Virus, trojan im not sure Mbam combofix wont run

Discussion in 'Malware Help (A Specialist Will Reply)' started by tgreen300, Dec 16, 2010.

  1. tgreen300

    tgreen300 Private E-2

    Trying to clean up my girlfriends computer its running and slow and whenever I try to run any known Malware removal apps they all stall Mbam, combofix, Mgtools, Avira I even tried in safe mode im at loss here and any help is greatly appreciated I have attached what little I think I could get to run
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. tgreen300

    tgreen300 Private E-2

    Thanks so much patiently awaiting
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.

    Rename Combofix.exe to coconut.com and rename MGTools.exe to magpie.com try running them in normal mode first, if not safe mode, then let me know how you get on.
     
  5. tgreen300

    tgreen300 Private E-2

    Renamed both and neither went through could not complete online scan they alll stall a few mins in
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. tgreen300

    tgreen300 Private E-2

    Hello well now I can only boot in safemode and the same thing happens with OTL runs but never completes locks up as well at the bottom it says scanning driver Tcpip....
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to start : Type in Cmd click on cmd.exe

    Type in tasklist and press enter > select all > save to a notepad and attach here.
     
  10. tgreen300

    tgreen300 Private E-2

    I burnt the freakin cd in for the life of me it won't boot
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And what about a response to my post #9?
     
  12. tgreen300

    tgreen300 Private E-2

    Sorry abou that was trying to boot from the disc yet I have attached the task list from safe mode
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have UAC diabled and have you rebooted at least once after disabling it? UAC must remain disabled all thru the cleanup process. If not, you need to do this.

    After trying what Kestrel13! last posted, please try the below.



    Now attached the C:\MGlogs.zip file no matter what problems you run into above.
     
  15. tgreen300

    tgreen300 Private E-2

    Ok thanks guys. I tried the renamed ones with no luck. UAC is disabled when I ran through command prompts as admin most went through until I got to analasyse then the system froze again. I attached the MGtools.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you ran these last scans from the command prompt, did you have no network connectivity? It looks like there is no network drivers or hardware present. Was this because they were run in safe mode and your drivers do not load in safe mode? If you ran in safe mode, can you run them in normal boot mode and also reverse the order of analyse and GetRunKey since analyse froze last time?


    Also run the below ( try normal boot mode but you can use safe mode if necessary ).



    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
    Last edited: Dec 23, 2010
  17. tgreen300

    tgreen300 Private E-2

    Unfortunately I am only able to load in safe mode now it wont boot in normal mode. Thanks for the help to this point pretty frustating. I attatched TDSS
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then I sugget that you see if you can run System Restore to try and go back to a Restore Point from before the time the problem began. Thus far, there are no signs of malware. Your problems could be with Windows itself.
     
  19. tgreen300

    tgreen300 Private E-2

    Ok its just strange it just locks whenever I try to run any malware removals ..... and now states there are no restore points now .... I don't know what to do
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running the below and attaching the log.

    Using ESET's Online Scanner


    What was your exact problem with running the Avira CD? Did you burn it iso image properly to make it a bootable CD? You cannot just copy/burn the file directly to a CD as that would just basically make a copy of the file but not make it a bootable CD. Also did configure your PCs BIOS to boot from the CD before the hard disk.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds