Re: REdirect malware logs attached...please assist

Discussion in 'Malware Help (A Specialist Will Reply)' started by sberkkoch, Dec 12, 2013.

  1. sberkkoch

    sberkkoch Private E-2

    Hi Again,
    I still cannot get online. Same error message :'Proxy server is refusing connections'

    IE is gone. The icon in the taskbar is blank. Not found in my apps. (running windows 8)

    I cleared all my caches. (except IE) Ran CC and did all the steps.
    Then I went back to READ ME.
    I ran the hitman the way the instructions said for offline. I clicked ignore but it repaired anyway! I am very sorry, I hope this won't cause a problem w your interpreting the results. I've attached all the logs again. I appreciate your help.

    Sad Sue
     

    Attached Files:

  2. sberkkoch

    sberkkoch Private E-2

    I'd love some help with this, please! The logs are above. I can't believe this happened. I was so close. I'd downloaded a new version of the defogger. Apparently it was not defogger, but a nasty virus.

    Can you help me get rid of it? I just tried to boot in safe mode and do a scan. The message said that I needed a recovery disc or to contact a system admin?

    Is this impossible to fix?

    Do I need to wipe the hard drive and start over? Will that solve the problem?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't bump! It only hurts you.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry or PROXY tab and locate this detection:

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Now re run RogueKiller again (just a scan) and attach log.

    Explain how things are running.
     
  4. sberkkoch

    sberkkoch Private E-2

    Hi Kestrel 13!,
    It says in my email that I'm required to reply before you'll reply again, so I did. I didn't mean to bump.

    I ran the rogue killer. The first time I found the entry but it was in 'proxy' and I could not check it there. I took my best guess and deleted the first entry in 'registry'

    I've attached the logs. Some are leftover from before, but I could not tell which was which, so I have uploaded all three.The fourth one marked (2) is the scan only.

    Unfortunately there is no change in the machine. IE is still a blank rectangle on the task bar. I cannot get online.

    Thank you,

    Sue
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Still there. Try it this way, re run Hitman and have it fix the proxy, should be under heading/tab marked "Repairs"

    Then rescan with Hitman, and then RogueKiller, and attach both logs.
     
  6. sberkkoch

    sberkkoch Private E-2

    Hitman fixed the proxy! Thank you.
    I am online on the machine. It is running slowly and IE is still a white rectangle in the taskbar.

    Logs for scans attached. I didn't repair anything else, just scanned.What next?

    Thank you! Thank you!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What happens if you find iexplore.exe inside of this folder and try to start IE that way? :confused

    C:\Program Files (x86)\Internet Explorer

    Also, you can have Hitman fix that other Potential Unwanted Program.
     
  8. sberkkoch

    sberkkoch Private E-2

    It's odd but when I do a search for any C:\ ... I get a message saying my computer is not connected to the internet right now. But here I am, connected in firefox. Something is hiding the program files from me.

    I'm not sure why I can't access them. There was an app icon called 'this pc' which took me directly to my program files, but it is gone. It's impossible to get to my local disk.
    I put in a CD in the D drive then I can work my way there, but nothing happens when I click on the folder Internet Explorer. It won't run, open or the like.

    Any thought?

    I'll run hitman again.

    Attaching log and actually, I did find the icon 'my pc' ! I can access my local disk from it, but IE is still not working.
     

    Attached Files:

    Last edited: Dec 13, 2013
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you click Start > and type in Internet Explorer. Do you see it crop up in the list there? Also, does Internet Explorer (no add ons) pop up>?
     
  10. sberkkoch

    sberkkoch Private E-2

    I have windows 8 for an OS. When I type internet explorer in the 'search box of that wand bar, the IE folder opens in Program Files (x86)
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But you cannot double click on iexplore.exe within the folder to start IE, correct?
     
  12. sberkkoch

    sberkkoch Private E-2

    I apologize but I wanted to add this information!
    I re read all your posts just now...I found 'iexplore.exe' inside of the program folder and it DID open! But the icon or when I type IE in the search bar brings me to the Program Files (x86) IE folder. It does not open the browser.

    Thank you.
     
  13. sberkkoch

    sberkkoch Private E-2

    It does open! I apologize about the mix up of earlier.

    I tried it several times and it works. I can just create a shortcut on the desktop and that should do it, no? I don't need to do anything else?

    So YOU DID IT! Thank you.

    Do I need to clean anything else up? Should I go to your entry when we thought we were done? I cannot get the defogger to change the setting in step 2, however. I don't want to download another version. That is how THIS trouble started, from the debugger web page.

    Thank you for your patience with me!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  15. sberkkoch

    sberkkoch Private E-2

    No, not from your web page. Thank you for that link. I somehow got to this web page:

    http://www.bleepingcomputer.com/download/defogger/dl/8/

    And that is where I downloaded a new defogger, figuring since the version on my desktop wasn't working, maybe I needed a new version. It was from that download that the proxy server block happened.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's a legit webpage, with a legit download, so not sure I understand anymore now. :confused

    How is everything running at this point? Do you feel that it's time for final steps?
     
  17. sberkkoch

    sberkkoch Private E-2

    I don't understand, either, but that is the page I used for the defogger download. It's fine, one of those things. A string a bad juju that is now over, thanks to you.

    Everything is working well. I will keep malwarebytes, that nifty revo uninstaller and I already had CCleaner. Do I need the rest?

    I am ready for the final steps!

    One more question....should I download Firefox 26? Or just let it update? I found this....

    http://www.majorgeeks.com/news/story/firefox_now_blocks_all_java_by_default.html

    I wonder if it was the java download onto my machine that could have caused the problem rather than the showtime plug in? Do I need to run java?

    Thank you Kestrel 13!

    Sue
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just use the latest Firefox, always use the most up to date version.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  19. sberkkoch

    sberkkoch Private E-2

    Thank you again, Kestrel 13!:)

    I followed the steps. Again, I am hung up on #2. Defogger was unable to open the file, it said. I went on and MG tools took off all the software I'd installed in the READ ME post, including defogger.

    I am hesitant to download defogger again. Is it a problem that defogger could not re enable my disc emulation software?

    Thank you!

    Sue
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can ask about that in the software forum. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds