trojan? combo, RR, and MG tools are hanging!

Discussion in 'Malware Help (A Specialist Will Reply)' started by frederic99, Dec 22, 2010.

  1. frederic99

    frederic99 Private E-2

    Hi,
    I have not been able to complete the whole Vista cleaning process because the last three steps are hanging: Combofix, RRepeal, and MG tools are hanging.

    Here are the two files from SuperAntiSpyware and Malwarebytes. I have also attached log for RR with error code.

    FYI, before I decided to open this forum, Spybot had found win32.autorun.tmp.

    Thanks for your help. Fred.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Is the only reason that you are running the clenaing procedure due to what Spybot detected or are you having some actual malware problems?
    • Have you shutdown all of your protection software including firewall before trying to run these?
    • Have you disabled UAC and rebooted your PC after disabling? UAC must remain disabled during cleaning.
    • If you have done both of the above and still have a problem, see if you can run ComboFix and MGtools in safe boot mode.
     
  3. frederic99

    frederic99 Private E-2

    I have had an issue with my credit card which has been compromised. My gadgets stopped working and found some small issues here and there. Enough to make me suspicious.

    I am sure you saw that trojan 'fake alert' in Malwarebytes log.
    * Have you shutdown all of your protection software including firewall before trying to run these?
    >> YES
    * Have you disabled UAC and rebooted your PC after disabling? UAC must remain disabled during cleaning.
    >> YES
    * If you have done both of the above and still have a problem, see if you can run ComboFix and MGtools in safe boot mode.
    >> will do now.

    thanks. F.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but it removed it. So I was wondering what exact problems you were still having. If your credit cards have been compromised then you need to take serious action on them ( getting accounts and passwords changed ). And do you know for sure that they were compromised via this PC? Could it have been from another PC you use? Or even from physically using the credit card somewhere especially at an airport?

    No matter the outcome from trying to run those scans in safe boot mode, still run the below.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  5. frederic99

    frederic99 Private E-2

    Here is the log for TDS Skiller. Looks like it is clean.
    The only problem I have seen today is that sometimes the PC prevents me to run some tasks because I am not log as administrator; this is of course not true.

    I am leaving for 12 days vacation. I would like to thank you for your time and help. I will read your reply when I come back.
    In the mean time, please take care and I wish all of you a Merry Christmas.
    Fred.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you are not logged in as the Adminstrator. You are just logged in with a user account that is a member of the admin user group which is not really the same. However, there are many noted cases of people having permissions issues with Win 7 and Vista and many of these are not due to malware which means we may not be able to address them in this forum. More problematic is that I have never seen any real fix.... at least not an easy one. You may have to treat each case of these "permissions issues" on a one by one basis. Give me a couple of very specific examples.


    We also need to figure out why you cannot get MGtools to run. Get those logs may give us some helpful info. To that end, please do the below

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the log: C:\MGlogs.zip


    If MGtools still did not run, try doing the below.

    Boot into Safe Boot mode.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds