Here are my logs from Read and Run Me

Discussion in 'Malware Help (A Specialist Will Reply)' started by jdoginc, Aug 4, 2009.

  1. jdoginc

    jdoginc Private E-2

    I followed all of the steps read and run me, as i have MANY times on so many other computers. BUT i am still locked out of my msconfig and do not have full privelages. Please let me know what is going on. I have attached my logs. Let me know...thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    But you didnt. Otherwise you would have attached the logs for:
    RootRepeal
    C:\MGLogs.zip
     
  3. jdoginc

    jdoginc Private E-2

    sorry I ran them but forgot to attach
     

    Attached Files:

    Last edited: Aug 6, 2009
  4. jdoginc

    jdoginc Private E-2

    ok, here they are again, all I hope!!
     

    Attached Files:

  5. jdoginc

    jdoginc Private E-2

    here are my MGTools logs as wee
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system, however, you are running an old version of MGTools.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the MGTools.exe and attach the new log.
     
  7. jdoginc

    jdoginc Private E-2

    well...i would love to run the new MGTools!

    OH MAN! its bad! I cant run executable files, when I try to start in safe mode it just loops and goes right back to asking me if i want to start in safe mode, when i try and pull up regedit, it flashes, then tell me that i need to turn on my virus protection because executable files are infected. I cant run task manager. I have a recovery console installed onto the computer but i am not sure on how to run it OMG please help TIMW!
     
  8. jdoginc

    jdoginc Private E-2

    was making headway..

    i made it into the regedit through command:. I typed "copy regedit.exe regedit.com" it copied one file and then i typed "regedit.com" it opened upp registry. Then i couldnt find a file, so i search for it HKEY_CLASSES_ROOT \ exefile \ shell \ open \ command" and it shut reg down after searching and now the same commands wont work. I am so frustrated! I really need help, my uncle does actually! HELP
     
  9. jdoginc

    jdoginc Private E-2

    progress again

    hope I am not doing things incorrectly as far as forum etiquet goes.
    I am making headway again, I got back into the registry by following this link, "http://www.kellys-korner-xp.com/xp_tweaks.htm" going to line 12, and inputting onto my hard drive and running it. what should i do, i do not want to lose this regedit again.
     
  10. jdoginc

    jdoginc Private E-2

    removed monopod from [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    I did some looking around and also just deleted "shmgerate.exe" from "=%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE"

    any ideas
     
  11. jdoginc

    jdoginc Private E-2

    OKAY this is it..i am about to shoot it!

    I managed to do this and do that to the registry. Got MSCOnfig back. And regedit. I then once again, began read and run me first, with fresh downloads. Disabled Symantec E.C., view hidden, sun java, quarantine removal,
    ran ccleaner=successful.
    Uninstalled suspicious programs=successful.
    Tried to run SAS, recieved message about not having privileges to run the program.
    Restarted. at desktop startup, received message "Generic Host Process for Win32 Services has enocountered a problem and needs to close..."
    Tried to run Notepad=cant
    PopUp- "Attention! System detected a potential hazard (TrojanSPM/LX) in your computer that may infect executable files. "You" private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need update your current security software. Click OK to download official intrusion detection system. (IDS software).
    In middle of MBAM scan, quit and displayed "Application cannot be executed. The file is infected. Please activate your antivirus software."
    Ran combofix, green load bar ran to finish=nothing!
    Root Repeal=success (at the very last seconds, received "unable to execute" message.
    MGTools After the command window shows up, "Application cannot be executed. The file is infected..."

    SO I have no clue what to do, PLEASE HELP ME, and then i can quit filling up this forum with my stupidity.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    IMPORTANT NOTE: Some if not many, of your Windows system files are infected. And many other non-Windows files could also be infected. Even if we attempt to fix these problems (which may not be easy to do unless you have an original Windows XP SP3 bootable CD), your system may be unreliable and untrustworthy.You may need to reinstall this system.

    Your logs show that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possible become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to perform a total reinstall of Windows and all other necessary software. DO NOT reinstall from any executable files you backed up because they are most likely infected.
     
  13. jdoginc

    jdoginc Private E-2

    Hey TimW,
    Thank you very much for taking the time to help me out. One last question..(maybe) I do not have restore disks, HP says, "we dont give those out anymore". They didnt even come with the computer. I do however, have the recovery console on the computer..can i use that, or do I need to call HP and b*t%h until they send me a disk? and If i can use recovery console, how do I use it? it gives me the three options to choose from, and when I choose "1" it just tells me to hit enter, I do and all i get is a command line...
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, sadly you can't use the recovery console to do a reinstallation. The only way you can do it is with the disc. You need to call and tell them that your system was destroyed by a virut infection and you need to have the installation discs!

    Raise hell!
     
  15. jdoginc

    jdoginc Private E-2

    Thank you VERY much for your time TimW, I really do appreciate you and the rest of the "Anti-Malware Militia" (yep, i think I will copyright that bad boy) You guys do a great service, Keep up the Great WORK!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...I hope you can get the install disc! Good luck! :)
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you hvent yet gotten a disc., we may be able to clean this without it! Please the current version of MGtools and get me a new log.
     
    Last edited by a moderator: Aug 25, 2009
  18. jdoginc

    jdoginc Private E-2

    hey timW,
    Chaslang has been working with me while you have. It was quite unintentional. I started on my laptop on one thread and uncle's pc on the other, and as things got worse for the pc, they got better for my laptop and the threads developed into being both about the pc. I apologize for my using two threads. I used some of what you told me and some of chaslang. It worked out for the best and it seems to be running fine now. And I did call HP and had those discs sent. I did in fact, "raise hell". I thank you for your time, and appreciate everything. Keep geekin' it.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are sure you have it all sorted, then good. If you need further assistance let me know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds