First Time Poster Seeking Assistance

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kool aid man, May 24, 2011.

  1. kool aid man

    kool aid man Private E-2

    Hello Major Geeks,

    Over the past couple of months my PC's performance has become increasingly affected by malware. I have been encountering many problems such as site redirection, blocked access to programs, and overall slow performance. I attempted the "READ & RUN" malware removal guide and followed every step except for running Combofix. This guide helped remove some malware, but my PC is still suffering. I am posting to request help from a Malware Removal Team Member to help me effectively eliminate malware from my PC. I am a mostly novice PC user so I will finish the post here until a Team Member provides me with further instructions for the next step. Thank you for taking the time to read my post and provide help.

    kool aid man
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, kool aid man

    Please go to the below link and follow the instructions for running TDSSKiller from Kaspersky.

    TDSSkiller - How to run

    Then - run ComboFix as instructed in the READ & RUN ME First guide.

    Next - Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Attach the following logs to your next reply:
    • SASlog.txt log from SuperAntiSpyware.
    • Malwarebytes Anti-Malware log
    • RRlog.txt (from RootRepeal)
    • ComboFix.txt (normally C:\ComboFix.txt)
    • C:\MGlogs.zip
    • TDSSKiller log.txt

    *NOTE: The SUPERAntiSpyware and Malwarebytes' log can be found in the following directories:
     
  3. kool aid man

    kool aid man Private E-2

    Hello dr.moriarty,

    Thank you for responding to my post. Unfortunately I am unable to run Combofix after having used TDSSkiller (which found no infected files). When I click on the Combofix.exe icon on my desktop I am prompted with the "Open With..." window (as I am with all other programs I attempt to open).

    After I browse and select Combofix.exe from the "Open With..." window it begins to load, then prompts me again with the "Open With..." window. This repeats every time and floods my taskbar with Combofix.exe and "Open With...".

    Are there any ways I can eliminate being directed to the "Open With..." window so I can continue with the malware removal process? I would post a screen shot of the problem using Print Screen, but when I try to open it in MSPaint I receive the error message (after, again, selecting MSPaint in the "Open With..." window): C:\Windows\System32\mspaint.exe
    Paint cannot read this file
    This is not a valid bitmap file,
    or its format is not currently supported.


    Thank you

    kool aid man
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    In order to try to fix a suspected file associations problem, please tell me what operating system you're using.

    dr.m
     
  5. kool aid man

    kool aid man Private E-2

    I'm using Vista 32-bit.

    K
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go HERE and click on the exe file fix. Let us know it that works.
     
  7. kool aid man

    kool aid man Private E-2

    The exe file fix worked. Thank you, TimW. I will now attempt to use Combofix and send each log.

    k
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. We will be here when you are ready.
     
  9. kool aid man

    kool aid man Private E-2

    I am receiving an error when trying to run Combofix. I attached a screenshot of the error message combined with how far I get using Combofix. The error mentions a "Spooler Subsystem App".

    k
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then skip that step and get me the rest of the requested logs.
     
  11. kool aid man

    kool aid man Private E-2

    These are the logs I was able to find. I uninstalled MGTools after using it over a week ago so the logs are gone.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe file. (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the C:\MGLogs.zip
     
  13. kool aid man

    kool aid man Private E-2

    Here is the MGlog.zip. On a side note, is there a way to fix the "Spooler Subsystem App" error message? I get it occasionally, not just when trying to run Combofix.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will have to post in the software forum for help with your spooler issue.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  15. kool aid man

    kool aid man Private E-2

    I am unable to find C:\MGtools\analyse.exe. I found only C:\MGtools.exe and ran that as instructed, but I was could not a menu interface that would allow me to select the options you mentioned.

    Unfortunately I was not able to begin on the instructions, and I must leave my computer. I will return in 10 hours to continue the malware removal process. Thank you.

    k
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    C:\MGTools\analyse.exe is there. Just open the C:\MGTools folder to find it.

    From you newfiles log within the C:\MGLogs.zip:
    Code:
    "C:\MGtools\"
    analyse.exe   Apr 22 2010      388608  "analyse.exe"
     
  17. kool aid man

    kool aid man Private E-2

    I found the C:\MGtools\analyse.exe after searching thoroughly, and then followed the instructions as written. I received a success message after using fixME.reg. The only thing that did not happen as planned was the license agreement after running C:\MGtools\Getlogs.bat. Below are the two attached logs as instructed.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  19. kool aid man

    kool aid man Private E-2

    I deleted the Combofix.exe from my desktop yesterday. Should I just download it again to my desktop and then try to run the uninstall command?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, as that will remove the other folders associated with Combo. ;)
     
  21. kool aid man

    kool aid man Private E-2

    I have now uninstalled Combofix.exe, and have completed the remaining instructions. Thank you very much for taking the time to help me clean my computer.

    k
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds