I waited until it was done, and it said "hitting any key will close this" etc and then did so.

    Way back during the guide and tutorial on using ComboFix, (I
    thought it was during CClean, but I must have remembered wrong,
    because my note is on the ComboFix pages I printed)
    a message said "driver VOLSNAP.SYS is patched with a rootkit;
    attempting disinfection" -- which it apparently did, and then
    instructed me to reboot, which I did, and then it resumed.

    So... could that have been causing all the mayhem? Because I didn't see a thing, after that, indicating that anything else had been discovered (that I can recall). I just don't remember everything being fine from that moment... it seemed to happen later. But I may be mistaken.

    Thanks so much for your help!
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, it could have been the main cause of your problems:
    .

    The rest of your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  13. babbaroni

    babbaroni Private E-2

    Omigoodness, that's a lot left to do! I'm startled! Not complaining... just startled. I'll get started now.

    I looked up "rootkit" and I was flabbergasted at what they can do.

    Again, thanks a million... and I intend to put my money where my mouth is (just need to decide which way).

    Babbaroni
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not really, as it all cleans up pretty quickly. And yes, rootkits can be a real pain.

    You are most welcome. Safe surfing. :)
     
  15. babbaroni

    babbaroni Private E-2

    I have to make a confession. I did not do one part of the clean-up. Since the only way I can make Microsoft Security Essentials stop working is to uninstall it, and I had just reinstalled it, I didn't "disable" it before uninstalling ComboFix.

    Do I need to redo anything? Will that come back and bite me in the butt?

    Thanks for your patience,
    babbaroni
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, you should be fine. As long as Combo has been removed, your good. ;)
     
  17. babbaroni

    babbaroni Private E-2

    Can I send a donation via PayPal?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  19. babbaroni

    babbaroni Private E-2

    Oh, dear, I fear the rootkit may have left a shadow behind...

    I recently upgraded to IE 9, but nothing I do (including some lame suggestions from a MS help forum) will make the "open previous browsing session" function work. It's always grayed out.

    They had me uninstall IE9 , and told me to reinstall it. But while it was uninstalled, I opened IE8, and it's grayed out in that, too, under Tools, and doesn't appear at all in the New Tab page.

    When I went to look for the link I had saved to this thread, it was only a file consisting of the name of the thread; no link. Maybe a fluke, because all of my other links are still OK.

    What do you think?

    Thanks in advance for any input,
    babbaroni
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    These sound like issues that you should address in the software forum. Do you have any problems with using a different browser, say FireFox?
     
  21. babbaroni

    babbaroni Private E-2

    No... but the rootkit did not affect Firefox. And it did hide aspects of IE.

    So, I'm thinking it worked/s through IE, and a bit of it is still on my PC somewhere, and becoming active, in this new way. It did "mutate" quite a bit before apparently being removed the last week or two.

    When I tried to work through the issue with MS support, they gave up pretty easily. But, I will open a thread on the software board, as you suggest.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see what they say in software. I will try to keep an eye on your thread there. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds