1. LogosEther

    LogosEther Private E-2

    Hey, so my computer was totally messed. There were so many problems that I can't even begin to list them here. I ran the malware FAQ as closely as I could and it got rid of the vast majority of my problems! Now I only have a couple of popups on startup, it seems. Here are my logs. Please let me know if there are other things I can do.

    Thanks so much for your help!!! Nothing got me anywhere until I found this site.
     

    Attached Files:

  2. LogosEther

    LogosEther Private E-2

    And my MG logs. Thanks!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are very badly infected!!!

    You have a bunch of infected Windows System files. Many other executable files may also be infected. I want to warn you up front that this could lead to you needing to do a total reinstall since even after we clean everything we can see, your system could still be infected and it may well be unreliable and untrustworthy. In addition the act of cleaning PCs with these kinds of infections could at some point render the PC unbootable. You should backup any important data you need now before doing anything else. DO NOT backup any executable type files as they maybe infected and if you copy them back or run the later, you could just reinfect you PC.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java(TM) 6 Update 5
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {9E8F3700-B204-4A1F-A637-3DE5381CDF53} - c:\windows\system32\srvgenx.dll
    O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
    O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
    O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
    O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\SAH\reader_s.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\SAH\reader_s.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
    O20 - AppInit_DLLs: c:\windows\system32\jolikiwe.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. LogosEther

    LogosEther Private E-2

    Alright, first of all, thanks for all your help. Here's why I haven't responded...

    My computer got worse. I couldn't boot in normal or safe mode. I attempted to fix things in the recovery console by trying to rename a .dll file (which was recommended to me after I did some research) and by running the repair stuff on there, but neither of those worked. Finally I got my Windows XP cd sent in the mail (because I didn't have it with me) and repaired using that.

    So now my computer runs again, but still has problems. I get an error message at start up. I can't use the internet at all. Windows Media Player doesn't run. Windows Firewall doesn't run. Long startup. A few others...

    I've attached my NEW MG logs. In the meantime, I'm going to run what you have recommended below.

    Thanks a bunch!

    -Logos
     
  5. LogosEther

    LogosEther Private E-2

    New MGlog. Read below too, please.
     

    Attached Files:

  6. LogosEther

    LogosEther Private E-2

    One error message I get is on startup:

    "explorer.exe - Entry Point Not Found

    The procedure entry point SHCreateThreadRef could not be located in the dynamic link library SHLWAPI.dll."

    It should be known that a while ago I copied explorer.exe as explorer2.exe so that I could change the text of my start button (newbie mistake, I know...). I'm not sure if that affects things or not.

    -Logos
     
  7. LogosEther

    LogosEther Private E-2

    Alright, hopefully this is the last post of the day.

    I ran MG and CCleaner and copied the logs over to my external using run>browse. Many hijack things were different now, but I got rid of what it seemed I'd need to do.

    Now I need explorer running again before I can tell you if everything else is fixed or not.

    Sorry for the multiple posts. I'm updating as I work on this. Thanks!

    -Logos
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but now you have a load of issues because you used a CD that was Windows XP SP1 and you had Windows XP SP3 installed. Now your PC is in and unknown state and anything not working may be more a result from the repair that you did rather than from malware. However many of your system files and older backups are still infected. Your best bet for reliability and security may be to perform a full reinstall. Trying to fix this could just be a delaying the inevitable.

    What happens when you try to connect to the internet? Are you sure you have it setup properly to obtain an IP address automatically....etc? Since you did a repair, you may have changed many settings to defaults.

    Your ComboFix log is very incomplete which indicates that it never finished running. You will have to try again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds