Help, I am having problems with an infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by mquelch, Sep 14, 2010.

  1. mquelch

    mquelch Private E-2

    Hi,

    I am having problem with an infection. My computer was restarting every time, and I couldn't get to run any removal tools. I finally got it to run my last good start up. I've tried running MGtools but it wouldn't run and I couldn't get any logs. I've run the rest of tools and I've attached the logs.

    Please help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about Combofix? Try running that please unless you are on a 64-bit system. Then I want you to rename MGTools.exe to 123.com and try and run it again, if not in normal mode then in safe mode.
     
  3. mquelch

    mquelch Private E-2

    I am running 64 bit and I cannot run Combofix. I also tried renaming MGtools to 123.com but it still wouldn't run.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your OTL log this is likely because you have not disabled UAC and rebooted as instructed. Your OTL log shows UAC is enabled
     
  5. mquelch

    mquelch Private E-2

    I did disable UAC after I send the post and I did try running MGtools again but I had the same results. Now I can't get logged in, it says user profile cannot be loaded.
     
  6. mquelch

    mquelch Private E-2

    I forgot to mention that I've tried using my restore disk to repair the system but that is not working as well.
     
  7. mquelch

    mquelch Private E-2

    Here is the OTL log, and I still cannot run MGtools.
     

    Attached Files:

    • OTL.Txt
      File size:
      127.9 KB
      Views:
      3
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    If it ran, attach the logs.
     
  9. mquelch

    mquelch Private E-2

    I tried your suggestions and it did not run. I got "find" is not recognized as an internal or external command, operable program or batch file.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have MGTools downloaded to C:\MGTools.exe? Where did "find" come from? Is UAC disabled? Are all your AV and AS software disabled?
     
  11. mquelch

    mquelch Private E-2

    MGtools was downloaded into the root directory of C:\, and expanded from there so there is a MGtools folder. "Find" is the response when I used the commands you suggested in the cmd window. UAC, AV, and AS are disabled when I ran the commands.

    When I run GetRunKey and ShowNew I get "find" is not recognized as an internal or external command, operable program or batch file.
     
  12. mquelch

    mquelch Private E-2

    I tried running MGtools again and it ran for about 1 second and stopped. I've attached the logs, but I am not sure what is inside.
     

    Attached Files:

  13. mquelch

    mquelch Private E-2

    I just tried running ShowNew from inside the MGtools folder and it started then stopped with an error. "\??\C:\MGTools\ltime.exe" cannot start or run due to incompatibility with 64-bit versions of windows. Is there a 64-bit version of MGTools?

    I am running Windows 7 64-bit.
     
  14. mquelch

    mquelch Private E-2

    Hi

    I am still having difficulty with my computer. I noticed that my McAfee firewall goes off. When I turn it on it goes off again. Also I am getting an error when I try to install Windows Updated. The error code says my firewall is stopping the updates but the firewall says it is off.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If the C:\MGTools folder was created, try running these:
    C:\MGtools\GRK64.bat
    C:\MGtools\SN64.bat
     
  16. mquelch

    mquelch Private E-2

    I tried to run both C:\MGtools\GRK64.bat and C:\MGtools\SN64.bat and none of them ran.

    I just see the cmd black screen briefly.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can get HITMAN to free you up enough to run the scans.
     
  18. mquelch

    mquelch Private E-2

    Hi,

    I had to get Hitman 64-bit from the author's site. It ran ok and I've included the log. I also included the log for Kaspersky virus removal tool that I ran earlier.

    I am still having the same problems with my computer.
     

    Attached Files:

  19. mquelch

    mquelch Private E-2

    Hi,

    I just realized the Hitman log did not get attached. The log only showed MGtools.exe as a Trojan, it did not find anything else.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then Hitman pro did not fix anything! It is obviously incorrect about MGtools.exe Hitman Pro is actually more instrusive and does more questionable things then MGtools. ;) That still does not make Hitman a trojan. Obviously Hitman is not actually verifying anything related to MGtools which is rather easy to do. The same is all true for the false detection by Kaspersky.


    Note your last OTL log still showed UAC enabled so when you are disabling it, it is not really disabling. Also after disabling, you have to reboot for it to take effect.

    When you ran GRK64.bat and SN64.bat from the command prompt, what messages did you see? If they are not running, some form of error message should appear or does it just abort. You MUST run it from the command prompt like below to debug.


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    SN64 <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.



    ALSO note, you should shutdown your McAfee software before running any of the MGtools scans to avoid problems due to McAfee interference.
     
    Last edited: Sep 16, 2010
  21. mquelch

    mquelch Private E-2

    Hi,

    I am really having a difficult time with this computer.

    I've tried to disable UAC again, and I tried to run GRK64 and SN64 from the MGtools directory in the cmd and again I get the following.

    "find" is not recognized as an internal or external command, operable program or batch file.

    I ran the Kaspersky virus removal tool again and I don't know if the results is any help. I've attached the log.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I know it will probably not work, but you mentioned you could not run combofix, but what about after renaming it? I know you renamed MGTools, but what about CF? Try it just to see. Rename to abc.com and give it a go.

    Also although you are on a 64 bit system, this tool here (if it will run at all due to the condition your machine's in) should run in a reduced functionality mode, but it may still catch something so let's see...

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  23. mquelch

    mquelch Private E-2

    Hi,

    I tried running Combofix but I get an error saying wrong OS - this product only works for workstations with Windows 2000 and XP.

    I ran TDSSKiller and I've attached the log.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What happened when you tried to do a repair install?
     
  25. mquelch

    mquelch Private E-2

    Last time I did that nothing happened, it did not repair anything.
    Do you think it is time for me to use the repair disk using the image I created. I made this disk on July 31, 2010. I will probably lose some information.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If your image was from before all this occurred, I would definitely use it. You may wish to check for things that you will lose and safely back them up. But I do believe that reverting to that saved image will help. Much of what is happening seems to be software related, not necc. malware related.
     
  27. mquelch

    mquelch Private E-2

    Ok, I will try using the image to fix the issues.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how that goes. I would hope you can then run the scans to be on the safe side. :major
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Likely very true that the Windows OS has been corrupted. The message below
    "find" is not recognized as an internal or external command, operable program or batch file.

    which was received when trying to run the batch files, indicates that either you are missing a file which is part of Windows or that your path has been corrupted and the file could not be located. find.exe is a part of Windows and on an x64 system copies should be located in both of the below folders:

    C:\Windows\system32
    C:\Windows\SysWOW64
     
  30. mquelch

    mquelch Private E-2

    Ok, I will repair with the image then run MGtools and post the logs.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Fingers crossed!! :)
     
  32. mquelch

    mquelch Private E-2

    Hi Guys,

    I repaired my computer with the image repair, and I ran MGtools. I've posted the logs, so tell me if I still have a problem.

    Thanks
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Based on the fact that you can now run MGTools and after a quick look through those logs, you are good to go!! The only thing I can recommend at this point is to first clean out this folder:
    C:\Users\Michael Quelch\Local Settings\TEMP\

    Then create a new restore point.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  34. mquelch

    mquelch Private E-2

    I want to thank all of you at Major Geeks for your assistance. You've done me a great service for which I am very grateful.

    God's blessings to all of you.

    Thank you.
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome!! Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds