Win64 Patch A

Discussion in 'Malware Help (A Specialist Will Reply)' started by deepinit, Dec 9, 2012.

  1. deepinit

    deepinit Private E-2

    I am getting notices from AVG about service.exe.

    I ran Rogue and it crashed before completing. I included a screen shot.
    MalewareB ran fine, found stuff, log included.
    TDSKiller ran found Services.exe but said was not able to fix. Although there is a Quarantine area in C:/ there is no log file. I may have something going on for permissions on the c:/ directory due to this computer being on a work network before. I am admin but...
    HitMan log included
    MGTools ran and could not create logs because of issue with c:/ (see mg002)

    So doesn't look good without C: available, huh? I have not been able to fix this.

    Thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.

    Now have it fix all that it finds.

    Reboot and re-run Hitman and see if you can now run RogueKiller.

    Attach the logs.
     
  3. deepinit

    deepinit Private E-2

    Hitman did well, replaced Services.exe, erased some files in windows install areas and I went ahead and deleted dumb stuff like Ask toolbar.

    Rogue still won't run all the way through. Here is a jpg of what it found before erroring.

    Ran hitman again and showed no problems. Included log.
     

    Attached Files:

  4. deepinit

    deepinit Private E-2

    Sorry I don't want to appear to be a bump, just more info.

    With AVG running, system is running fine with no notices.

    The RK screen capture I sent was incomplete so here are three that cover everything that it had found. In other tabs it found a proxy setting in IE but it is disabled and changes regularly with HotspotShield. It found a homesever reference that is normal.

    The attachment is like the last sent but with a few more items as it scrolls.
     

    Attached Files:

    • rk4.jpg
      rk4.jpg
      File size:
      36.4 KB
      Views:
      2
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you are probably ok, but let's have you run
    MGtools


    Download it to your C drive and run it. Attach the log: C:\MGLogs.zip.
     
  6. deepinit

    deepinit Private E-2

    Will unless I can change the directory where it write the log, I can't see the results. Here is a jpg of the app running and the getunkey log.

    Not sure what else I can do without being able to write to root C:.

    I did run full virus scans with AVG and Ad Aware and found nothing. But I would Iove to make sure.

    WAIT scratch all that. I think all the logs are in the MGTools directory and I just have to make my own zip. Here it is.


    Thanks!
     

    Attached Files:

    Last edited: Dec 10, 2012
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can't run it from the root folder, just run it from the desktop. It will still produce a log on the C ( root ) drive>>>> C:\MGLogs.zip.
     
  8. deepinit

    deepinit Private E-2

    As it shows in the screen capture, I (and software) can't create files in the c:\ directory. the program runs and all the logs are created in the MGTools directory but the zip doesn't create because it is in c:\. But I zipped all the logs that there were from MGTools and put them in the zafind.zip file. Are these not the same files? If not, I am stuck. Thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok. I am not seeing any remaining malware in your logs. Tell me what issues, if any, you are still having.
     
  10. deepinit

    deepinit Private E-2

    I was going to say no problems but I seem to be having some issues with IE. It seems to be telling me that a page has caused problems with IE (no particular page) and that it is closing IE. It reinitializes my tabs but this is a couple of times a day with heavy use. Every now and then I have slowness for browsing or getting a cursor to be available (more than usual).

    Besides that, doing good but nobody seems to be able to help me on the forum with my login issues and root (c:\) directory availability. Eventually I'll do a Windows 8 load from scratch. Without being able to run RogueKiller, what does that leave me most vulnerable to? Registry problems? I appreciate all your help! Thanks
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can only suggest that you pursue your remaining issues in the software forum.

    Since you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds