ready to toss pc into sea

Discussion in 'Malware Help (A Specialist Will Reply)' started by nietzsche1899, Jun 6, 2009.

  1. nietzsche1899

    nietzsche1899 Private E-2

    hello guys. my computer will not boot, runs slow, and now after running combo fix i cannot access e-mail. am ready to chuck machine into ocean. hence, my quest for help. i believe i have followed the requisite procedures and have attached the necessary logs.

    any help you can offer is greatly appreciated.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. You need to explain "won't boot" --> I am assuming this is a sporadic occurrence. Have you run SAS and MBAM on each user account? Do they also come back as clean?
    Combo did not remove anything from your system.

    We can remove some leftover junk, but it is not the cause of your problems. You need to add more RAM to your system:
    Total Physical Memory 512.00 MB
    Available Physical Memory 278.55 MB

    Do you know what these are:
    C:\Documents and Settings\All Users\Application Data\1317F
    C:\Documents and Settings\All Users\Application Data\272E
    C:\Documents and Settings\All Users\Application Data\C86

    You at one time had AVG so lets remove the leftover service:
    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * Any SAS or MBAM log that shows infections from the other user accounts.
    * C:\MGlogs.zip
     
  3. nietzsche1899

    nietzsche1899 Private E-2

    thank you very much for the help. I removed the AVG remnants as requested and successfully changed the registry. As for those 3 files, they were some kind of "winamp" files which froze when I tried to open them.

    I have attached the logs you requested.


    My boot problem is that whenever i restart the system I get the message: "NTLDR is missing" press ctrl alt del to start. I downloaded a boot.ini to work around this, which gets my computer running but I don;t know how to actually repair it. I don't have an windows xp install cd, which seems like an easy fix and the actual instructions to repair this without the cd are difficult for me to follow with my limited technical abilities. I found the temporary fix at tinyempire.com/shortnotes/files/ntldr_missing.

    thanks again for the help.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can borrow the same version of what you have...xp home or pro, then the people in software can walk you thru it.

    Your logs are clean......If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  5. nietzsche1899

    nietzsche1899 Private E-2

    hello. just a quick question. computer still really slow and malwarebytes shows a "rogue.winantivirus" that was deleted successfully. should I be concerned with this?

    thanks for looking into this.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are multiple causes for slowness....I would post in software and look at using a startup manager.

    As long as the scans are removing the malware, you should be fine.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds