Read and Run Me issue Step 6

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jobuh, Jan 10, 2010.

  1. Jobuh

    Jobuh Private E-2

    Ok so I have followed all of the steps in the READ & RUN ME FIRST thread to the letter.

    I'm at step 6 where the installation of the cleaning programs takes place.

    I attempted to install SUPERantispyware, but after I hit "Run", it gives a crash notice like this one:

    "Internet Explorer has encountered a problem and needs to close. We are sorry for the inconvenience."

    This same kind of notice is constantly popping up for iexplorer.exe (being opened by the virus constantly) and firefox.exe. I noticed that If I just drag the firefox error box down I can still use it.

    I also tried to open the other cleaning programs (malwarebytes, combofix) but neither of those will open. I doubleclick on the icon and for a millisecond the hourglass appears and then nothing happens.

    I would post any logs if I had them but I have none.

    One thing I did notice was that these errors only started popping up after I reinstalled java and ran ccleaner. I'm guessing one of those is the source of the problem.

    Thanks in advanced for any help and sorry if theres a similar post and I did not look hard enough for it.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Jobuh

    Step 1:
    Let's try to download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double-click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully be created on your Desktop as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post)

    Step 2:
    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Step 3:
    Next, try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Step 4:
    Now run a new scan with MGtools: Using MGtools

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    *The C:\ assumes that drive C is your Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. Jobuh

    Jobuh Private E-2

    I haven't noticed any changes but here are all the logs.

    Sorry I didn't know how to get the log from online SAS.

    If its a crucial step I can run the scan again.

    Thanks so much for the help btw.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below fixes and advice are specific to this member's problem and should be used for issue(s) on this machine only.

    Hello, Jobuh, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up this account's Desktop immediately leaving only links.[ C:\Documents and Settings\jon\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.

    Step 2:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 3:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    Step 6:
    * Uninstall any previous versions of SUPERAntiSpyware and Malwarebytes.

    Referring to: Windows XP Cleaning Procedure - download both > update and perform their scans. Then also install and run ComboFix.

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • SASlog.txt log from SuperAntiSpyware.
    • Malwarebytes Anti-Malware log

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds