Help Needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by BadaBing, Oct 6, 2009.

  1. BadaBing

    BadaBing Private E-2

    I am trying to fix a laptop for a friend and am not having anyluck. It was booting up and all I would get is Privacy Center. The by going in task manager I was able to kill that. I noticed that I had a folder named PCenter and was able to delete it. However I am not able to run explorer.exe I get an error "Windows cannot access the specified device, path, or file. You may not have the approproate permissions to access the item." I am having to do all work through the Task Manager and File Open. It is XP Home with SP2. any help would be greatly appriciated. I did do the scans I was having trouble with some of them but here is what I have. These are the only logs i am able to retrive. I will run the other apps again if I need to.
     

    Attached Files:

    Last edited: Oct 6, 2009
  2. BadaBing

    BadaBing Private E-2

    Ok I have they combo fix log now as well
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the below log from SUPERAntiSpyware:
    Code:
    "C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Oct  5 2009       87727  "SUPERAntiSpyware Scan Log - 10-05-2009 - 17-56-18.log"
    Now delete the below old copy of ComboFix which is in the wrong location.
    C:\ComboFix.exe

    Now download the current version of ComboFix from the below link and save it to the Desktop as required or later steps will not work:
    combofix.exe


    Now run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    HijackThis 1.99.1
    Java 2 Runtime Environment, SE v1.4.2
    Spybot - Search & Destroy 1.3 <-- 5 yrs out of date
    Viewpoint Media Player <-- should have been uninstalled in step 5 of the READ ME


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now you must run MSconfig and make sure the PC is in Normal Startup mode as requested in step 4 of the READ & RUN ME. You did not do this last time.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the SUPERAntiSpyware log
    • the win32kdiag.txt log
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. BadaBing

    BadaBing Private E-2

    ComboFix is froze What would you like for me to do? Also after running Win32kDiag explorer is now able to load.
     
  5. BadaBing

    BadaBing Private E-2

    Here are my logs. I wasn't able to get combofix to finish running but I went ahead and finished the rest of your directions. I hope that doesn't mess anything up. The laptop is booting into Windows as it should now and I was able to get BearShare and Viewpoint Media off. I will wait for futher instruction from you before I do anything else.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we will have to do this differently since you could not get ComboFix to run.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\win32kdiag.exe -f -r just like I had you run in my previous fix.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • the new Win32kDiag log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. BadaBing

    BadaBing Private E-2

    sorry it has been so long I am not able to get a network connection to connect on the laptop since running the scans I am not able to work on it at work so if you have any ideas how to get the network going again I would like to try to get this resolved so that I will be able to finish working with you.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You best bet is to complete the instructions given. You don't need the network running to do them. You can download any necessary tools using another PC and burn them to a CD to copy to this PC.

    However if you were using a wireless connection, try a wired connection. Also check to make sure the parameters for your network interface are still setup properly to use DHCP (assuming you don't use a static IP address). DHCP means you should be set to Obtain an IP address automatically. If you don't know how to do this see this link: http://uits.iu.edu/page/aiyy
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds