problems opening everything

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by silas, May 26, 2011.

  1. silas

    silas MajorGeek

    Related thread http://forums.majorgeeks.com/showthread.php?t=238128 Had issues of opening everything on computer. Always gave some sort of error or blah blah. It got rid of my antivirus. I tried downloading avast and mb and sas all again. Finally got them to work today. I also scanned with SAS yesterday and since the restart it gave me all the problems. I go to open my SAS to check and undo what happen. Nothing.. not even a log from that scan was there.
     

    Attached Files:

  2. silas

    silas MajorGeek

    i went to upload the last log combofix and I notice its not under the C:Then i restart again. And its not there. And now my combofix program that was on my desktop isn't there anymore? Any solutions? Re download and run it?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All those "New Folder"'s on your root drive C:\ .. are they empty? If so delete them.

    Java(TM) 6 Update 20
    <-- Uninstall outdated Java

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :files
    C:\Documents and Settings\mel\Local Settings\Application Data\4386ix5j14f331siojf0til42vv64u6er30t8sxk15c7a
    C:\Documents and Settings\mel\Local Settings\Application Data\d7u7u25o323ig4344hx1dgw1001sapbdji68426ql32
    C:\Documents and Settings\All Users.WINDOWS\Application Data\4386ix5j14f331siojf0til42vv64u6er30t8sxk15c7a
    C:\Documents and Settings\All Users.WINDOWS\Application Data\d7u7u25o323ig4344hx1dgw1001sapbdji68426ql32
    C:\Documents and Settings\mel\Templates\4386ix5j14f331siojf0til42vv64u6er30t8sxk15c7a
    C:\Documents and Settings\mel\Templates\d7u7u25o323ig4344hx1dgw1001sapbdji68426ql32
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\windows\Run32A50.mch

    Yes please. (regarding Combofix)

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. silas

    silas MajorGeek

    Link for Oldtimer isn't working. Try again at later time?
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks like geeks to go is down. I'll revise a fix in a minute. Desperate for a cup of tea.
     
  6. silas

    silas MajorGeek

    No need to rush. Iam grabbing coffee
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's replace the Combofix step with Avenger then.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Then continue with the rest of my instructions from previous post.
     
  8. silas

    silas MajorGeek

    I mentioned that the link for Oldtimer wasn't working. Combofix would/will work. Did you mean to replace oldtimer to avenger?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry I meant replace the OTM steps with avenger. Before you run the getlogs.bat you can run Combofix.
     
  10. silas

    silas MajorGeek

    So far all done cept the combofix. I don't know what you mean exactly by what VirusTotal is saying to give to you. I can highlight some of it and see if it will post here.
    0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.

    File name:
    Run32A50.mch
    Submission date:
    2011-05-27 15:58:06 (UTC)
    Current status:
    queued (#32) queued (#32) analysing finished
    Result:
    0/ 43 (0.0%)

    Antivirus Version Last Update Result
    AhnLab-V3 2011.05.27.01 2011.05.27 -
    AntiVir 7.11.8.160 2011.05.27 -
    Antiy-AVL 2.0.3.7 2011.05.27 -
    Avast 4.8.1351.0 2011.05.27 -
    Avast5 5.0.677.0 2011.05.27 -
    AVG 10.0.0.1190 2011.05.27 -
    BitDefender 7.2 2011.05.27 -
    CAT-QuickHeal 11.00 2011.05.27 -
    ClamAV 0.97.0.0 2011.05.27 -
    Commtouch 5.3.2.6 2011.05.26 -
    Comodo 8857 2011.05.27 -
    DrWeb 5.0.2.03300 2011.05.27 -
    Emsisoft 5.1.0.5 2011.05.27 -
    eSafe 7.0.17.0 2011.05.26 -
    eTrust-Vet 36.1.8352 2011.05.27 -
    F-Prot 4.6.2.117 2011.05.26 -
    F-Secure 9.0.16440.0 2011.05.27 -
    Fortinet 4.2.257.0 2011.05.27 -
    GData 22 2011.05.27 -
    Ikarus T3.1.1.104.0 2011.05.27 -
    Jiangmin 13.0.900 2011.05.27 -
    K7AntiVirus 9.104.4730 2011.05.27 -
    Kaspersky 9.0.0.837 2011.05.27 -
    McAfee 5.400.0.1158 2011.05.27 -
    McAfee-GW-Edition 2010.1D 2011.05.27 -
    Microsoft 1.6903 2011.05.27 -
    NOD32 6158 2011.05.27 -
    Norman 6.07.07 2011.05.26 -
    nProtect 2011-05-27.01 2011.05.27 -
    Panda 10.0.3.5 2011.05.27 -
    PCTools 7.0.3.5 2011.05.19 -
    Prevx 3.0 2011.05.27 -
    Rising 23.59.04.03 2011.05.27 -
    Sophos 4.65.0 2011.05.27 -
    SUPERAntiSpyware 4.40.0.1006 2011.05.27 -
    Symantec 20111.1.0.186 2011.05.27 -
    TheHacker 6.7.0.1.211 2011.05.27 -
    TrendMicro 9.200.0.1012 2011.05.27 -
    TrendMicro-HouseCall 9.200.0.1012 2011.05.27 -
    VBA32 3.12.16.0 2011.05.27 -
    VIPRE 9405 2011.05.27 -
    ViRobot 2011.5.27.4482 2011.05.27 -
    VirusBuster 13.6.373.0 2011.05.27

    Additional information
    Show all
    MD5 : 4007cbf52a1ebbc98c1e8d4e95bd0540
    SHA1 : d28892b9f384272fa8d5d6b179addfa0b2ab0121
    SHA256: 7b82b4cd5e9e7c229ae07d30141f290bdf90a3457854b8a8c8e201454d6a68ec
    ssdeep: 96:AqOxQJ4EiwTs6WZDARmwkcUlmRRt7sp0o2xm2GT7bx:ANYiL6yDARmwknlmRRt7sppx
    File size : 6716 bytes
    First seen: 2011-05-27 15:58:06
    Last seen : 2011-05-27 15:58:06
    TrID:
    Unknown!
    sigcheck:
    publisher....: n/a
    copyright....: n/a
    product......: n/a
    description..: n/a
    original name: n/a
    internal name: n/a
    file version.: n/a
    comments.....: n/a
    signers......: -
    signing date.: -
    verified.....: Unsigned

    VT Community

    0

    This file has never been reviewed by any VT Community member. Be the first one to comment on it!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That report just shows that the file you had them scan was not malware. Did you do the Avenger fix? If so, attach the log and re-run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  12. silas

    silas MajorGeek

    Hello sorry I was gone a day or two. Family problems I did do the Avenger fix and was getting ready to run combofix again and upload the logs. I re ran MGTools and combofix
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're logs are clean, silas. What malware issues are you still having, if any?
     
  14. silas

    silas MajorGeek

    Nothing that I can see:zzz
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. silas

    silas MajorGeek

    All done and thank you very much. You and TimW too.:wave Time for coffee and cig:zzz
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    On behalf of us both, you're welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds