TornTv, System Restore not working

Discussion in 'Malware Help (A Specialist Will Reply)' started by slapper121, Jan 23, 2014.

  1. slapper121

    slapper121 Private E-2

    I downloaded a torrent, had problems, tried to erase a bunch of stuff, and now have the following problems
    1. Cannot remove/delete/uninstall TornTv
    2. homepage changed/wont connect to internet and changed to conduit search from google
    3. "NTLDR is missing" and wont boot without a disk (I think I may have erased something i shouldnt have)
    4. System Restore seemed to do nothing

    I downloaded, scanned, and made logs. here they are:

    My Malwarebytes has 22 logs, do i need to attatch them all?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs did not attach, and yes you need to attach all of them please. :)
     
  3. slapper121

    slapper121 Private E-2

    sorry heres all but the malwarebytes logs
     

    Attached Files:

  4. slapper121

    slapper121 Private E-2

    mbam logs 1-5
     

    Attached Files:

  5. slapper121

    slapper121 Private E-2

    mbam logs 6-10
     

    Attached Files:

  6. slapper121

    slapper121 Private E-2

    mbam logs 11-14. i think this is all of them
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't know why you attached 11 empty Malware Bytes logs, showing nothing found. That was unnecessary, but never mind.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : NextLive (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Owner\Application Data\newnext.me\nengine.dll",EntryPoint -m l [-][-][x]) -> FOUND
    • [RUN][SUSP PATH] HKUS\S-1-5-21-1960408961-1364589140-839522115-1003\[...]\Run : NextLive (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Owner\Application Data\newnext.me\nengine.dll",EntryPoint -m l [-][-][x]) -> FOUND


    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman and have it remove items under the headings Malware and Potential Unwanted Programs.



    If you did not deliberately set this proxy yourself (seen in the HJT log) then please include it in the HJT fix further below:
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;<local>
    • O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe

    After clicking Fix exit HJT.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Documents and Settings\Owner\Desktop\TornTV.lnk
    C:\Documents and Settings\Owner\Local Settings\Application Data\genienext
    C:\Documents and Settings\Owner\Local Settings\Application Data\io7x3tnn4g674j0qr3y08
    C:\Documents and Settings\Owner\Local Settings\Application Data\Mobogenie
    C:\Documents and Settings\Owner\My Documents\Mobogenie
    C:\Documents and Settings\Owner\Start Menu\Programs\TornTV.com
    C:\Program Files\Mobogenie
    
    :reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "mobilegeni daemon"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.




    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. slapper121

    slapper121 Private E-2

    i dont have a MGtools\analyse.exe thats seperate only the one thats part of the MGtools. i ran the whole MGtools scan but dont see where to fix anything.
    should i download HijackThis and scan?

    The newest rouguekiller log is attached
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should have C:\MGTools\analyse.exe

    Check again please.
     
  10. slapper121

    slapper121 Private E-2

    ok you were right i found and ran the analyse.exe and followed the other instructions. logs attached

    my pc is running much better. everything seems resolved except for this boot issue. still says "NTLDR is missing" and have to boot with a disk. thanks for your continued help
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So you ARE set up to use this proxy?? :confused

    Topic for the software forum I suspect.
     
  12. slapper121

    slapper121 Private E-2

    Yes. I was able to fix the NTLDR thing on my own. Things are working normally. one question: should i attempt a system restore to a date before all this or just go forward from here? Thanks very much for your help
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No offence, but why system restore if all is working well? :)

    You are most welcome for the help. You ready for final steps if everything's running nice?
     
  14. slapper121

    slapper121 Private E-2

    I was wondering if it would make my pc boot normally like before I had to replace these NTLDR files. And also I guess I assume theres other missing files but maybe thats not the case
    Yes, I'm ready to finish this
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds