Unable to run scans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by alway1, Sep 1, 2011.

  1. alway1

    alway1 Private E-2

    Hello:

    I am having some problems with my computer. I got the following message on two separate occasions:

    “Unknown device installed. The device has been successfully installed.” This is the message that brought me to this forum.

    I downloaded and saved to my desktop the five programs recommended in the ‘read me’ thread, but was unable to run them.

    Super Anti Spyware –I got the following message, “Set up requires administrator use.” I right clicked to attempt to run as an administrator but still no luck.

    MalwareBytes - I got the following message, “The setup files are corrupted. Please obtain a new copy of the program.”

    ComboFix- I got the following message, “Installer integrity check has failed. Common causes include incomplete download and damaged media. Contact the installer's author to obtain a new copy.”

    RootRepeal – I got the following message, “Windows cannot open this file."

    If you could let me know exactly what’s going on and why I am unable to run these programs, it would be appreciated! Also, I have two questions:

    1) If I am signed on under one user, will these scans capture everything from each user of this computer?

    2) How exactly do I uninstall these corrupted programs? I tried to uninstall via the control panel and did not see the names of any of the five programs I downloaded.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you downloaded them to your desktop and they wouldn't install, then just right click them and delete them. You didn't mention what happened when you tried to run MGTools. Did that error out as well?

    Did you try running any of the tools in safe mode?
     
  3. alway1

    alway1 Private E-2

    Hi Tim W:

    Thanks for your response. I did not mention MGTools because I was able to run it. Yes I tried safe mode. Should I be running these things as an admin or just a regular user?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach that log --- C:\MGLogs.zip

    Yes, you should be running these scans on an account with Admin. privileges. ;)
     
  5. alway1

    alway1 Private E-2

    Hey Tim:

    MG Tools is currently on an account that does not have admin rights. Is there a way I can move MG Tools to an admin account?
     
  6. alway1

    alway1 Private E-2

    Also, should I disable user account control before I run MG Tools?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to disable the UAC control before running any of the scans. If you need to, switch into an account with Admin, privileges and download MGtools and save it to your root folder. If you can't get it to the C: drive, just run it from the desktop.
     
  8. alway1

    alway1 Private E-2

    Hey TimW:

    Just to be clear, any of the programs that I did not download under an admin account have to be dowloaded again? There is no shortcut or way to reroute this?

    Also, how much info will MG Tools reveal? I am a little concerned about my privacy since this is a public forum.

    Back to my initial question, what exactly do you think this message means? “Unknown device installed. The device has been successfully installed.” It is a clearly a virus?

    Thanks again TimW for all your help!
     
  9. alway1

    alway1 Private E-2

    Hey Tim:

    While running MGTools and I got a pop up message from HiJackThis:

    "For some reason your system denied write access to the Host files. If any
    hijacked files are in this file, HijackThis may NOT be able to fix this..."

    I did not have HiJackThis running at the time.

    Do you have an idea as to why this would popup?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is part of MGTools. Don't worry about it, we can try running it later. And don't worry about any info the scan will produce, it will not reveal anything that could make you vulnerable. ;)
     
  11. alway1

    alway1 Private E-2

    brb...
     
  12. alway1

    alway1 Private E-2

    Hey TimW:

    The MGTools scan is finished. I tried to find C:\MGLogs.zip as I browsed my files, but still no luck. Perhaps it's filelog.txt?

    Thanks again for your patience!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double click My Computer and look on the C: drive. It will be there.
     
  14. alway1

    alway1 Private E-2

    Hey TimW:

    I tried what you just suggested and the only thing I see related to MGTools is the MGTools folder. I don't see C:\MGLogs.zip.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  16. alway1

    alway1 Private E-2

    Hey TimW:

    Thankfully I was able to successfully scan this and attach this log. Let me know what's going on and more importantly what I need to do next to fix this issue ;)
     

    Attached Files:

  17. alway1

    alway1 Private E-2

    Hey TimW:

    When I first attempted to run SuperAntiSpyware I got the message, “Set up requires administrator use.” I attempted to open it again later on and didn't have any problems.

    I didn't make any changes to my computer, so I'm confused as to why the program finally opened for me. If you could offer insight to this issue, it would be most helpful!

    The log for SuperAntiSpyware is attached.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware so far. Please uninstall:
    Viewpoint Media Player

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  19. alway1

    alway1 Private E-2

    Hey TimW:

    Thanks for checking out my logs. Attached is the MGTools Log. As always, your assistance is most appreciated!
     

    Attached Files:

  20. alway1

    alway1 Private E-2

    Hey TimW:

    I was able to run ComboFix.

    The log is attached
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, we can clean up a few things.

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 2

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\Temp\TMP0000004579AB787D32BAEDB8
    
    Folder::
    C:\WINDOWS\Temp\1f5dc264-7ce9-4396-993c-00a261e1158f
    C:\WINDOWS\Temp\2af13a74-b886-41d0-90f3-d34cc70fbc11
    C:\WINDOWS\Temp\34703cc8-0699-4910-8abc-34d29372a218
    C:\WINDOWS\Temp\7a8e270b-c516-4ccd-a1dd-b28582dbd507
    C:\WINDOWS\Temp\7df20854-fcce-4a0f-9eab-8a44413c27c3
    C:\WINDOWS\Temp\97fba513-b86d-42c2-85b1-fe15050934fd
    C:\WINDOWS\Temp\d6afc652-276a-41b8-9d50-84abde824d73
    C:\WINDOWS\Temp\e0f675a4-4543-47e4-8f8c-c8eb2dd05e41
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now download and install:
    Java Runtime 6

    Now tell me what issues you are still having, as I may need to send you to the software forum for additional assistance.
     
  22. alway1

    alway1 Private E-2

    Hey TimW:

    1) I did not see the line below when I ran C:\MGtools\analyse.exe, so I could not delete it:
    2) When running combofix, i got this message:
    What is this and what does that mean for my PC?
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a fault with Combo. You need to tell me what issues you are still having, if any.
     
  24. alway1

    alway1 Private E-2

    How can I delete this line:
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    Where can I find it in the log?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it is not showing in HJT ( analyse.exe in the MGTools folder), then don't worry about it.
     
  26. alway1

    alway1 Private E-2

    Hi TimW:

    I am concerned by that line. if it isn't necessary, I would like to remove it from my computer. Please let me know how I can delete it since it is not showing up in the HiJack this log.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If it is no longer showing in the HJT log, then it is already gone. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds