I can't find anyone who can help me......

Discussion in 'Malware Help (A Specialist Will Reply)' started by cstagg, Dec 17, 2008.

  1. cstagg

    cstagg Private E-2

    Hey everyone,

    I recently downloaded a file off limewire, as soon as the download was complete I had a virus warning from Symantic antivirus when I clicked on the removal process the scree went blue and shut down...the cmputer then restarded and once everything loaded up it went blue again then restarted in safe mode......everytime. I have run mgtools with the logs. I have no idea what they mean which is why I am here I need the pros to help me Which I would really be greatful for. Here they are.
     

    Attached Files:

  2. cstagg

    cstagg Private E-2

    more to come
     

    Attached Files:

  3. cstagg

    cstagg Private E-2

    missed one
     
  4. cstagg

    cstagg Private E-2

    For some reason the site is telling me when I try and post the remaining logs that I may have already posted the file on this site when I haven't....Whats going on here
     
  5. cstagg

    cstagg Private E-2

    For some reason the website will not let me attach my procdll.txt
    here is the remaining logs
     

    Attached Files:

  6. cstagg

    cstagg Private E-2

    O.K. the Vunfind.txt reads:

    Entries 0 (0)
    Directories 0 Files 0
    Bytes 0 Blocks 0
     
  7. cstagg

    cstagg Private E-2

    So thats it.....anyone kind enough to help a fella out man I would greatly appreciate it.

    Thanks again

    Chris
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. cstagg

    cstagg Private E-2

    O.K. sorry about that...is it o.k. to run the removal guide in safe mode??? It's the only way my laptop will work regular mode just shuts off in like two mins.

    Thanks again

    Chris
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, if you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
    Last edited by a moderator: Dec 18, 2008
  11. cstagg

    cstagg Private E-2

    O.K. so first of, my apoligies for not reading the instructions in my other post. I have however went back and started form the begining and ran everything the way you wanted and here is what happened.

    First off I had to run in safe mode because my computer keeps resetting in normal mode, it would not let me un-install java so I skipped the step, then I could not get into the hidden files section and I assume that this has to do with safe mode as well. The first program SAS would not install saying the installer was not authorised, I followed the link for having problems with the install but it never helped. So I continued on to the next program, this one worked and found a few problems, I followed the instructions and it did it's thing, I then ran Malware bytes which didn't seem to find anything, then combo fix. This is the program that seemed to really straighten things up it went on to restart the computer and I am now running in normal mode and everything seems to be going good. I want to post my logs now the ones in section 4 but I can't seem to find them on the computer. Other then that the only problem that I am noticing right now is on startup my computer tells me it does not recognise the battery and will be unable to recharge, even though it does charge when plugged in. I llstand by on where to find the logs and what to do next. Oh and by the way thanks again so much.

    Chris
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open MalwareBytes and you will find the logs tab.....open it and save it to the desktop so you can attach it.

    MGTools will be here ---> C:\MGLogs.zip

    Combo log should be on the C:\ drive
     
  13. cstagg

    cstagg Private E-2

    here are the files
     

    Attached Files:

  14. cstagg

    cstagg Private E-2

    I have searched everywhere for the MGtools file and SAS file, they are not anywhere I can see them......would you like me to run those scans again??
    Thanks
    Chris
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow these instructions:

    Please use add/remove programs to uninstall:
    Java(TM) SE Runtime Environment 6

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  16. cstagg

    cstagg Private E-2

    Hey,

    I ran the avenger scan and insert the script, I deleted the files in in c:windows/temp, My computer will not let me access documents and settings it comes up access denied. The odd thing is, is that it has now a shortcut icon on the folder which I am almost sure it didn't have before. Would you like me to continue anyways with the mgtools or would you rather sort this issue? Here is the copy of the avenger log.

    Thanks again
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes I want the new MGLogs.zip.
     
  18. cstagg

    cstagg Private E-2

    here it is
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    And tell me what this is:
    O4 - Startup: Registration Lock On

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
    Last edited: Dec 23, 2008
  20. cstagg

    cstagg Private E-2

    O.k. I completed the steps and here are the logs. The file O4 - Startup: Registration Lock On, is from a video game I had installed but have long since re-moved it. Everytime I start up my compter it ask what progam to open this file with.
    The computer is still not recognizing my battery and says it won't be able to charge just in case you were wondering as well....
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not allow MGTools to run to completion. Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Your battery problem has nothing to do with malware. And I suspect that your logs are clean at this point.

    Though removing that 04 item in HJT may solve your start up issue.
     
  22. cstagg

    cstagg Private E-2

    Hey Tim,

    Sorry about taking so long to get back to you, I got called to work x-mas eve and have been playing catch up with everything since. Anyhow I ran mgtools again this morning it told me a log file has been created in c:/mgtools.zip or somthing but for some reason it's not there. I have winzip, and I know where the file is supposed to be but nothing is showing up. My computer is still not running right. I am unable to open the file documents and settings along with a few others. As well my disc space seems to be almost full but I have very little on this computer......somthings up.......maybe you might be able to help me find this mgtools.zip file. I apoligize if I am doing somthing very stupid.

    Stagg
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Lets do this:

    Look for and delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip.

    Also Uninstall SuperAnti-spyware.

    Now go back to the Read and Run First instructions and download the latest version of MGTools.exe as well as the new version of SAS. Run both and get me the logs.
     
  24. cstagg

    cstagg Private E-2

    O.K. I ran both scans here are the logs
     

    Attached Files:

  25. cstagg

    cstagg Private E-2

    MGtools logs
     

    Attached Files:

  26. cstagg

    cstagg Private E-2

    the rest
     

    Attached Files:

  27. cstagg

    cstagg Private E-2

    So here they are, the biggest problems right now are that the battery is giving all kinds of warnings and I put in my spare which is never used and it's giving the same warnings, also my disc space is showing very little left when I have very little on my hard drive. I am also unable to view alot of my folders, I click on for example documents and settings folder and it says I do not have permission to enter this folder contact admin or somthing along those lines. Also when I went to install these to programs on my C: drive it said I didn't have authority to do so and to contact admin. I went into safe mode and downloaded them and restarted in normal and then ran the scans....anyway I appreciate al the help! Have a happy new year!

    Chris
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system

    The battery issue is not malware.

    I suggest that you post in the software section regarding your permissions issue with Vista.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds