Ran "read & run me first" and encountered some errors

Discussion in 'Malware Help (A Specialist Will Reply)' started by trascendenza, Aug 14, 2008.

  1. trascendenza

    trascendenza Private E-2

    Unfortunately, I'm not sure when problems with this system started -- it's a shared office computer, but this is what I know:

    - Since upgrading to QuickBooks 2008, all firewalls have been disabled (they were interfering with running QuickBooks through the network, or some such).
    - The system has been running very slowly and freezing periodically to frequently.

    What I did:

    - Before following the Malware Removal Guide on this forum, I'd already downloaded and run CCleaner in all modes, including registry cleaning out, as well as RegSeeker. I backed up both times.

    - Then I followed the steps on the Malware Removal Guide. The first time I ran SAS, the computer froze halfway through, so I unchecked "Use Kernel Direct File Access (recommended)" and "Use Kernel Direct Registry Access (recommended)", though I'm not sure I should have, because I didn't see a blue screen of death. The computer simply froze somewhere around 12 minutes into the scan, in the same fashion it had been freezing during regular computer operation. It completed the scan successfully the second time.

    - I already had Spybot Search & Destroy installed (downloaded only a week ago, so I thought it was a recent enough version), so I ran that. I encountered the following error twice while scanning: "There were problems in the include file C:\Program Files\Spybot - Search_Destroy\Includes\Trojans.sbi. See 'Include errors.log' for details." I re-downloaded and re-installed Spybot after a system restart and tried again, and the scan ran to completion without errors the second time.

    - ComboFix seemed to run fine.

    - While running MGTools, I encountered this error:

    "Error details:

    An unexpected error has occurred at procedure: modRegistry_IniGetString(sFile=system.ini, sSection=boot, sValue=Shell)
    Error #5 - invalid procedure call or argument

    Windows version: Windows NT 5.01.2600
    MSIE version: 7.0.5730.13
    HijackThis version: 2.0.2"

    - I also have a pop-up error at startup that has persisted. Prior to using RegSeeker and CCleaner, there were numerous pop-up errors occurring, which seemed related to the numerous errors I ran into when trying to uninstall old and/or suspicious programs via Add/Remove. The current pop-up startup error is:

    "MotiveSB.exe - Entry Point Not Found

    The procedure entry point ?InstallHook@@YAHK@Z could not be located in the dynamic link library SBHook.dll."

    - Other than that, there don't seem to be any apparent system issues, but I was a bit worried because it seems from start to finish I've been encountering errors. One of the main reasons I decided to go through with the whole cleaning procedure was because of the errors I kept encountering while trying to uninstall programs, because some were resisting uninstall, and the system doesn't seem to remove unnstalled programs from the start menu, though until I uninstall something post-cleaning I won't know if that has persisted.

    Am attaching my logs and would be most grateful for any help! Thanks so much for your time.
     

    Attached Files:

  2. trascendenza

    trascendenza Private E-2

    My MGLogs.zip file.

    Also, forgot to mention -- if it would be helpful, I have screenshots of the three of the errors I mentioned above would be happy to attach those images.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    You may have to redownload your QuickBooks web connector : http://marketplace.intuit.com/webconnector/

    Delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file,
     
  4. trascendenza

    trascendenza Private E-2

    Thanks so much for the help, Tim. I followed your instructions and this is my new MGLogs.zip file.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean...though I have to wonder what transpired between your last post and this newest one. :confused

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds