Author Topic: I have a Win32 and win 64 -- have Logs Needed Plz Help !!  (Read 3952 times)

0 Members and 1 Guest are viewing this topic.

GTalkofthetown

  • Guest
I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« on: August 09, 2012, 11:44:51 PM »
Hello i have followed the other topic on how to run the programs i gain the logs but when i Run aswMBR it runs for a while and then crashes my computer ... so i cannot ever get the log from it

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #1 on: August 09, 2012, 11:49:45 PM »
try to run it in safe mode

GTalkofthetown

  • Guest
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #2 on: August 09, 2012, 11:53:16 PM »
Ok Gona try now

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #3 on: August 09, 2012, 11:58:54 PM »
Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


    Quote
    :OTL
    DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a068iszq)
    IE - HKU\S-1-5-21-247472737-1075982631-554670806-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&babsrc=SP_ss&mntrId=e65256020000000000000019d1e84749
    IE - HKU\S-1-5-21-247472737-1075982631-554670806-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>
    FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
    O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)

    :Files
    C:\Windows\Installer\{b76e7a93-8cb4-86e1-5877-959d2265e3d2}
    C:\Users\James\AppData\Local\{b76e7a93-8cb4-86e1-5877-959d2265e3d2}
    ipconfig /flushdns /c
    netsh int ip reset c:\resetlog.txt  /c
    ipconfig /release /c
    ipconfig /renew /c
    sc create BITS binpath= "c:\windows\system32\svchost.exe -k netsvcs" start= delayed-auto /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

FINALLY

run farbar service scanner



Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

GTalkofthetown

  • Guest
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #4 on: August 10, 2012, 01:51:57 AM »
ok i have followed all of that  but with the Conbo fix i have this prop

GTalkofthetown

  • Guest
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #5 on: August 10, 2012, 01:52:47 AM »
it has stayed like that for hour and a Half :/

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #6 on: August 10, 2012, 02:49:27 PM »
OK reboot and try one more time, if it fails then we will need to work outside of windows.

In your safe boot menu is there the option "repair my computer " ?

GTalkofthetown

  • Guest
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #7 on: August 12, 2012, 02:05:57 PM »
When in Safe Mode theres No repair computer ?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I have a Win32 and win 64 -- have Logs Needed Plz Help !!
« Reply #8 on: August 12, 2012, 02:40:44 PM »
Download the following three programmes to your desktop :

 
1.  WiNTBootIc
2.  Windows Vista RC
3.  Farbar Recovery Scan Tool x64

Extract wintoboot to your desktop
Insert a USB drive of at least 4GB
Run Wintoboot



Drag and drop the Windows 7 ISO to the programme in the space indicated
Tick the Format box and accept the warnings
Press Do It

You will see it progressing



It will let you know when it is done
Then copy FRST to the same USB




Insert the USB into the sick computer and start the computer.  First ensuring that the system is set to boot from USB
Note: If you are not sure how to do that follow the instructions Here

 
When you reboot you will  see this.
 Click repair my computer

 
Select your operating system

 
Select Command prompt

 
At the command prompt type the following  :

notepad and press Enter.
The notepad opens. Under File menu select Open.
Select "Computer" and find your flash drive letter and close the notepad.
In the command window type e:\frst.exe and press Enter
Note: Replace letter e with the drive letter of your flash drive.
The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.