Try to run ComboFix from Safe Mode. If a log is made please attach it…if not let me know what happens. ![]()
It started running in safe mode, got fairly far by the looks of it, and the stopped with an error message in 7 languages saying ‘Incompatible OS’. :-\
http://i1224.photobucket.com/albums/ee380/jeffce74/mbarrrrr_zps191062b8.jpg
Malwarebytes Anti-Rootkit
Please download Malwarebytes Anti-Rootkit and save it to your desktop.
[*]Be sure to print out and follow the instructions provided on that same page.
[*]Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
[*]Scan your system for malware
[*]If malware is found, please go to the MBAR folder and then attach the contents of the MBAR-log-***.txt file to your next reply.
If there is no malware found, please let me know as well.
When I try to run it, or run as admin, I get the usual ‘“The System could not find the environment option that was entered.”’. If I try to run it from safe mode or command prompt, I get the error message “The subsystem needed to support the image type is not present.”
What now?
Run a new scan with FRST and attach the new log as well as doing the following…
SystemLook
Please use either of the following links:
Download Mirror 1
Download Mirror 2
[*]Right-click and Run as Administrator SystemLook.exe to run it.
[*]Copy the content of the following codebox into the main textfield:
:filefind
*services.exe
[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi, neither of those SystemLook links work (on either my infected or other computer).
Also, attached is my latest FRST64 scan.
In other news, a disappointing ending to World War Z… Who’d have thunk it.
Sorry about that…that was my fault. Try it now.
I agree with the WWZ ending too. Not quite what I was expecting.
Attached.
Hi,
Just so you know…this infection is the real deal and effects every system differently so this may take a bit. ![]()
Please go back to Reply 10 and follow the instructions there. Do Not run these instructions in Recovery Mode. If possible, please just run them on your system in Normal Mode or Safe Mode. If you run the instructions in Safe Mode, allow the tool to reboot your system (or do so manually if asked to do so) and then let FRST complete it’s run. It will produce a log that I need for you to attach.
Still here?
Still here - was out of town for the weekend. Fixlog attached.
Great job! ![]()
Please download and run [url=http://kb.eset.com/library/ESET/KB Team Only/Malware/ServicesRepair.exe]ESET ServicesRepair[/url]
Once complete please run a new scan with FRST and post the new log created. You can just run FRST in Normal Mode.
I tried running the services repair in normal mode, didn’t get an error message, but nothing actually happened; so I ran it in safe mode, where it worked and forced a reboot. Then tried running FRST in normal mode, but got the usual error message, so rebooted again and ran it once more in safe mode. File attached.
Hi,
First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.
Copy the contents of the code box > right click in the command window and select paste
replace "C:\Windows.old\Windows\System32\services.exe C:\Windows\System32\services.exe"
Press Enter (you won’t actually see anything happen)
Close the Command Prompt window.
Run a new scan with FRST and post the new log please.
Let me know how your system is running as well.
Hi Jeff is away for a few days so I will be helping now… Could you update me on the current status of your computer … Also are you able to run OTL
Download OTL to your Desktop
Secondary link
[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif
[*]Select All Users
[*]Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
dir “%systemdrive%*” /S /A:L /C
CREATERESTOREPOINT
[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Post both logs
Hi Essex Boy, thanks for the help in advance!
That OTL scan is a scarily powerful program! As usual (random environment error message - see earlier in thread for more details), I couldn’t run it in normal mode. So I rebooted in safe mode. First I ran through Jeff’s last instructions and have attached the FRST file he was after. Then I ran OTL and you’ll find the files attached.
The OTL.txt file was 3kb too big (!) to upload by itself, so I have split it into two text files. Please just C&P part 2 into the end of the OTL.txt.
And Part 2…
OK this is an upgrade to windows 7 … Hence the big log ![]()
Methinks we are now in the repair phase
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:OTL
O33 - MountPoints2\{430ba810-0faf-11e1-9213-ec9f1b2e4f70}\Shell - "" = AutoRun
O33 - MountPoints2\{430ba810-0faf-11e1-9213-ec9f1b2e4f70}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{6c096a27-faad-11e1-aa47-001e101fa1f5}\Shell - "" = AutoRun
O33 - MountPoints2\{6c096a27-faad-11e1-aa47-001e101fa1f5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{6c096a35-faad-11e1-aa47-001e101fa1f5}\Shell - "" = AutoRun
O33 - MountPoints2\{6c096a35-faad-11e1-aa47-001e101fa1f5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{8e08862c-2279-11e1-9152-b0fc61eacf4a}\Shell - "" = AutoRun
O33 - MountPoints2\{8e08862c-2279-11e1-9152-b0fc61eacf4a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{8e08863b-2279-11e1-9152-b0fc61eacf4a}\Shell - "" = AutoRun
O33 - MountPoints2\{8e08863b-2279-11e1-9152-b0fc61eacf4a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{999d27ae-f793-11e1-b0c6-f31a42c70a9f}\Shell - "" = AutoRun
O33 - MountPoints2\{999d27ae-f793-11e1-b0c6-f31a42c70a9f}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{999d27be-f793-11e1-b0c6-f31a42c70a9f}\Shell - "" = AutoRun
O33 - MountPoints2\{999d27be-f793-11e1-b0c6-f31a42c70a9f}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{bb92472c-4791-11e2-af7b-bd087aaaf849}\Shell - "" = AutoRun
O33 - MountPoints2\{bb92472c-4791-11e2-af7b-bd087aaaf849}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{bb92473c-4791-11e2-af7b-bd087aaaf849}\Shell - "" = AutoRun
O33 - MountPoints2\{bb92473c-4791-11e2-af7b-bd087aaaf849}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{ff88ffdd-fe40-11e1-b16c-001e101f4da1}\Shell - "" = AutoRun
O33 - MountPoints2\{ff88ffdd-fe40-11e1-b16c-001e101f4da1}\Shell\AutoRun\command - "" = F:\AutoRun.exe
[2013/07/01 21:16:46 | 000,004,608 | -HS- | M] () -- C:\Windows\assembly\GAC_32\Desktop.ini
[2013/07/01 21:16:46 | 000,006,144 | -HS- | M] () -- C:\Windows\assembly\GAC_64\Desktop.ini
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN
Open an elevated command prompt :
Go > Start > All Programs > Accessories
Right click Command Prompt and select run as administrator
In the black box that opens type the following command and press enter :
sfc /scannow
Once it has rebooted then re-run OTL scan with the following script
netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
So I managed to run OTL in safe mode and paste the fix stuff in. WHen it rebooted, I was presented with a text file whose title comprised of numbers, when I clicked save, i didn’t notice the path and now I cannot find it - it’s not on the desktop where everything else associated with OTL is.
However, it rebooted (in safe mode, as I couldn’t run CMD prompt as admin in normal mode). I then ran the quick scan, the result of which is attached.
When I tried to run the sfc/scannow, it stopped at 12% saying “windows resource protection found corrupt files but was unable to fix some of… em. Details are included in the CBS .log windir\logs\CBS\CBS.log. For example”
Though when I go to 'c:\windows\logs\CBS\CBS.txt, it says ‘access denied’ when I run it. However, I can go to windows.old and access the log file there, which I attach now, though it’s probably not helpful.
I have not performed the final bit of your instructions "Once it has rebooted then re-run OTL scan with the following script
netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe" as the previous scan part failed.
Please advise what to do now.