I am in need of "MAJOR" help

Discussion in 'Malware Help (A Specialist Will Reply)' started by juntuo, Mar 19, 2008.

  1. juntuo

    juntuo Private First Class

    I have read forums on removing malware, I have logs and hope some on can help. computer boots I can surf web, download, etc... I cannot burn discs, some of my icon disappear!?
    win xp pro sp2
    p4 2.6
    1.25 gb ram

    I am new here to your forum I hope I am doing this right and this is info you need to help me, TIA for any help. juntuo
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  3. juntuo

    juntuo Private First Class

    Thank you so much for your help I am going to burn a dvd to see if this worked. I posted new logs. I have two other machines any chance you could help with these as well? Thanks again. juntuo
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good...just remove your old Java. Yes you can have us look at the other computers...just start a separate thread for each one and be sure to identify them as different systems.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  5. juntuo

    juntuo Private First Class

    No, looks like I am still having problems. dvd still wont burn, runs thru process then errors out. icon switching around desktop. should I post MGTools and combofix again? I hate to be this much trouble, I just plain don't know what else to do.

    fabdvd
    nero
    shrink
    dvdx
    clonedvd
    ripit4me
    roxio 9

    I am running winpatrol and something seem to pop up says its microsoft and a bunch of giberish. some program will not start itunes, noadware, and sometimes zonealarm. Thanks loads for any and all help. juntuo
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you can attach a new MGLogs.zip and ComboFix log, but I suspect this is not malware related.
     
  7. juntuo

    juntuo Private First Class

    I will take steps to remove CF and MG I am a little unsure about what you are talking about removing java and the restore point. I know about turning on/off auto restore but don't know about the java. Thanks for taking the time! juntuo
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I thought you wanted to attach new logs? Are you saying everything is running OK?

    These old Java files:
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) 6 Update 3

    And turning off system restore, rebooting and then turning it back on will flush your old restore points that may have some infected files in them.
     
  9. juntuo

    juntuo Private First Class

    yes I was going to post logs. Sorry about that. If this problem I am having isn't malware related can you point me to the right section to solve problem?
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean ....though I see you have an "e" partition. Have you run malware scans on that drive?

    I would suggest you post in the software section for further assistance as this does not appear to be malware related.
     
  11. juntuo

    juntuo Private First Class

    yes I do have other partitions too H,I,J,K,L,N. H,I,&J. are all for my music K&L would get downloaded to and N is fo converting and holding files. should I run all of my partitions? here are the log for E. Thanks again for taking your time to help! juntuo
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo found a bunch on that partition ...so yes, run it on each as well as the SASpyware program to cover ALL drives.
     
  13. juntuo

    juntuo Private First Class

    ok I am scanning Thanks a bunch for pointing out the partitions! juntuo
     
  14. juntuo

    juntuo Private First Class

    h partition
     

    Attached Files:

  15. juntuo

    juntuo Private First Class

    I partition
     

    Attached Files:

  16. juntuo

    juntuo Private First Class

    J partition
     

    Attached Files:

  17. juntuo

    juntuo Private First Class

    K partition
     

    Attached Files:

  18. juntuo

    juntuo Private First Class

    L partition
     

    Attached Files:

  19. juntuo

    juntuo Private First Class

    N partition
     

    Attached Files:

  20. juntuo

    juntuo Private First Class

    forgot MGlogs for L and N
     
  21. juntuo

    juntuo Private First Class

    n partition
     
  22. juntuo

    juntuo Private First Class

    MGlogs
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean ...are you having any other problems?
     
  24. juntuo

    juntuo Private First Class

    you wrote and said I had a bunch of problems in the logs of my e partition. Don't I need to clear something out of there?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry...I meant that you had a bunch of new garbage that showed up on your ComboFix log that had previously either been removed or was new.

    We need to re-run ATF Cleaner and also remove these:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  26. juntuo

    juntuo Private First Class

    new logs. Thanks for taking a look. juntuo
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can use windows explorer to find and delete:
    C:\WINDOWS\unins000.dat Mar 1 2008 2548 "unins000.dat"
    C:\WINDOWS\unins000.exe

    Otherwise, I don't see any problems.
     
  28. juntuo

    juntuo Private First Class

    Thank you so much for all your help with my computer, I am on the computer a lot and would like to know more about malware removal. I would be interested in knowing how to read hijack/MGTool logs and know how and what to remove. Any direction you could send me? You have been a big help to me and I hate to keep posting with these problems as I have twelve machines that myself or my daughter work with. I am a major computer junkie and am always testing things out, so why not learn this! Would love to know more. Thanks again for your help. I do have a couple other machines I will be posting maybe you will take a look. Thank you! juntuo
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome .....12 machines? For personal use? Rather overkill, eh?

    If you want to learn...you might consider going to :
    malwareremoval.com
     
  30. juntuo

    juntuo Private First Class

    TimW
    No not all for my personal use, I teach some kids 8 to 12 how to use computers. So I have machines set up with xp that I dual boot with other operating systems so I can learn new things too. I do this as a free service thru our local chamber. I run four for my personal use. I read a lot in news groups mainly alt.binaries. My three kids have their own machines too. So no not over kill. Just p.c. personal computer. Man I only needed help with four machines. Two here, my laptop, and my machine at work. You so far have helped me fix my laptop, and my main machine at home, And I greatly appreciate your help! I didn't come here to cause problems. Thanks for All your help. I will check out website and see if I can fix problems myself. Thanks man, your friend -juntuo
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No harm meant or caused .....we have had users in the past who have been running a business and using our limited resources to facilitate their repairs. It can be aggravating, to say the least.

    This is why some explanations before hand can be of benefit, as we are more than happy to support community and esp. childress programs. Chas was concerned as he is the one that handles the majority of the threads and also this forum, so it was a legit question, and not meant to be accusatory.

    You can sign up at that site and become a student, as well as just read the threads here and look at the logs to see what is being removed. :)
     
  32. juntuo

    juntuo Private First Class

    TimW
    thanks for the reply I do understand. I hope to get better soon, and reading on that site and the forums here I have learned a little. Thanks again. juntuo
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're most welcome.....:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds