Got a/some problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by luckyvic, Feb 2, 2010.

  1. luckyvic

    luckyvic Corporal

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will only be able to remove items in your system restore folders when you toggle system restore. Do not do it now.

    Please disable all AV and AS programs while you try to run ComboFix ( it is on your desktop, isn't it??).

    We also need the logs from running:
    RootRepeal
    C:\MGLogs.zip --> from running C:\MGTools.exe
     
  3. luckyvic

    luckyvic Corporal

    Here are Rootrepeal logs.
     

    Attached Files:

  4. luckyvic

    luckyvic Corporal

    more...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All I asked for was the RootRepeal and the C:\MGLogs.zip.
     
  6. luckyvic

    luckyvic Corporal

    one more.

    Could not run MGTools.exe, see attache.
    Also can not run Combofix.
     

    Attached Files:

  7. luckyvic

    luckyvic Corporal

    Well, I can't run MGTools.exe, so no log from it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  9. luckyvic

    luckyvic Corporal

    I ran the the Getlogs.bat from the MGTools folder and got the zip.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay.

    You have a bunch of system files that need to be renamed! Look in this folder:
    C:\WINDOWS\system32\
    and all the files that end in .tmp rename by right clicking it and then just backspace out the .tmp.
    Look for files such as these:
    batmeter.dll.tmp
    browseui.dll.tmp

    You will find them listed in your NewFiles log within the MGLog.zip.

    Then you can run CCLeaner to empty out this folder:
    C:\Documents and Settings\Victor\Local Settings\Temp\

    In the mean time, Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now go to start / run / and type:
    sfc /scannnow ( have your xp cd handy).

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  11. luckyvic

    luckyvic Corporal

    Sorry for not getting back sooner. Had to reformat, the pc started act crazy, crashing, lots of beeping sound and then finally stubborn as a mule it wouldn't bootup.
    I really appreciate everybody's help. You people are the best.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks for letting me know. Hope all is fine now. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds