TechSpot

Can't complete 8 steps

By misterzacho
Apr 24, 2009
  1. every time i try to install MBAM or superantispyware i think something is blocking it from installing.

    i can download the installers but they wont work.

    and the thing is. only the antispyware/antivirus kind of programs wont work. other things can install just fine.
     
  2. touch

    touch TS Rookie Posts: 978

    Hello misterzacho

    Ok, let´s try combofix then ->

    Rightclick on the link to download combofix here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe << Save as.

    Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.

    Now, please make sure no other programs are running, close all other windows.

    Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
    Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall.
    It may take a while to complete scanning and this is normal.

    You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after
    scanning has completed.

    Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post
     
  3. misterzacho

    misterzacho TS Rookie Topic Starter

    i tried to save it as you said but this pops up

     
  4. touch

    touch TS Rookie Posts: 978

    Ok. try again without renaming it -

    Please download Combofix:
    http://subs.geekstogo.com/ComboFix.exe

    And save to the desktop.

    Close all other browser windows.

    Please connect all your external hard drive/flash drive before running Combofix, if you have any


    Double-click on the combofix icon found on your desktop.

    Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

    Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post
     
  5. misterzacho

    misterzacho TS Rookie Topic Starter

    im getting the same message.

    i actually renamed MBAM to "123" and the installer worked. but the program still wont run. hah.
     
  6. touch

    touch TS Rookie Posts: 978

    Try combofix and MBAM (123) from safe mode, and see if any of them will run ?
     
  7. misterzacho

    misterzacho TS Rookie Topic Starter

    thanks for all the help touch. actually all i had to do was rename some stuff and i was able to get all the programs working. here are the logs.

    edit: added a combofix log also.
     
  8. touch

    touch TS Rookie Posts: 978

    Great :)

    You have two Antivirus programs installed - AVG8 and McAfee
    "Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and will typically cause your computer to crash, and will provide less protection.
    Not more"

    I´ll therefore recommend you remove AVG8 from add/remove programs in controlpanel.

    Reboot.

    BTW. Have you paid for McAfee ?

    Download LSP-Fix and save it into its own directory. You can download LSP-Fix from the following location:
    http://www.bleepingcomputer.com/files/lspfix.php
    Once the file is downloaded navigate to where you saved the file and double-click on it to start the application
    Click on -> I know what I'm doing – move - 3724890.dll to rigth pane using >>> then – Finish – button

    Reboot

    Open notepad and copy/paste the text in the quotebox below into it:
    Name the file as CFScript
    and Save it on the desktop

    http://www.fromsej.saknet.dk/billeder/cfscript.gif

    Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe.

    Combofix will create a logfile and display it after your computer has rebooted.

    Usually located in c:\combofix.txt, please attach it to your next post


    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall
     
  9. misterzacho

    misterzacho TS Rookie Topic Starter

    avg wont let me uninstall. it gives me this message:
    3724890.dll isnt in the the list in LSPfix

    there is mdnsNSP.dll, MSWsock.dll, winrnr.dll, and rsvpsp.dll
     
  10. touch

    touch TS Rookie Posts: 978

    Ok. We deal with AVG later, and don´t remove - mdnsNSP.dll, MSWsock.dll, winrnr.dll, and rsvpsp.dll. close LSP Fix

    Continue with combofix
     
  11. misterzacho

    misterzacho TS Rookie Topic Starter

    ok. here ya go.:)

    oh, and i uninstalled AVG.
     

    Attached Files:

  12. touch

    touch TS Rookie Posts: 978

    There are still remnants from AVG ;)

    You have viewpoint running on your computer ->

    Viewpoint is considered foistware and is not needed on your computer.


    Download and unzip to own folder on Desktop - http://bellsouthpwp.net/p/r/prprogramsstudios/viewpointkiller.zip

    Run ViewpointKiller.exe

    Reboot.

    ViewpointKiller 1.2 FinalViewpointKiller does exactly what it's name says: Kills Viewpoint Media Player. Viewpoint Media Player is an adware that displays bandwith eating popup ads in IE and on your desktop. It comes silently with an install of AIM and will be reinstalled by AIM if uninstalled.ViewpointKiller fixes all of that. It takes off Viewpoint Media Player once and for all.


    Open notepad and copy/paste the text in the quotebox below into it:


    Save this as:
    CFScript

    http://www.fromsej.saknet.dk/billeder/cfscript.gif

    Refering to the picture above, drag CFScript into ComboFix.exe

    Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post.
     
  13. misterzacho

    misterzacho TS Rookie Topic Starter

    im feeling fat and sassy.
     
  14. touch

    touch TS Rookie Posts: 978

    Why are you feeling fat and sassy ?


    Please attach a whole combofix log, as the log you have sent, is a bit short ;)
     
  15. misterzacho

    misterzacho TS Rookie Topic Starter

    hahah. how did that happen
     
  16. touch

    touch TS Rookie Posts: 978

    Dunno :D

    Open notepad and copy/paste the text in the codebox below into it:
    Name the file as CFScript
    and Save it on the desktop

    Code:
    Killall::
    
    Snapshot::
    
    File::
    c:\windows\system32\sgccwnj0ev4t.dll
    c:\windows\\system32\\buzozati.dll
    c:\WINDOWS\\system32\\ddayx.dll
    g:\resycled
    Folder::
    g:\resycled
    Filelook::
    c:\documents and settings\zach cross\pdq.exe
    
    Dirlook::
    c:\program files\12345
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "BearShare"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e4190eb-4e03-11dc-b0a1-001320c08592}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48c780d4-c92b-11db-b01f-000f66efd05b}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InprocServer32]
    @=-
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddayx]
    "DllName"=-
    [-HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtUmMEUk]
    http://www.fromsej.saknet.dk/billeder/cfscript.gif

    Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe.

    Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post


    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall
     
  17. misterzacho

    misterzacho TS Rookie Topic Starter

    tuesday's coming. did you bring your coat?
     
  18. touch

    touch TS Rookie Posts: 978

    How are things running now ?
     
  19. misterzacho

    misterzacho TS Rookie Topic Starter

    very very very very beautifully.

    thank you very much, my friend.

    i love you. (no homo)

    lol :grinthumb
     
  20. touch

    touch TS Rookie Posts: 978

    Great, and I was glad to help :D

    You should Create a New Restore Point to prevent possible reinfection from an old one.
    The easiest and safest way to do this is:
    Go to Start > All Programs > Accessories > System Tools > System Restore
    Select Create a restore point, and Ok it.
    Next, go to Start > Run and type in cleanmgr
    Select the More options tab
    Choose the option to clean up system restore and OK it.

    This will remove all restore points except the new one you just created.


    Please download OTCleanIt
    Save it to desktop.
    This will remove all the tools we used to clean your computer.
    Double-click OTCleanIt.exe. Click CleanUp. Say Yes to the "Begin cleanup Process?"
    When asked if you want to proceed with the cleanup process, click Yes. Restart your computer when prompted.
    Please note. It will NOT remove Mbam, Ccleaner and SuperAntispyware.

    To learn more about how to protect yourself while on the internet, please read Tony Klein´s guide:
    How did I get infected in the first place

    Keep safe :wave:
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...