Help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sailor63, Feb 2, 2011.

  1. Sailor63

    Sailor63 Private E-2

    Hello,
    I am in desperate need of help. I went through all of your Read & Run Me first. I have all the logs but Combo fix it would get to deleting files then give me a blue screen of death saying Bad_Pool_Header. When i reset the laptop it would only get to the log in screen where i typed in my password then it would go no further. I could start up in safe mode. After 3 attempts it finally came up. I then finished all that was required and I thought i had it beat. Had to do a restart for something, and the laptop then would not pass the login screen no matter how many times i tried. So I went into Recovery console and fixed my MBR and it has come back up. Have not restarted since then (yes I am scared). Anyway I believe it is not gone so I am going to post all my logs. Also I have run SPY-Bot search and destroy, ran superantispyware in safe mode (trying to fix restart), and installed AVAST instead of AVG (Combo fix told me to uninstall AVG). Hope I did not do to much damage. All scans resulted in finding nothing.

    Thanks in advance
     

    Attached Files:

  2. Sailor63

    Sailor63 Private E-2

    just adding attachements.

    Again thanks in advance for yout time and help.

    Chip
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Currently reviewing your logs and will post back with a response soon. :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:49798
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Run the avg removal tool and try to run combofix again.

    AVG Remover(32bit) 2011
    (avg_remover_stf_x86_2011_1165.exe)


    Delete this file using windows explorer unless you know what it is for.

    C:\Documents and Settings\Mikebest\Application Data\325E.7D7

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. Sailor63

    Sailor63 Private E-2

    Thank you for your help.
    Disabled Antivirus
    Ran the MGtools no problem
    Ran the FixMe got the success message
    Ran the AVG Remover no problem
    Ran ComboFix and I got the BSOD Bad_Pool_Header at the same spot as soon as it says deleting files. I had brain fart here, yesterday I went to msconfig and did a selective startup because of the BSOD not letting me get past the Welcome (where you input password) screen. I also reenabled TeaTimer. SO i went to msconfig again and did normal startup and I also d turned off teatimer and rebooted, this time it stopped at the same spot (welcome screen at password input) restarted and it came up. Ran Combofix again and at the same spot I got the BSOD Bad_Pool_Header.
    Deleted 325E.7D7 file no problem.
    Ran MBRCheck but could not right click on screen so I did a screen print see Jpeg.
    Ran MGTools Get logs bat file, zip file attached.
    Sorry about changing Teatimer and Msconfig.
     

    Attached Files:

  6. Sailor63

    Sailor63 Private E-2

    Sorry for posting again but I was looking at the desktop and found MBRCheck.txt, so I wanted to attach it. Boss has so many icons it is not funny, and maybe just maybe he will not give his kids his work computer.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs look good, but you must describe to me how things are running for you at this point.
     
  8. Sailor63

    Sailor63 Private E-2

    Seems to be running fine. I will give back to the boss and if he notices anything I will let you know.

    Thanks a Million

    Chip
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds