need help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by 19vigilante73, Apr 7, 2013.

  1. 19vigilante73

    19vigilante73 Private E-2

    followed the procedure for removing malware/cleaning procedure for windows 7, now need help on what to do next, ran all 5 scans and uploaded logs here. Malware bytes and 2 other ones didn't find anything, but the 2 that did is attached! Attached I also put in an overview of my system! Thanks bunches
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would still like to see logs from Malware Bytes and Hitman please. ;)
     
  3. 19vigilante73

    19vigilante73 Private E-2

    Had to rerun the scan for malware bytes and hitman, logs are not on my desktop like the other logs are! WIERD, yesterdays log for hitman came back clean and today is showing signs! Had to figure out how to save it to desktop! I looked everywhere, even did an indexed search! DID NOT DELETE THEM! But can't find them, found the files from yesterday, but no logs! So here are the new scans!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O1 - Hosts: 255.255.255.255 broadcasthost
    • O1 - Hosts: ::1 localhost
    • O1 - Hosts: 216.34.181.45 s # slashdot.org
    • O1 - Hosts: 64.233.187.104 g # google.com

    After clicking Fix exit HJT.

    Delete this:
    • C:\Users\Administrator\AppData\Local\visi_coupon

    Give Ccleaner a run, not the reg scanner, just the cleaner itself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. 19vigilante73

    19vigilante73 Private E-2

    Did as you asked.....C:\MGtools\analyse.exe ran with no problems....to delete the visi_coupon, had to search just that in my computer.....would not find it under the C:\Users\Administrator\AppData\Local\visi_coupon in the search, but it found 3 of them, 2 under admin and 1 under Danny, deleted all 3! Ran c cleaner. Now the C:\MGtools\GetLogs.bat it came up with an exception, so I clicked OK to terminate, attached is a screenshot. I'm attaching the mg file and 2 screenshots, did a restart and another error came up with kernell base! (screenshot is attached of it) THANK YOU!
     

    Attached Files:

  6. 19vigilante73

    19vigilante73 Private E-2

    STRANGE, DID THE OTHER SCANS YOU ASKED FROM TODAY AND POSTED IT, IT'S NOT SHOWING HERE AT ALL! OK.....Again, did them all, only issue was that the visi_coupon, could not find with all the C: etc, had to type in just visi_coupon, found 3 files asscociated, deleted all 3 (2 were from admin, and 1 was Danny); Then did the last scan from MG bat and it came up with an exception, attached is the screenshot of that and the log file from it.....and I then did a restart and another error came up, also screenshot attached! Thank you!



    Service Control Manager
    1203 - Description : The following boot-start or system-start driver(s) failed to load: johci

    What does this mean, keep getting it when running a diagnostic. I'm gonna attach the asc diagnostic for an overview of other issues, if they affect my computer! Sorry, know your still reviewing my last thread, butjust wanted to throw this out too and see if it needs any assistance!
    Thank you sooooooo much!!!:major
     

    Attached Files:

    Last edited: Apr 9, 2013
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. :) Your latest logs looks good, so any other issues you now have I would suggest that you post about them in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. 19vigilante73

    19vigilante73 Private E-2

    Thank you so much!!! Was greatly appreciated! :major
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome! Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds