Should I just Reinstall Vista?

Discussion in 'Malware Help (A Specialist Will Reply)' started by kevgeez, Aug 26, 2009.

Thread Status:
Not open for further replies.
  1. kevgeez

    kevgeez Private E-2

    I have thoroughly read the READ and RUN beginners guide.
    I would gladly just go thru it, but I can't open SAS, or MGTools after downloading them.
    I hate to start another thread on this topic, but the other threads I read don't really have my problem.

    Are the directions telling me to put the MGTools.exe inside my C: folder?
    It wont let me do that.

    I'll include my HJT log. Hopefully it helps.
    Btw i ran HJT a couple days ago, and i think i may have deleted some important things thinking they were maleware.
    I was following the HJT tutorial at the time.

    Should i just go ahead and reformat my hard drive/reinstall Vista?
    I'm tired of all these problems.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you tried running steps in safe mode? have you tried renaming the set up files for SAS? What happens with Malware Bytes Anti-Malware?

    Yes it needs to be on the root folder of the drive where you have installed Windows (Typically this would be C:\ )

    If you installed HJT correctly then there will be an option to backup the changes that you made. We will sort that out soon.

    Not yet - let's see what happens after you rename SAS and MBAM (if you couldn't get that to run either) and also we will try renaming MGTools.exe to 123.com.

    Were you able to run RootRepeal or not?

    Do try running steps in safe mode too and let me know what happens.
     
  3. kevgeez

    kevgeez Private E-2

    I'll try to make this short

    Mbam worked as usual.

    SAS worked finally. I had to go into the admins profile(my old profile)* and run it. Then when i went back to my new profile, the logfile was still there.
    :)

    Combofix worked, but I had to leave the house during the scan.
    My sister came in and chose "no" after the restart....i hope that wasn't a big deal. So Combofix was run twice. This is what happens when you use a family computer...yes i'm working on getting my own.

    MGTools....:(
    I still dont know how i got it to work. Anyway, i had it right, but i cant find the log anywhere.
    New MGtools scans aren't making a new log either.


    At first RootRepeal was working....but i was not expecting it to take 4 hours.
    So i stopped the scan 4 hours into it, and now i can't run another one.
    Kept saying an error.
    I'm going to run rootrepeal again...but not until i go to bed. I'm not going to sit up and wait for it to finish again.
     

    Attached Files:

  4. kevgeez

    kevgeez Private E-2

    The other Problem I've been ignoring.

    *This is a family computer. 6 different profiles. I have two. In my old profile i came across some kind of virus that makes a black box pop up constantly. A white box pops up along with it asking me to "close" or "Ignore"
    It has something to do with NDTCV Error, wucaultexe., and the sytem32 folder.
    I'm at a loss on it.

    I posted in other malware removal sites around the internet and no one helped(for that black ghost box problem).
    So i finally figured to make a new profile a let it be a standard user profile, and keep the old one there.
    So instead of fixing my problem, i just ran away and forgot about it.
    :-D
    But that problem is still there.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs created from running MGTools should be at: C:\mglogs.zip.

    If there are several accounts on this family machine then it would be a wise idea to run the scans on each account. Attach the appropriately named logs here.


    I shall take a look thru the logs you have provided me with and again, will get back to you ASAP. Thanks for your patience.

    IMPORTANT
    : on reviewing your MBAM log I see that it found alot! But that you took no action, you need to rescan with MBAM and let it fix what it finds this time round.

    Kes13!
     
    Last edited: Aug 31, 2009
  6. kevgeez

    kevgeez Private E-2

    ...hmm
    I think the log saved before I removed the bad stuff after MBam was done.
    I removed it instantly.


    Also, when i run the scans, it does scan all the profiles at once whether i do a quick scan or a complete scan.

    And i still cant get RootRepeal to run again.
    Its has an error box popping up saying: "Decompression error 5"
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's do this:

    1. Do actually use the iWin Games? If not, I suggest removing them. It may not show in Add/Remove programs so please uninstall it if you don't bother with it.

    2. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    DirLook::
    c:\windows\system32\Service
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3. Now we need to replace some missing files, to do this please refer to the below:

    Running SFC Scannow


    4. Go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    5. Run the new MGTools.exe and report any errors you may receive. Attach the log it generates C:\mglogs.zip and also the log from running Combofix.
     
  8. kevgeez

    kevgeez Private E-2

    New results

    No bluescreens, or freezes since running the Combofix the yesterday.
    This was before even running MGTools.
    Hopefully everything is good.

    It did freeze a couple times when my lil bro was playing his online game called "Grand Chase"
    The black ghost box popups still exist on the admin profile.

    Everything else is good.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: New results

    You didnt answer my question in step 1 regarding iwin games. :)

    Did you complete step 3 which was to run scannow?
    we will discuss this further soon.
     
  10. kevgeez

    kevgeez Private E-2

    Re: New results

    I deleted that iwin stuff but forgot to post it.

    I ran scannow before doing MGTools. I dont remember there being a log for it afterwards.
    I noticed the thing I'm attaching on the admin desktop recently though.
    Idk what it is.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I believe it's time we now had you restore what you "fixed" with HJT. :)

    1. Run the original HiJackThis from the original location and restore what ever you removed. To do this please see the below:

    • Once HJT is opened up, under "other stuff" section click on CONFIG.
    • Next hit the "Back up's" tab.
    • Place a checkmark next to the items you fixed.
    • Then choose to "restore"

    2. Now tell me if you deleted any files on your own? Files you may have suspected were baddies? If so can you recall what they were and let me know if you do remember.


    3. In msg # 8 you said the below:
    Are you referring to a command prompt window? When you say 'admin profile', did you really mean the Administrator account? Or did you mean some other user account and if so specifically which account has the problem? Also are the logs being posted for the account with the problem? Could they be related to the Windows Parental Controls (WpcUmi.exe) software that is running?

    Now please do the below:

    4. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    Kes13!
     
  12. kevgeez

    kevgeez Private E-2

    I do not remember which files got deleted in HJT.


    No, when we first got this computer there was only one profile/account.
    I split them up into 5 different accounts. I was originally using the account, but when the problem started, I created another account for myself, and left the old one alone. I designated that one as the Administrator. The command box problem only happens in that profile. I had the problem in my new profile, so i decided to make my new profile a "Standard" profile.
    The pop up box problem ceased to exist.
    So that is why i keep the old one as the Admin account.

    The problem is there's a black command box that pops up in 3 different ways.
    Flashing repeatedly
    Flashing every 15 seconds
    Popping up and staying there unless i minimize the box.
     
  13. kevgeez

    kevgeez Private E-2

    Posting this from the admin account

    And i'm noticing everything is pristine so far.
    No wuauclt pop up boxes at all.
    :)
    Here's the MGlogs zip file.
    I didnt have time to do it yesterday.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please put this machine into normal start up mode before we continue, by using MSCONFIG.

    2. Please go to Add/Remove Programs and uninstall the following older version of Java:

    • Java(TM) 6 Update 13

    3. Why are you using this machine without being protected by any anti-virus?!

    4. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Not a wise idea to place any site into your TZ. So fix optionally.

    After clicking Fix exit HJT.

    5. Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    AVG Free8 E-mail Scanner
    AVG Free8 WatchDog
    
    File::
    C:\Windows\system32\CF18658.exe
    C:\Windows\system32\CF29953.exe
    C:\Windows\system32\avgrsstx.dll
    
    Folder::
    C:\PROGRA~1\AVG
    C:\Users\owner\AppData\Roaming\AVG8
    C:\ProgramData\Viewpoint
    C:\\Program Files\AVG\AVG8
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "combofix"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "combofix"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG7Uninstall]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG7Uninstall\Directories]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  15. kevgeez

    kevgeez Private E-2

    ...

    ok, i'll attempt to install an Anti-virus program.
    ...But what i was wondering is do i really even need an AV program?
    I think the whole deal is a bit suspicious and shady.
     

    Attached Files:

    Last edited: Sep 14, 2009
  16. kevgeez

    kevgeez Private E-2

    Avg

    for some strange reason, the computer will not let me install AVG....i'll try some others, but this is the reason i dont use an anti-virus program.
     
  17. kevgeez

    kevgeez Private E-2

    I didnt install an anti virus, but i did grab two different ones on the AV page here.
    One is Anti-Worm, which doesnt install, but you can run it whenever you want to.
    The other is like that, in that they are both executable that sit on the desktop until they are used.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. FYI: if things seem a little slow:
    2. As for the installation of avg that is incomplete (I do see services running from it) you would be best off working it out in the software forum but I can suggest you use their removal tool:

    Try running the AVG Removal Tool: AVG Remover(32bit) Read the info here http://www.avg.com/download-tools and make sure you reboot after running it.

    3. You are running ComboFix from the wrong location:

    It should not be inside a folder, its executable should be sat directly on your desktop! Please move it to the desktop now before we move on.


    4. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    c:\users\owner\AppData\Local\temp\EAD3A41.exe 
    c:\users\owner\AppData\Local\temp\EAD3A41.exe ?
    C:\Users\owner\AppData\Local\temp\EAD890C.exe
    C:\Users\owner\AppData\Local\temp\EAD890C.tmp
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif



    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    6. Run the new MGTools.exe and afterwards please attach the C:\mglogs.zip file that it generates into your next reply as well as the C:\combofix.txt from running ComboFix.

    7. Let me know how things are running now.
     
  19. kevgeez

    kevgeez Private E-2

    everything is running fine.
    A bit slow though. Yes i have to upgrade the RAM.
    1.5 isnt enough for anything.
     

    Attached Files:

  20. kevgeez

    kevgeez Private E-2

    usb

    I'm noticing that the joystick on my USB Arcade stick is not registering.
    The buttons are though.

    It was fine before i ran combofix, and MGTools today.
    I was using it right before i ran them.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you knowingly install the Ask Toolbar? If not then please go to add/remove programs and uninstall it. Let me know.

    Thanks
    Kes13!
     
  22. kevgeez

    kevgeez Private E-2

    Just Deleted the Askbar

    :cool

    that other post about the USB...just ignore it.
    Its fixed already.


    The Ask Toolbar*
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: ask toolbar - did you knowingly install it and want it on your machine?
     
  24. kevgeez

    kevgeez Private E-2

    No. I dont use toolbars.

    I guess my Utorrent program got deleted during this cleanup project...

    Should i download the program again?
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then please uninstall the ask Toolbar.

    Your last combofix log was incomplete. I will need you to rerun my last script in post #18 step #4. Ensure please that before doing so Combofix is indeed on the desktop in it's proper location.

    Yes you should reinstall your utorrent if necessary.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  26. kevgeez

    kevgeez Private E-2

    ..........

    :cool
    things are running good.
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it. Now just the below to do and we can wrap up.

    Navigate to the following bold directory and delete it.
    • c:\programdata\avg8

    Now please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Important:
    Install yourself some antivirus from the "How to protect yourself from malware" link. I know you think it's 'shady' but you really ought to secure your machine with that layer of protection, otherwise, you may be back here in a week with a fresh set of problems. ;)

    Now follow the below instructions:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. kevgeez

    kevgeez Private E-2

    Uninstall Combofix?

    I don't have the money for an Anti virus at this moment...so i'll look at your free ones.
     
    Last edited: Sep 28, 2009
  29. kevgeez

    kevgeez Private E-2

    Ok Everything is cleaned out.

    I'm gonna try Avast again. It worked well last time i had it.
    I still have avg8 in my system somewhere...so i'll look around to see if i can get rid of it somehow.

    Thanks a lot for the help!
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Ok Everything is cleaned out.

    I have used avast! for a while and am satisfied with it.

    Didn't the avg removal tool help that I posted here in my step # 2?

    The following folder is all I see left of avg:

    c:\programdata\avg8

    You're very welcome. Safe surfing:)
     
    Last edited: Sep 29, 2009
  31. kevgeez

    kevgeez Private E-2

    Computer freezing up all crazy

    I dont have long to type this before my computer freezes again.
    I shouldnt say "freeze"....its saying mozilla isnt responding.
    :(
    I downloaded MGTools again in hopes that you could tell whats that problem with the computer.

    I'm thinking its because i have:
    SAS
    Comodo antivirus
    Mbam
    Spybot s&d

    I cant think of any other reason why its freezing like this.
    Also, the fan is buzzing heavily... when all this is going down.
    I open task manager and its saying the computer is running on 100%
    o_O

    Any advice?
     

    Attached Files:

    Last edited: Oct 8, 2009
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean.

    But this is a problem, especially when running Vista. You need a memory upgrade!
    You will need to work out any other issues you have in the hardware or software forums.
     
    Last edited by a moderator: Oct 8, 2009
  33. kevgeez

    kevgeez Private E-2

    cleaning up XP laptop

    hey.
    i have a laptop and i'm goin thru the XP cleanup procedure.

    This thread was for my Vista Computer.
    That computer is running great.
    I noticed something in the Combofix tutorial that is different here.

    The tutorial doesnt say anything about using CFScript to startup combofix.

    Should i go ahead without the CFSript?
     
  34. kevgeez

    kevgeez Private E-2

    .........
     
    Last edited by a moderator: Apr 21, 2010
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: cleaning up XP laptop

    You should have started a fresh thread. Continuing here will make things awkward and confusing. Please follow the instructions in the R&R very carefeully. :) I am going to lock this thread now and you can begin a new thread in malware removal.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds