please help me

Discussion in 'Malware Help (A Specialist Will Reply)' started by bachmyvo, Mar 18, 2009.

  1. bachmyvo

    bachmyvo Private E-2

    My computer runs very slow.
    Here is MGtools Zip File.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to complete ALL instructions in the below. MGtools is only one piece and it is the last piece.

    READ & RUN ME FIRST. Malware Removal Guide

    I see you have Spyware Doctor with Threatfire installed. Did you also install the antivirus and firewll with this or is it just the antispyware program with Threatfire?
     
  3. bachmyvo

    bachmyvo Private E-2

    Thanks for your reply.
    It is the full version of Spyware Doctor with Anti Virus .
    I will do all of the step and send you the log soon.
    Thanks for your help.
     
  4. bachmyvo

    bachmyvo Private E-2

    Here is the log file of Malware Bytes 's Antimalware .
    I also use SuperAntiSpyware but I do not know how to find log file for that.
    SuperAntiSpyware olnly find some cookies like adyield manager etc. v.v
    Please check it for me.
    Thanks for your help.
     

    Attached Files:

    Last edited: Mar 25, 2009
  5. bachmyvo

    bachmyvo Private E-2

    I found out the log for the SUPERAnti Spyware .
    Please help me.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not use the current version of SUPERAntiSpyware. You are way out of date.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Also you still need to attach the log from ComboFix and then you will need to download the new version of MGtools and run it and attach a new MGlogs.zip file.
     
  7. bachmyvo

    bachmyvo Private E-2

    Sorry because I respond it late.
    I will do it soon and send you the result.
    Thanks for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just make sure you attach the below three logs

    • New SUPERAntiSpyware log
    • ComboFix log
    • New log from MGtools
     
  9. bachmyvo

    bachmyvo Private E-2

    Hi,
    I did install new SuperAntiSpyware and run Combo Fix.
    In SuperAntiSpyware, it did not find anything.
    In Combofix, it deleted some file.
    My computer runs a little bit faster now.
    However, I could not run MGtools . I did download the newer version to my computer . However, when I click on MGtools.exe , it appears the cmd.exe in the DOS environment and it stays there. How do I uninstall the old version of MGtool ?
    Anyway, thanks for your help.
    Here are the log file for SuperAntiSpyware and Comboxfix.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to uninstall the old version since it is really not a program that is truly installed. Try the below.

    Shutdown your protection software (Spyware Doctor as it is probably getting in the way). Note that Spyware Doctor with AntiVirus and with Threatfire could be the contributing to the slow PC. But we need to complete your malware removal first.


    Uninstall the below software:
    CA Yahoo! Anti-Spy (remove only)
    Java(TM) 6 Update 10

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {285F4226-B850-40FA-875D-22E3E25CB156} - (no file)
    O2 - BHO: (no name) - {30C5C438-BB83-4969-83F0-519946D83C74} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
    O2 - BHO: (no name) - {bcb09bb4-f0eb-4167-a542-0c8b2d955698} - (no file)
    O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
    O20 - AppInit_DLLs: hohrdr.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Tien Ho\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Shutdown your protection software again to make sure it does not interfere with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 12, 2009
  11. bachmyvo

    bachmyvo Private E-2

    Dear Sir,
    I did that.
    Here are the two logs.

    I think combox fix does not detect anything new.
    Please let me know.
    Thanks for your help
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not do what was requested with ComboFix. You need to follow the instructions and created the CFscript.txt file and drag it ontop of ComboFix. You just simply ran ComboFix which is not what was requested.
     
  13. bachmyvo

    bachmyvo Private E-2

    Dear Sir,
    Thanks for your help.
    I created cfscript.txt and put it on desktop. I do not know how to drag the text file on top of combofix.exe . I dragged the cfscript.txt on top of icon combofix.exe but it does not help.
    Could you tell me more specific please ?
    Thanks for your help.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just need to left click on the CFScript.txt file and while still holding the mouse button down, drag the CFScript.txt file on top of the ComboFix icon and then let go of the mouse button. Please Note: The version of ComboFix that you have will now be out of date so before trying to run the fix, you need to download the current version of ComboFix from the link below and save it to your Desktop.

    combofix.exe
     
  15. bachmyvo

    bachmyvo Private E-2

    Dear Sir,
    I did what you said . This is a new combofix.txt file.
    Thanks for your help
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  17. bachmyvo

    bachmyvo Private E-2

    Dear Sir,
    Thanks for your help.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds