Problems after SUPERAntispyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by cmoazz, Aug 3, 2009.

  1. cmoazz

    cmoazz Private E-2

    I was following the Read Me and had just finished running the SUPERAntispyware. After the reboot that was suggested by SUPER Windows is unresponsive, my mouse cursor gets the little sand thing for waiting when you place it over the task bar. I can't right click on the desktop nor click on any desktop items, it's just stuck...

    Help?
     
  2. cmoazz

    cmoazz Private E-2

    Oh and I'm on XP
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Reboot.
     
  4. cmoazz

    cmoazz Private E-2

    I can't, can't click start, Ctrl + Alt + Delete doesn't work.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hold the power button down for 5 sec.
     
  6. cmoazz

    cmoazz Private E-2

    I had tried that already but it didn't help, it worked this time thankfully.

    I was installing now the next step, which is malwarebytes but it's at the "finishing installation" with the bar fully loaded for 5 minutes now, I think it failed...?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just continue on with the instructions...tell us what problems you encounter. Neither ComboFix nor MGTools require an istallation.
     
  8. cmoazz

    cmoazz Private E-2

    Mbam and combo dont seem to be working... should I keep going without them?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes. I at least need the C:\MGLogs.zip to start with.
     
  10. cmoazz

    cmoazz Private E-2

    Ok I'm doing the MG now, about how long does it take? Does it tell you when it's done? It's neat, using the black window to run the program ;)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just wait till it tells you it is finished...and I hope you made the agreement to run HJT. When done attach the log.

    You will then be in our work queue and will be replied to when your turn comes up.
     
  12. cmoazz

    cmoazz Private E-2

    ******************************************************************************
    * GetLogs.Bat - (c) 10/02/2006 By Chaslang *
    * This version supports Win2K, XP and Vista *
    * This small batch file is just used to automatically run GetUnKey.bat, *
    * analyes.exe (HijackThis), GetRunKey.bat, ShowNew.bat and processDLL.exe. *
    * It is automatically run by MGtools.exe during installation and can be run *
    * at anytime there after to create a full set of logs. *
    * 01/23/2009 Version 2.18 allow for x64 versions of tools. *
    * Show only important Restore Point files *
    ******************************************************************************

    32 bit Windows OS found

    Running scan with GetUnkeys.bat - 08/11/2006 by Chaslang and ShadowPuterDude

    32 bit Windows OS found
    adding: GetUnKey.txt (188 bytes security) (deflated 89%)


    Running scan with GetRunKeys.Bat - (c) 01/28/2006 By Chaslang


    NOTE: Ignore any error messages about not finding registry keys!
    Just wait for the program to finish running!!

    The system cannot find the file specified.
    adding: runkeys.txt (188 bytes security) (deflated 79%)


    Running scan with ShowNew.Bat - (c) 07/01/2006 By Chaslang

    ************************** WARNING **************************
    If you see a popup saying that:

    SteelWerX WhoAmI application has stopped working

    do not click the Cancel button that first appears. Wait for
    the Close program button to appear and click it to continue
    ************************** WARNING **************************

    Scanning please Wait.
    ============= Finding copies of actxprxy.dll ============= Please be patient
    ============= Finding copies of beep.sys ================= Please be patient
    ============= Finding copies of csrss.exe ================ Please be patient
    ============= Finding copies of ctfmon.exe =============== Please be patient
    ============= Finding copies of explorer.exe ============= Please be patient
    ============= Finding copies of kernel32.dll ============= Please be patient
    ============= Finding copies of lsass.exe ================ Please be patient
    ============= Finding copies of powrprof.dll ============= Please be patient
    ============= Finding copies of proquota.exe ============== Please be patient
    ============= Finding copies of regedit.exe ============== Please be patient
    ============= Finding copies of services.exe ============= Please be patient
    ============= Finding copies of spoolsv.exe ============== Please be patient
    ============= Finding copies of svchost.exe ============== Please be patient
    ============= Finding copies of termsrv.dll ============== Please be patient
    ============= Finding copies of userinit.exe ============= Please be patient
    ============= Finding copies of user32.dll =============== Please be patient
    ============= Finding copies of wininit.dll ============== Please be patient
    ============= Finding copies of winlogon.exe ============= Please be patient
    ============= Finding copies of ip6fw.sys ================ Please be patient
    ============= Finding copies of ndis.sys ================= Please be patient
    ============= Finding copies of ws2_32.dll ============== Please be patient

    Checking for .COM files to Delete. They will only print if deleted!

    Looking for new Vundo type infection. Be patient while scan runs!!

    Listing DLL, EXE, and SYS file in C:\WINDOWS
    Locating DLL files in C:\WINDOWS
    Locating DLL files in C:\WINDOWS\system32 - recursive
    Locating EXE files in C:\WINDOWS
    Locating EXE files in C:\WINDOWS\system32 - recursive
    Locating SYS files in C:\WINDOWS
    Locating SYS files in C:\WINDOWS\system32 - recursive
    adding: newfiles.txt (188 bytes security) (deflated 80%)
    adding: ffdata.txt (188 bytes security) (deflated 81%)
    adding: winfiles.txt (188 bytes security) (deflated 86%)

    Zipping UserInfo.txt
    adding: UserInfo.txt (188 bytes security) (deflated 70%)



    Nothings happening....
     
  13. cmoazz

    cmoazz Private E-2

    still nothing
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No error messages? Try running it in safe mode.
     
  15. cmoazz

    cmoazz Private E-2

    Ok it's all done, which of the files from mglogs do I post, the hijack one?

    Also, do I change the view hidden files back to normal? what about start up mode?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  17. cmoazz

    cmoazz Private E-2

    Hope it worked
     

    Attached Files:

  18. cmoazz

    cmoazz Private E-2

    This morning I tried booting it up, it gets stuck while loading at the beginning. It just shows the cursor with hourglass and it's stuck, I can move the mouse around but nothing is working. I did a manual reboot with the power button, same problem...
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are going to have to work that issue in the software forum. Once you can get back to a stable system, we can deal with what little malware there is.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds