Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
laptop infected cannot run any anti malware program [Solved], can not run any anti virus or anti malware
sezersenli
post Nov 6 2009, 05:54 PM
Post #1


Member
**
Posts: 11
OS: vista 32bit





Hi i have a problem with my laptop. My operating system is windows vista 32bit home edition. I can not run internet explorer, any anti virus program. What should i do? I have read about a similar topic but the topic was closed.

Please help me with this trojan.
Go to the top of the page
 
+Quote Post
2 Pages V   1 2 >  
Start new topic
Replies (1 - 14)
fenzodahl512
post Nov 6 2009, 09:50 PM
Post #2


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



Hello, my name is fenzodahl512 and welcome to the forum.. Please do the following....


Please download The Comedian.exe by Rorschach112 to your desktop
  • Please disable all of your antivirus/firewall before doing this step. Please visit HERE if you don't know how..
  • Double click the program to run it. It will only take around several minutes to run.
  • It will do a series of tasks and tell you when each one is finished.
  • You will be prompted to press any key after each step
  • When it is done it will close and exit itself automatically.
  • You can delete The_Comedian.exe once it is finished
STOP! if you can't complete this step.. Tell me more about it..



NEXT


Please download Malwarebytes' Anti-Malware from HERE or HERE

Note: If you already have Malwarebytes' Anti-Malware, just run and update it.. Then do a "Perform Full Scan"

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



NEXT


Please download RSIT by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run RSIT
  • Before you click "Continue", make sure you change the List files/folders created or modified in the last 3 months
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.




NEXT


Please download GMER and unzip it to your Desktop. <<mirror>>
  • Open the program and click on the Rootkit tab.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click on Scan.
  • When the scan has run click Copy and paste the results into a Notepad >> save it and attach in this thread.


IMPORTANT: Do NOT run any program while you are doing this scan as it may interfere with the output result



Post me these logs in your next reply.. Post each log in separate post..

1. Malwarebytes'
2. RSIT log.txt
3. RSIT info.txt
4. Attach GMER result..
Go to the top of the page
 
+Quote Post
sezersenli
post Nov 6 2009, 10:35 PM
Post #3


Member
**
Posts: 11
OS: vista 32bit



I installed anti malware, scan started but then immediatly the program was closed and i can not run the program until then.
Go to the top of the page
 
+Quote Post
fenzodahl512
post Nov 6 2009, 10:42 PM
Post #4


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



proceed with next steps smile.gif
Go to the top of the page
 
+Quote Post
sezersenli
post Nov 6 2009, 10:44 PM
Post #5


Member
**
Posts: 11
OS: vista 32bit



same thing happened with the next step
Go to the top of the page
 
+Quote Post
fenzodahl512
post Nov 6 2009, 10:47 PM
Post #6


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



Please save this file to your Desktop. Double-click on it to run a scan. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.

Go to the top of the page
 
+Quote Post
sezersenli
post Nov 6 2009, 10:56 PM
Post #7


Member
**
Posts: 11
OS: vista 32bit



Thank you. I just did it however i think it was stuck at a dll file. It was too big to paste so i attached it.
Attached File(s)
Attached File  Win32kDiag.txt ( 381.02K ) Number of downloads: 8
 
Go to the top of the page
 
+Quote Post
fenzodahl512
post Nov 6 2009, 11:01 PM
Post #8


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



Please download The Avenger by Swandog46 and unzip it to your Desktop


Please open The Avenger. Then, please copy/paste the script inside the codebox into the Input script here: box..

CODE
Begin copying here:
Files to move:
C:\Windows\System32\logevent.dll | C:\Windows\System32\cngaudit.dll


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
  • Now, click on Execute. Just say Yes at every prompted


The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

Please copy/paste the content of c:\avenger.txt into your reply.



NEXT


Make sure you save Win32kDiag on your Desktop BEFORE doing below fix..

Go to Start >> Run >> copy/paste below >> Enter. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.

"%userprofile%\desktop\win32kdiag.exe" -f -r
Go to the top of the page
 
+Quote Post
sezersenli
post Nov 6 2009, 11:15 PM
Post #9


Member
**
Posts: 11
OS: vista 32bit



Thank you i just finished it. There are the results. Log was too big i compressed it.
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "C:\Windows\System32\logevent.dll|C:\Windows\System32\cngaudit.dll" completed successfully.

Completed script processing.

*******************

Finished! Terminate.

Attached File(s)
Attached File  Win32kDiag.zip ( 34.22K ) Number of downloads: 11
 
Go to the top of the page
 
+Quote Post
fenzodahl512
post Nov 6 2009, 11:18 PM
Post #10


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



Now, can you run Malwarebytes' or any antivirus/antimalware program? smile.gif
Go to the top of the page
 
+Quote Post
sezersenli
post Nov 6 2009, 11:46 PM
Post #11


Member
**
Posts: 11
OS: vista 32bit



i am running it now. what should i do when its finished?
Go to the top of the page
 
+Quote Post
fenzodahl512
post Nov 6 2009, 11:58 PM
Post #12


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



Just let it finish and remove everything that it found. Then post the log here.. smile.gif

Have to go now, see you this afternoon smile.gif
Go to the top of the page
 
+Quote Post
sezersenli
post Nov 7 2009, 12:00 AM
Post #13


Member
**
Posts: 11
OS: vista 32bit



Thank you very much. I'll post immediately then will be waiting for your answer.
Go to the top of the page
 
+Quote Post
sezersenli
post Nov 7 2009, 02:00 AM
Post #14


Member
**
Posts: 11
OS: vista 32bit



I have finished full scam, it has found 2 trojans and removed them.
Go to the top of the page
 
+Quote Post
fenzodahl512
post Nov 7 2009, 07:00 AM
Post #15


Trusted Helper
Group Icon
Posts: 9,808
OS: Windows XP



Ok, lets do another scan with ESET Online Scanner...


Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan.
  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic



How's the computer now? smile.gif
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 12th March 2010 - 05:21 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising