Need fixlist.txt - FRST.txt attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lakers123, Mar 25, 2013.

  1. Lakers123

    Lakers123 Private E-2

    Hi,

    I'm having a similar problem as I've seen others have. I removed the Alureon virus and now my system won't boot. I just keeps going to the recovery screen after a brief blue screen while Windows 7 is trying to load. I ran FRST.EXE and created the log attached. Can someone please help me to get my system to boot? I believe I need a fixlist.txt file...correct?
     

    Attached Files:

  2. Lakers123

    Lakers123 Private E-2

    Oh, by the way, I'm running windows 7 64bit. The problem occurred when removing Alureon with MS Defender Offline. After removal, the system wouldn't reboot. This is my work (home) PC and won't be able to work tomorrow If I cant resolve this issue. Thanks for any help...it is greatly appreciated.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally. Let me know how you get on.

    -------------------------------
     

    Attached Files:

  4. Lakers123

    Lakers123 Private E-2

    Wow...thanks so much. The system boots up now!!! ...attached is the fixlog

    I had restored the computer to a previous point when I was originally trying to fix the problem. Upon this successful boot, there was a message that my restore was successful. Therefore, I'm assuming the Alureon might reside again on my PC. I will use the steps written in the thread on this site to scan/remove this time

    Thanks again...please let me know if you have any comments regarding above and/or the fixlog
     
  5. Lakers123

    Lakers123 Private E-2

    Hmmm...not sure why the fixlog didn't attach. I will try again.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  7. Lakers123

    Lakers123 Private E-2

    Hi Kestrel13,

    Thanks again. I have followed all the steps in the link(s). Here are some details:

    Downloads:
    CCleaner....scan done and finished.

    RogueKiller....my AVG Internet Security 2013 (paid) was blocking this program as a threat. Tried to click "allow", but there was an error that wouldn't allow me to proceed. I suspected a problem with AVG and tried to uninstall with the intention of re-installing again later, but also ran into problems with that. I don't believe I was ever able to completely uninstall, but was able to stop it from blocking RogueKiller...log attached

    Malwarebyes....scan done, no detections...log attached

    tdsskiller....scan done, found something (didn't write down), but when clicking continue/next it didn't seem to remove...log attached

    HitmanPro....scan done, no detections...log attached

    The AVG issue has me perplexed. I even tried to use their removal tool, but did not work. And, while I have been typing this response, AVG popped up asking me to run my "First Scan"...as if I just installed it. Not sure what to do.
     

    Attached Files:

  8. Lakers123

    Lakers123 Private E-2

    Hi Kestrel13,

    After finishing up on the scans and response I sent you...I went to my MS Outlook to respond to some emails and it seems I'm running into a new problem. I can navigate around Outlook to see all my folders/emails, but if I click reply to any email the pop-up email response window looks strange and I can't do anything with it. I have attached a screenshot of this for you to see.

    I assume that the logs I sent earlier will point you to the issues with my system. And, in turn, your response/solution will likely resolve this issue, but I wanted to report this issue to you just fyi
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can i see the MGLogs.zip from running MGTools.exe please?
     
  10. Lakers123

    Lakers123 Private E-2

    I somehow missed that step at the end. Ran it this morning and it is attached. System is running really slow now. Thanks for your help with all this.
     

    Attached Files:

  11. Lakers123

    Lakers123 Private E-2

    Hi Kestrel13,

    By any chance would you know why my MS Outlook is not working right? I can't send emails. The email window that pops up freezes and doesn't look right. Is there a fix? Or, do you need to have me run any steps?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All I can do here is deal with actual malware removal, so if i have to send you off to the software forum for that after we finish up here don't be surprised.

    Checking the leatest logs now, i am running all behind tonight.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman and have it delete Potential Unwanted Programs then let me know what actual malware issues remain.
     
  14. Lakers123

    Lakers123 Private E-2

    Thanks. I'm feeling confident that the oulook issue has to do with the malware. Again, much appreciated
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. When you are ready you can follow the below steps. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. Lakers123

    Lakers123 Private E-2

    Hi, I ran hitman again and removed the three items. I also ran Malwarebytes again just for the heck of it and it found something (see attached log). I went ahead and removed the bug and it required a reboot. I also ran RogueKiller once more and the log has different entries than the first one I sent you, so I'm attaching it as well. I didn't make any changes with RK, just created a log.

    So, it seems I still have some issues. The MS Outlook is still having its same issues.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, everything was all clean....
    I already explained you may have to ask in software forum about the outlook issue ;)

    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 2 detections:

    [RUN][SUSP PATH] HKCU\[...]\Run : Zeon (Rundll32.exe C:\Users\Barry-New2\AppData\Local\Zeon\docdtvbf.dll,DllCanUnloadNow) [x] -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-2195443469-1181145480-4017838751-1000[...]\Run : Zeon (Rundll32.exe C:\Users\Barry-New2\AppData\Local\Zeon\docdtvbf.dll,DllCanUnloadNow) [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Delete this folder, reboot, does it still exist?
    C:\Users\Barry-New2\AppData\Local\Zeon

    Now re run RogueKiller, just a scan and attach the log for me to see.
    Does MBAM continue to find anything else?
     
  18. Lakers123

    Lakers123 Private E-2

    Hi,

    Thank you. I ran RogueKiller and deleted the two items (log (RKreport[4] attached), then rebooted. I then found the file (C:\Users\Barry-New2\AppData\Local\Zeon) and deleted it, then rebooted and then checked the file location and it was still deleted (good). So, finally I ran RogueKiller again to generate only the log. Attached is the log report (RKreport[5]).

    I ran MBAM earlier this morning and there was nothing. I just ran it again and still nothing (great!!!)

    Lastly, I managed to fix the outlook problem on my own. Not sure if it was related or coincidence, but it is fixed and running fine.

    Soooo...I think I'm clean now!!! System seems to be running well. I am very grateful for all your time and help with this messy thing.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome ;) You can now follow final steps.
     
  20. Lakers123

    Lakers123 Private E-2

    Thanks Kestrel13. All is well now. Have a nice weekend.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks Lakers, you too!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds