temp stopped and pop ups come

Discussion in 'Malware Help (A Specialist Will Reply)' started by suzie290304, Mar 20, 2008.

  1. suzie290304

    suzie290304 Private E-2

    mt tmp 0 1 2 3.exe has stopped working and i keep on getting pop ups i have run super anti spyware and deleted what was there but keep on getting them then i ran hjt

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:57:44, on 20/03/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16609)
    Boot mode: Normal


    would love sum help to sort out the problem x x x
     
    Last edited by a moderator: Mar 20, 2008
  2. Lev

    Lev MajorGeek

  3. suzie290304

    suzie290304 Private E-2

    done scans they r


    ComboFix 08-03-22.1 - suzie290304 2008-03-22 19:24:28.1 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.318 [GMT 0:00]
    Running from: C:\Users\suzie290304\Desktop\ComboFix.exe
    * Created a new restore point


    any other that will help just let me no x x x
     
    Last edited by a moderator: Mar 23, 2008
  4. Lev

    Lev MajorGeek

    You did not post up the logs in the way they were requested in the link I provided. Please try again, following all instructions step by step.
     
  5. suzie290304

    suzie290304 Private E-2

    sorry have done scans here they are x x x
     

    Attached Files:

  6. suzie290304

    suzie290304 Private E-2

    i have just noticed that i can now not get into my documents and settings on disk drive c it says access denied not accessible x x x :cry
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this:

    First Disable Spybot's TeaTimer as requested in the READ ME

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  8. suzie290304

    suzie290304 Private E-2

    hi i have no more pop ups but still cant get into my documents and settings in hDD c still says access denied would love to resolve this matter thanks for your help here r the scans you asked for x x x :)
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not sure about the access ....I take it that right clicking the folder and choosing properties does not give you a security tab?

    (I will ask about this issue if it turns out to not be the malware).

    I looks like you did not let the C:\MGtools\MGGet.logs.bat did not run completely as the only file was the processes scan. Please run it again and attach the new MGLogs.zip
     
  10. suzie290304

    suzie290304 Private E-2

    hi its says application has generated an exception that could not be handled

    process id = 0x16ac (5804), thread id 0x1670 (5744) x x x
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Running the GetLogs.bat produced that error?

    Uninstall and re-install it. See if that corrects the problem.
     
  12. suzie290304

    suzie290304 Private E-2

    also when i right click documents and settings it does bring up tab of properties, it does have a security tab on it, it has group user names which are, everyone, system and administrators, but in the allow and deny list it has only got ticks for special permissions, in the allow for all three group and user names , and deny in the special permissions for the everyone, group are user name. also in the advanced setting it say the current owner is the system x x x
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Add your user name and give it full permissions.
     
  14. suzie290304

    suzie290304 Private E-2

    it produced another error which is process id=0x1078(4216) thread id= 0x1368 (4216) and said something about a dll i dont no if it has something with not being able to access my documents and settings because when i install it it comes up with another error access denied and at the end it says registered jit bugger not available cordbg.exe!a 0xaf4, i have added my name to folder documents and settings and gave myself full control but when i clicked apply it said access denied will not save changes x x x
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Our resident Vista expert has suggested the following .....

    1. Download and install the SubInACL utility http://www.microsoft.com/downloads/d...displaylang=en

    2. Create a new text file named fix_registry_permissions.bat and add the following text and save.


    3. Run the file from the elevated command prompt ( click Start > type in Start Search box CMD, then right click its icon and choose "Run as Administrator".

    Tell me if that works.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds