Vista MG log

Discussion in 'Malware Help (A Specialist Will Reply)' started by begin82, Oct 10, 2008.

  1. begin82

    begin82 Private E-2

    just ran some scans because computer has been freezing lately and a little slower than usual but nothing came up on any scans
    did not use combofix because its much more complicated than i remember ( i don't remember anything about the recovery environment before)

    any was i am adding only the main scan from MG

    Thanxs in advance
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Welcome to Major Geeks, begin82

    Please attach the remaining requested logs:

    SASlog.txt log from SuperAntiSpyware.
    Malwarebytes Anti-Malware log
    ComboFix.txt (normally C:\ComboFix.txt)


    dr.m
     
  3. begin82

    begin82 Private E-2

    her u go dr.m

    but as for the combofix

    i explained in my earlier post:confused
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Sorry about that, begin82

    ... couldn't edit my post in time...

    I'm looking over your logs and will post back.... please be patient.

    Thanks!
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, begin82

    Do you know what this file is for?
    Code:
    [B]"C:\ProgramData\"
    powjnvfp.pmy 2008-09-13 4864 "powjnvfp.pmy"
    
    [/B]
     
    Last edited by a moderator: Oct 10, 2008
  6. begin82

    begin82 Private E-2

    i have no idea how do i search or figure that out

    thanks doc
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, begin82

    Upload a File to Jotti

    Please visit http://virusscan.jotti.org/

    Copy/paste this file and path into the white box at the top:
    Press Submit - this will submit the file for testing.
    Please wait for all the scanners to finish then copy and paste the results in your next response.

    Thanks
     
  8. begin82

    begin82 Private E-2

    here u go doc
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, begin82

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Step 2:
    Please download The Avenger by Swandog46 to your Desktop

    Right click on the Avenger.zip folder and select "Extract All..."
    * Follow the prompts and extract the avenger folder to your desktop
    * Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
    Code:
    Files to delete:
    C:\Windows\system32\ActiveToolBand.dll 
    Now, open the avenger folder and start The Avenger program by clicking on its icon.
    • Right click on the window under Input script here:, and select Paste.
    • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
    • Click on Execute
    • Answer "Yes" twice when prompted.
    4.The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

    Step 4:
    Run Ccleaner, then re-boot into normal mode


    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the following logs to your next reply:
    • C:\avenger.txt
    • C:\MGlogs.zip

    Be sure to tell me how your computer is now running!
     
  10. begin82

    begin82 Private E-2

    heres the logs

    really hope u find something

    cause internet explorer and live mail are just terrible for somr reason and they werent before

    i know vista has issues but as long as i keep on top of things the computer usually runs smooth but lately it hasnt


    anyways thnx again in advance Doc.

    oops cannot find mgtools.zip
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Please click on Start > Computer > C drive.. that's where you'll locate MGlogs.zip.

    Thanks
     
  12. begin82

    begin82 Private E-2

    Sorry i thought they would have been in the Mgtools folder
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are all clean. If you are still having problems with applications freezing, you should post in the Software Forum.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds