Can't get any tools to run.

Discussion in 'Malware Help (A Specialist Will Reply)' started by jrvoodoo, Oct 1, 2009.

  1. jrvoodoo

    jrvoodoo Private E-2

    I've tried the read and run me first and can't get anything to run fully. Antivirus programs appear to install but then never fully run and the executables are disabled. After uninstalling virus programs the executables then cannot be deleted. Have tried pretty much everything I could find on majorgeeks and nothing works. Spybot, malwarebytes, super antispyware, mgtools, adaware, antivir, avast, avg, etc. Since nothing will run I haven't been able to get any log files either. I may have a couple partials which I will attach. Please help me I'm not sure where else to start next.
     
  2. jrvoodoo

    jrvoodoo Private E-2

    I tried running mgtools in safe mode and will attach the logfile.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Step 1:
    Let's try to download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double-click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.

    Step 2:
    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Step 3:
    Next, try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Step 4:
    Now run a new scan with MGtools: Using MGtools

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    *The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  4. jrvoodoo

    jrvoodoo Private E-2

    I tried your suggestions while in safe mode with antivirus off. The antivirus I was using was comodo internet security and it had already been disabled by whatever is infecting my system.
    I ran avpfind and the black command prompt window never closed. I attached the avp log.
    I ran exehelper and attached the log.
    Superantispyware loaded and started scanning then abruptly quit after about 45 seconds. I could not find any log.
    I ran mgtools and it seemed to run way too fast and I could not find a log.
    I also attached an avenger log from before.
    Thanks for your time.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, jrvoodoo

    Step 1:
    You must disable Spybot's TeaTimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    Step 2:

    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Step 3:

    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:

    Now run Win32kDiag per the below:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r

    Step 6:
    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator ) Make sure that you accept the license agreement for TrendMicro HijackThis if it popups up. You must click the Accept button twice.

    Step 7:

    Please attach the below logs to your next reply:
    • the log from exeHelper
    • C:\avenger.txt
    • Win32kDiag.txt
    • C:\MGlogs.zip
    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited by a moderator: Oct 11, 2009
  6. jrvoodoo

    jrvoodoo Private E-2

    Step 1: Spybot has previously been uninstalled along with teatimer so neither should be running on my system. I could not open spybot to disable teatimer.

    Step 2: ExeHelper appears to have run and I will attach the logfile.

    Step 3: Followed install directions for avenger.exe. When I got to the execute step I received and error message. Error: Invalid script, a valid script must begin with a command directive. Aborting execution.
    Did not work so I have no logfile to attach.

    Step 4: Ran CCleaner

    Step 5: Ran Win32kDiag and will attach logfile.

    Step 6: Ran mgtools. Window opened and closed immediately. Could not find mglogs.zip to attach.

    Step 7: I attached the two logs that worked.

    I will await further instructions. I have requested the xp install discs from dell to reload xp if my system cannot be cleaned but I have concerns about backing up my information and carrying malware over to a new install. I would rather fix my current install though if possible. Please let me know what the best course of action you would recommend. Again, thanks for your time.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds