malware, virus/ problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by objectnull, Sep 13, 2009.

  1. objectnull

    objectnull Private E-2

    Earlier today I had Total Security on my computer from something one of my kids had done. Since this computer has all my work files on it I need it fixed ASAP.

    Its an HP Pavilion laptop running XP Pro.
    I performed all the tasks noted in the stickies in the forum with the following results:

    CCleaner

    SUPERAntiSpyware - log attached (had to use alternate start)
    Rootrepeal - log attached
    Malware bytes - would not run - started and then shut off - repeated and it showed message stting it was already running - process was not visible and nothing happened for a couple hours. same with reboot and repeat
    Combofix - nothing happened
    MGTools - log attached
    win32kDiag - ran log attached



    Thanks for any assistance you all can provide!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Either you did not allow MGTools to run to completion or the malware is blocking it.

    Please put Combofix on the root folder rather than the desktop:
    C:\ComboFix

    Please go to start / run / type "cmd" without quotes.

    When the command prompt opens type:
    This should start Combofix. It may reboot your system.

    Once it has run, then again go to start / run/ and now type:
    C:\win32kdiag.exe -f -r

    Then please re-run MGTools,exe and let it run till it tells you it is finished.

    Attach both the C:\Combofix.txt and the C:\MGLogs.zip
     
  3. objectnull

    objectnull Private E-2

    Timw,

    Thanks for your response.
    I moved CopmboFix.exe to c:

    At the command prompt I typed the commands in and got
    [SC] ChangeServiceConfig SUCCESS on disable and enable
    When c:\Combofix was entered nothing happens (ie combofix does not start)


    since the first task was not completed I will wait for further respons before proceeding
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue on with the instructions please.

    After doing this:
    Then run Combo and attach that log as well as the new MGLogs/zip
     
  5. objectnull

    objectnull Private E-2

    win32kdiag was not present and I had to DL it then I ran it.
    ran MGTools

    performed win32kdiag -f -r and then as before had success with SC disable and auto, when combofix.exe was ran it waited about 4 seconds this time before the prompt came back..

    Tried to attach MGLogs.zip and uploader said its already been uploaded and will not let me...
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from running windiag32.
     
  7. objectnull

    objectnull Private E-2

    Thank you
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below to make a copy of the good system file into the root folder of your hard disk so that we can use it to fix your problem.

    1. Click on the Start button, then click on Run...
    2. In the empty "Open:" box provided, type cmdand press Enter
      • This will launch a Command Prompt window (looks like DOS).
    3. Copy the entire blue text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).
      copy C:\WINDOWS\system32\logevent.dll C:\ /y
    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.
    5. Press Enter.
      • When successfully, you should get this message within the Command Prompt: "1 file(s) copied"
        NOTE: If you didn't get this message, stop and tell me first. Executing The Avenger script below will not work if the file copy was not successful.
    6. Exit the Command Prompt window.

    Now download The Avenger by Swandog46, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now do the following (make sure you redownload the file. Do not use the old copy.):

    • Download this Win32kDiag(If on your desktop - Right click and choose copy / then Open my computer, click on the C drive and in the window paste it there) and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r

    Alternative:
    * Please save Win32kDiag file to your desktop.
    * Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished,
    there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    "%userprofile%\desktop\win32kdiag.exe" -f -r

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:

    • C:\avenger.txt
    • the new log from Win32kDiag
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds