Help needed / Virused PC

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sbattisti, Aug 18, 2011.

  1. sbattisti

    sbattisti Private E-2

    Hi folks,

    A friend of mine needed some help cleaning up her daughter's laptop, so I'm tackling the job. She did quite a number on this thing, but I can't provide any reliable information about where the problems came from.

    I've gone through all of the steps in the process. However, when running MGTools, the machine blue screened. I repeated the MGTools step again, and it bluescreened again.

    When I rebooted later, I re-enabled Avast, and it immediately detected a malicious URL, so apparently we still have some work to do. Logs attached below, and your help is greatly appreciated.
     
  2. sbattisti

    sbattisti Private E-2

    First four...
     

    Attached Files:

  3. sbattisti

    sbattisti Private E-2

    One more!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    Extract avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. sbattisti

    sbattisti Private E-2

    OK!

    Attached are the two new logs.

    Of note:

    1. MGTools bluescreened the computer again.

    2. Internet Explorer won't run on the machine, so I can't get online at all. It crashes each time I try to launch it. (However, I DO have an active internet connection, as Windows Update has been able to connect, as have tools like ComboFix.)

    3. I DID notice that this time around, after reboot, Avast isn't complaining about svchost trying to hit a malicious URL.

    Bottom line, I'm not sure I see any suspicious activity right now, but the computer still needs help. Pondering trying to repair IE, or install Firefox or something, to see if I can get online then.

    I also need to get this machine up to date on Windows updates, it's woefully behind.

    Thanks very much for your help! What next?

    ~Steve
     

    Attached Files:

  6. sbattisti

    sbattisti Private E-2

    I lied. The "malicious URL" message is still appearing in Avast. :(
     
  7. sbattisti

    sbattisti Private E-2

    There is so much going on with this machine, and because it's only used for a few games and Internet access, I'm just going to go ahead and reinstall the OS.

    So, thanks SO much for your help, but I believe this thread can be closed. (Unless there are viruses and such that would survive a total wipe and reload??)

    Thanks again,

    ~Steve
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's always a viable solution. Let me know if you have any additional issues. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds