Possible Malware issues.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Joeb102072, May 7, 2012.

  1. Joeb102072

    Joeb102072 Private E-2

    Hi,
    I am attaching the required logs after following the malware removal proceedures layed out on this site.

    This is not my computer, but the issues that this person is experiencing seem to lead me to think that there is or was a virus issue and its either still there or its damage is still affecting the computer.

    The desktop will not show. The boot time is more than doubled what it should be and when the computer boots a message comes up saying "C:\windows\system32\config\system profile\desktop refers to a location that is unavailable."

    When I try to navigate to anything in the system32 folder I get a message that says "windows explorer has stopped working" and the another dialogue box pops up immediately after that and says "windows explorer is starting up" The cycle continues until I get out of that screen.

    It appears when I try to add remove programs or try to alter any settings at all to the computer.

    Lastly when I try to boot into safe mode, I get the BSOD with an error message that says "bad_system_config_info"

    Thank you in advance for any help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your newfiles text did not populate:

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    SN64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  3. Joeb102072

    Joeb102072 Private E-2

    Unfortunately that menu item doesnt exist where you are telling me. I dont know why but under accessories it goes from "Calculator" to "connect to a network projector" and then "getting started".....?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if we can generate a new log. Go to the C:\MGTools.folder and right click the SN64 file and choose to run it as Administrator. Attach the log.
     
    Last edited: May 7, 2012
  5. Joeb102072

    Joeb102072 Private E-2

    Ok that seemed to work here is the log.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, still only generating an Add/Remove list.

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. Joeb102072

    Joeb102072 Private E-2

    Ok here they are...fingers crossed.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest you post in the software forum for further assistance.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  9. Joeb102072

    Joeb102072 Private E-2

    Wow...very odd behavior from this computer to find out it is clean...which im not complaining about at all. Many thanks!

    I did the first step to uninstall combofix... an odd error occured...

    "Windows cannot find 'C\windows\system32\config\systemprofile\desktop\combofix' make sure you typed the name correctly and then try again.

    And combo fix is not on the desktop in front of me?

    Before I abandon this thread I am wondering if this means anything to you and what else can I do to ensure combo fix is uninstalled?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you even download Combo? I think you are having system issues.
     
  11. Joeb102072

    Joeb102072 Private E-2

    I did originally when instructed too, and it ran with no issues.

    Oddly a system reboot just brought everything back to normal. I did the clean up process as you described above and I have no apparent issues.

    A Run sfc /scannow seemed to fix the windows explorer issues.

    I think all is well now.

    Thank you very much Tim!!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds