Viruses Gone - But ??

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sue548l, Jul 20, 2009.

  1. Sue548l

    Sue548l Private E-2

    Hello,

    I had several problems with my laptop. Followed the malware removal guide and everything seems great. Except for one thing - after running combo fix I can not get on the internet. It searches and searches and never finds an IP address. I also can not seem to find the log file that combo fix created. Can anyone help me figure this out?

    Thanks,
    Suzy
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your Combo log should be at C:\Combo.txt.

    Please attach at least the C:\MGLogs.zip.
     
  3. Sue548l

    Sue548l Private E-2

    OK,
    Here's the combo fix log and a copy of the ipconfig. I can not find any MGlogs on my laptop???
    Thanks, Sue
     

    Attached Files:

    Last edited by a moderator: Jul 24, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you actually go thru the entire Read and Run First instructions?

    If so you need to ATTACH the requested logs:
    SAS
    MBAM
    RootRepeal
    C:\MGLogs.zip --> from running the C:\MGTools.exe

    Read this:
    HOW TO: Attach Items To Your Post

    Your log of your ipconfig shows you have no IP address. You can try using SAS to repair your connection, but if that fails, and it is not a malware issue, then I will direct you to the networking forum.
     
  5. Sue548l

    Sue548l Private E-2

    OK,
    logs are attached. Reran SAS still no internet. Also receiving a Generic Host Process for win32 Services error when I go to shut the laptop off. This also appeared after running combo fix. This laptop seems to be sarting up slower and slower.
    Thanks, Suzy
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans took care of most of it....so let's just do this:

    What is this:
    C:\Documents and Settings\Nancy\Desktop\antivirus

    Please make sure msconfig is set to normal startup.

    Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.

    Please use add/remove programs to uninstall:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME
    Java 2 Runtime Environment, SE v1.4.2_03

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt10.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt11.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt14.xml 
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt15.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt16.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt1c.xml    
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt1d.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt1e.xml   
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt21.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt22.xml   
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt23.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt29.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt2a.xml    
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt2b.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt2e.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt2f.xml     
    C:\Documents and Settings\Nancy\Local Settings\Temp\imt30.xml    
    C:\Documents and Settings\Nancy\Local Settings\Temp\imte.xml    
    C:\Documents and Settings\Nancy\Local Settings\Temp\imtf.xml
    
    Folder::
    C:\Program Files\PersonalAV
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PersonalAV]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. Sue548l

    Sue548l Private E-2

    Tim - Thanks for help so far.

    I have a few questions before I begin the instructions you sent.
    Do I need to turn off system restore before I start?
    Also, If combo fix wants to upgrade it won't beable to will this cause a problem?

    The file you asked about on the desktop named antivirus contains all the icons for the programs I downloaded and ran, plus the antivirus and malware programs that were perviously on this laptop. The laptop belongs to a friend who aidmitted last night that she had turned off the symantec antivirus because she thought that was slowing the laptop down.

    Thanks again, Sue
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    NO! Leave system restore alone until you are clean and I give you final instructions.
    I suggest that you download a new copy of ComboFix to a different computer and then transfer it to you desktop via either cd or thumb drive. Then just drop it on top of the old version.

    It can cause slow-downs...but she should have replaced it!
     
  9. Sue548l

    Sue548l Private E-2

    Tim,

    My friend got tired of waiting for me to get it running. Instead she decided to take it in to have it fixed.

    Thank you for the time you spent looking at the logs and giving advice. I did learn several very useful things from your posts. And if I every have a situation like this occur again - I will go about it in a much more methodical fashion and will have a check list for each step.

    Thanks again !!!
    Sue
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds