Running Combofix per 'read this first' thread stalled?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by julepakfan, Aug 16, 2011.

  1. julepakfan

    julepakfan Private E-2

    Hi! I am having major problems here and I hope you can help. I was infected by Zentom System Guard and XP Security 2012...they pretty much hit at the same time. I was just getting WWE Summerslam updates...went to a couple of different sites, so I am not sure which one GOT me. Anyway, I was following the directions in the READ ME FIRST thread. I ran the SAS and the MBAM with no problems. Then I got to the ComboFix. It started out just fine, I got to "Completed Stage 16" and the flashing cursor is below that. However, it has been at the same stage for almost 2 hours. It said to be patient, but I am not sure how patient. I did try to X out of it, but it said that it was still running...but I don't think it is doing anything. Any ideas?

    Thanks so much!
    Julie
     
  2. julepakfan

    julepakfan Private E-2

    Okay, now I think I did even worse damage...you tell me. The Combo Fix was running for well over 3 hours without changing, so I closed it out and rebooted my computer. (It's an HP notebook). Now it tells me that my HP embedded security for ProtectTools is not initialized. I have no idea how to fix it. I can no longer access the internet from that computer. I already had the RootRepeal downloaded, but it would not let me access it to install, so I can't run it. (Honestly, I was just trying to follow your directions...skip the combofix and finish the rest of the programs on your list. Ugh! Now what can I do? I kind of feel like I am at war with my computer...and I must prevail.
    Thanks for helping!
    Julie
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Could you please attach logs from running Malware Bytes, SUPERantispyware and MGTools.
     
  4. julepakfan

    julepakfan Private E-2

    Hi, thanks for getting back to me so quickly! Gosh, if I was getting paid by the hour for fixing this, I could have bought two more computers. Anyway, I will try to attach the logs. I could not use my Firefox because I get an error that "platform version 1.9.2.18 is not compatible with min version/max version, 1.9.2.20. I had to use internet explorer, and even it is kind of touchy. I think that it is an embedded security issue. It is all Greek to me.
    Thanks,
    Julie
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below outdated software.

    • J2SE Runtime Environment 5.0 Update 6
    • Java(TM) 6 Update 23
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7
    Do you know what this file is for?

    C:\Documents and Settings\Administrator\Application Data\cryptobjacl.exe

    If not...

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\Documents and Settings\Administrator\Application Data\cryptobjacl.exe



    Could you please get this: cryptobjacl.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :services
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    
    :files
    C:\Documents and Settings\All Users\Application Data\3rd864h2p0sq0ns3710461njp85ym7l
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. julepakfan

    julepakfan Private E-2

    Wow...I was quite intimidated by all those directions, but it was so simple! Thank you so much for breaking it all down like that!

    I did not know what that "crypto..." file was, but after seeing the log, I think it was probably something that my school tech guy put on here when the computer was new. (I am a teacher and got it through a grant.) After a couple of years, it became all mine.

    The VirusTotal results on the 'crypto...' file said 0/44 (that sounds good, I think.)

    I am attaching the zip file as you asked. (at least I hope I am doing it right.)

    I ran the OTM and am attaching the log.

    I ran the TDSSkiller - "no infections found" but I am attaching the log...just in case.

    I ran the MBR check and the MGTools log and am attaching the logs in a separate post...I am not sure how many I can attach to one post.

    My computer is running pretty well right now. Start up is a little bit slow...but not terrible. I think that I have an unrelated problem with my Firefox. Since I couldn't use it, I got a newer version. It runs great under my administrator username, however it will not run under my personal username. It just asks me what program I want to open it with. I can still use Internet Explorer, but I really prefer FireFox. I have also noticed that when I log off of my personal username, I get a message that "NS App Shell: Event Window is not responding, so I just have to close it.

    I really can't thank you enough!
    Julie
     

    Attached Files:

  7. julepakfan

    julepakfan Private E-2

    Here are the other logs.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    After clicking Fix exit HJT.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  9. julepakfan

    julepakfan Private E-2

    Good Afternoon, Kestrel13!
    I did what you told me, but first, I accidentally ran the MGtools because I did not realize there was another folder with the analyse.exe. I hope I didn't mess anything up by doing so. Everything else went just fine. You did not tell me to attach the log from Avenger...but I will attach it anyway, just in case. I am also attaching the mgtools log.

    Thank you so much!
    Julie
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry about the rather delayed response. Busy weekend at work.

    Delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    C:\Documents and Settings\Administrator\Local Settings\Temp

    f you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. julepakfan

    julepakfan Private E-2

    Hi Kestrel,
    No need to apologize! I am so grateful for everything you have done. Everything seems to be running just fine. I am working my way through the list of things to keep me safe.
    I do have a couple of questions...just to make sure. I could not find HiJack This in my Add/Remove programs...so I didn't do it. The other programs, I just deleted since I did not see any official uninstall directions. (Except for the combofix of course.) When I ran the mgtools clean.bat, it just went really fast and I could not see what it said. I went back into the C drive to find it, thinking I would have to do it again, but the MGTools folder was gone. (Does that mean it worked?)
    I thought that I would have to go to the software forum to get help on my Firefox, but I figured it out all on my own. (At least I hope I did.) I just had to go to the properties and update the default operating system. It worked, so I am going to assume that I am okay.
    Thanks you so much! You really do some wonderful things here. I think that you are all one step away from sainthood.

    Thanks again!
    Julie:wave
     
  12. julepakfan

    julepakfan Private E-2

    I figured I better add this information before I got too far down the line. I guess that I jumped the gun by saying everything was okay. I still cannot access firefox (or several other .exe programs) when I am on my "user" account. This is the same account that I was using when I picked up the malware. I am able to access internet explorer from my "user" account. Do you think it is just a software problem? Or do I still have issues with "xp security 2012" or "Zentom Security Guard?"
    Thanks so much!
    Julie:confused
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you want to be sure then you can run the scans on the "User" account and attach them here for me to have look at. :)
     
  14. julepakfan

    julepakfan Private E-2

    I can't run them on my user account. I just keep getting the "open with" box. I also noticed that I cannot open my Word programs (I get Application not Found error), although I can open documents that were created with Word and Excel...and I can click on new document and create and save. It just won't work when I try to open the program. I can't open games...such as solitaire, again, I get the "open with" box. Ugh...I hope this is something easy...but I am very afraid that it is not.

    I appreciate any suggestions that you might have.

    Thanks,
    Julie:(
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run through the below, and then try again to run all the scans.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper

    Then as stated, continue with the R&R, see what you are able to get through.
     
  16. julepakfan

    julepakfan Private E-2

    Unfortunately, I could not get the Rkill. Internet explorer would not even open the site that had the download. I did, however get the Malwarebytes to run (am attaching file). I almost had the Superantispyware going, but it froze the computer while loading its updates, then I couldn't start it again. Now when I click on it, it just puts the yellow bug down in my processes running box (or whatever it is called) at the bottom of my screen.

    I did find something interesting though. When I right click on my start button and click 'explore' I can see the program file for Zentom System Guard. It says it is a shortcut. I looked at the properties, but it would only let me look at the one tab. It says the target location is: A5AF55563008B1558230C6203803BC46 Then it gives the Target: 63008B1558230C6203803BC46\mllsic70nb.exe"

    It says to Start In: C:\Documents and settings\JulieP\ApplicationData\A5AF55563008B1558230C6203803BC46\"

    I don't know if this helps with anything. I will leave it alone until I hear from you. I will continue to get those other programs to download and run.

    Hmmm...actually I had two mbam logs. I think I saved one before I cleaned the items, then the program saved another one. I hope it's not too confusing. I will keep at it.

    thanks so much!
    Julie:confused
     

    Attached Files:

  17. julepakfan

    julepakfan Private E-2

    Okay, somehow I got some of the other programs to run. I know that combofix found something, because it had that Zentom address listed several times in the log. Yeah! However, it does still show up in my programs from the Start button.

    I can open my programs such as Word, Excel, and other games and such. But, I still cannot open Firefox...now I just get the hourglass for a few seconds, then nothing happens.

    I am wondering if malwarebytes and superanti spyware are supposed to start up every time I start the computer...because that is what they are doing. I did not purchase them, so I didn't think they were supposed to run automatically.

    I have a bunch of logs to attach...hope they help!

    Thanks again!
    Julie
     

    Attached Files:

  18. julepakfan

    julepakfan Private E-2

    Here is the combofix log.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now I am confused because the logs you have posted here now are from the same account as last time ( Administrator) I thought you were saying that the Admin account was ok but that you were having trouble with an account called "User"... I see no account called User.
    We might have you back up your bookmarks, try uninstalling Firefox properly using Revo soon and then reinstall.

    Why are these files on the desktop?

    Then just delete the entry.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    oinoryfr
    File::
    c:\documents and settings\Administrator\Application Data\cryptobjacl.exe
    c:\windows\system32\drivers\oinoryfr.sys
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files\Mozilla Firefox
    • C:\documents and settings\UserAccount\Application Data\Mozilla

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  20. julepakfan

    julepakfan Private E-2

    Before I do all of that, I just want to clarify that I am doing it right. I was not able to run any of those programs from my user account, so from admin. I right clicked the start button and went to my user account desktop and ran them from there...or so I thought. Obviously, that is not what happened. I have all of that stuff on my desktop because I saved stuff to my desktop so I could find it again. (Except when I was told to save it to C:) Honestly, I have no idea what most of that stuff is. Yikes...my ignorance is showing through.

    Will the combofix work if I am running it on my admin? Or, is there a way that I can give my user account privileges to download and run these programs? I am wondering the same thing about the new firefox...will I be able to access it on my admin and user accts. if I just put in my user name?

    This is all so confusing...I envy your knowledge and talent.

    Just to be safe, I will not do anything until I hear from you. (Except to delete that Zentom Guard icon.):-o

    Thanks again,
    Julie
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    These are the users I see on this machine. The bold red entry is the account we are trying to work on now, correct?
    This account had admin provileges and you should have no problems running my instructions. (You ran them just fine previously) :)
     
  22. julepakfan

    julepakfan Private E-2

    Actually, the one I am having problems with is user juliep...I think I might have figured out why it is not showing up anywhere. When I log in as administrator, the domain I use is different than the domain I use to log into my user account.

    I have been running everything on admin, because that is the only place they will let me run them.

    I was able to run exe.helper and malwarebytes on my user account. I am attaching the logs...not sure if they will do any good, but I will send them anyway.

    My plans for the rest of the evening are to run the combofix like you told me to...but I will have to do it as admin. on the same domain I already ran it, because it won't let me under my user domain. Then I will try to do the Firefox procedure that you told me to try.

    My computer is actually running pretty well, except for the Firefox...so I think that might actually help. Fingers are crossed!

    I am so sorry if I have been more trouble than most people. I will let you know what happens.

    Thanks again,
    julie
     

    Attached Files:

  23. julepakfan

    julepakfan Private E-2

    :p I think we have finally been successful!! As of now, everything is running fine! I have a lot of cleaning up to do though. I was looking at all of those files on my desktop and I am really not sure how they got there. It is like the Superanti Spyware folder just exploded...I think many of them are files out of that folder. I have no idea what I did to make that happen.

    I also want to find someplace to figure out exactly what all the processes I have running at startup...I don't think I need all of that stuff running...although my speed isn't terrible.

    Anyway, I am attaching the logs. Hopefully, it will all look okay to you.

    I am planning on purchasing the Superantispyware, should I just click on the link in the program, or can I purchase it directly from Majorgeeks.com? I definitely want you guys to make the sale.

    Now you have me motivated to get my other computer cleaned up...no viruses, just slow. (But that's another story.):-o

    Again, I cannot thank you enough!
    Julie
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, as you are planning to purchase it, let's uninstall the version you have first of all using Revo: Try Revo Uninstaller. http://majorgeeks.com/Revo_Uninstaller_d5706.html

    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    Yes, click on the link, that will suffice.

    c:\documents and settings\Administrator\Application Data\cryptobjacl.exe <--- delete this file.
    Considering I am not terribly busy I suppose it would not hurt to touch on some of that here:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    (Please note, this is not malware, we are just trying to free up some resources.)

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Documents and Settings\Administrator\Desktop\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-21-1272985333-7236016-1905203885-1445\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'JulieP')
    O4 - HKUS\S-1-5-21-1272985333-7236016-1905203885-1445\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'JulieP')
    O4 - S-1-5-21-1272985333-7236016-1905203885-1445 Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (User 'JulieP')
    O4 - S-1-5-21-1272985333-7236016-1905203885-1445 User Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (User 'JulieP')


    After clicking Fix exit HJT.



    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Aug 24, 2011
  25. julepakfan

    julepakfan Private E-2

    Thanks, Kestrel13! My computer is running beautifully...better than it has in a long time. I really appreciate all that you have done for me. I am attaching the log that you asked for.

    Thanks again,
    Julie:)
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds