Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Log files from another computer


  • This topic is locked This topic is locked
20 replies to this topic

#1 dannyboy950

dannyboy950

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 03 November 2015 - 08:23 PM

I have run this tool unsuccessfully on this Vista machine twice but each time I installed it on the infected machine. This time I ran it from off a thumb drive.

 

This time it was able to complete and write 2 logs but it seemed not to make a fix list.

One of your trainees suggested I come here so you guys could have a try.

Just so you know Emisoft; SAS;

 

Spybot S&D and Malware bytes as well as every tool in your arsenal have been run on here. Most would not even complete their scans some would not even run.

 

The only ones that I was able to successfully run and complete were all on a thumb drive not installed on the system.

 

So for your casual light reading here goes. This one I will paste it is the main log. The other I will deliver if you guys want to see it.

 

 


HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,926 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:02 AM

Posted 06 November 2015 - 11:32 AM

ATTENTION: System Restore is disabled
How to: Turn System Restore ON - Windows
http://windows.microsoft.com/en-ca/windows/turn-system-restore-on-off#1TC=windows-7
---




Check "winmgmt" service or repair WMI.
DNS Servers: Media is not connected to internet.

Lets try to repair some important Windows services.


Please Download Tweaking.com Windows Repair tool to a CD or flash drive using a good computer.
Copy the program on the Desktop of the compromised computer.

Here
  • Install and then run the program
  • Execute the instructions on Step 1 Important
  • Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
  • On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
  • Click on Repairs
  • Click Repairs - Open Repairs in the bottom right corner
  • Click the Unselect All button then select just the item(s) listed below

  • 01 - Repair Registry Permissions
    03 - Reset Service permissions
    04 - Register System Files
    05 - Repair WMI
    09 - Repair HOSTS File
    10 - Remove Policies Set By Infections
    13 - Repair Network (previously Repair Winsock & DNS Cache)
    14 - Removed Temp Files
    15 - Repair Proxy Settings
    17 - Repair Windows Updates
    18 - Repair CD/DVD Missing/Not Working
    19 - Repair Volume Shadow Copy Service
    21 - Repair MSI (Windows Installer)
    26 - Restore Important Windows Services
    27 - Set Windows Service to Default Startup
    
  • Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
  • Please copy and paste the Contents of this file on your next reply.

  • ===

    How is the computer running now?






Edited by nasdaq, 07 November 2015 - 09:22 AM.


#3 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 06 November 2015 - 02:21 PM

Ok before I do this just so you know this is on a Vista machine which has no internet connection so DNS problems are to be expected I would think.

As far as system restore being off that is probably because the recovery partition no longer exists.
I sent that computer in year before last for a hard drive waranty repair and data recovery just before the warrenty expired. What I got back was no data and the recovery partition had been used instead.

I complained to Compaq to no evail. Windows moved my cd/dvd rom into D so it does not work anymore.
Hence the thump drive.
I will be more than happy to run the tool but the only computer connected to the net is this one Win 10 64 bit. Will it be formatted in 64 bit or win 32? And will it run on 32 bit Vista?
Farbar came in both a 64bit and a 32bit. I installed and ran the 32bit version does this tool come in both versions also.

I await your reply before continueing.

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#4 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 06 November 2015 - 04:23 PM

I went to the site and dl/installed the portable version it does not say if it is 32bit or 64bit.
It is a rather large zip file I am not shure if I have enough room on the drive to unzip in the drive so do I need to install to desk top and then unzip and run it.

Thank you.

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#5 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 06 November 2015 - 08:15 PM

Ok I finally got it on the other computer and it ran to completion I think. It made a log but every time I try to get it back to the thumbdrive windows explorer closes out. I tried running it 3 times but am unable to get the log over here.

I need to add that that program is the bad ass program synative had me run to fix my windows update problem on here. Has to be run in safe mode.

Edited by dannyboy950, 06 November 2015 - 08:52 PM.

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#6 nasdaq

nasdaq

  • Malware Response Team
  • 39,926 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:02 AM

Posted 07 November 2015 - 09:27 AM

It is a rather large zip file I am not shure if I have enough room on the drive to unzip in the drive so do I need to install to desk top and then unzip and run it.

Yes
The Tweaking tool is compatible with both 32 and 64 bit systems.


I have added this line to my previous fix. Post no.2.
18 - Repair CD/DVD Missing/Not Working

This will possibly restore you CD/CVD drive.

===

Run the tool from the Desktop of the compromised computer and let me know what problem persists.

#7 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 07 November 2015 - 10:49 AM

Still can not get you the log files. It creates them but within the program it gives me no option of where to make them or with what [notepad or other] I can see them when first opening tweak without actually re-running it by opening logs, but it opens in windows explorer. Before I can save to log to the thumb drive windows explorer crashes restarts but closes out.

Some observations while it is running. First it will not complete backing up the registry unknown error. When rebuilding wmi it seems to get hung for awhile. Somewhere around step six the computer shuts down. I had to step away for a few minutes so I did not see what caused it.

I assume it just completed and shut down instead of rebooting because when I did restart manually it opened up in regular mode.

The cd/rom is still listed as D. I did click on burn disc and the drawer opened but would not turn/burn a disk.

So here we sit what do we try next????

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#8 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 07 November 2015 - 03:51 PM

I finaly got the log to the thumb drive. Is it allright to attach it instead of copy paste. That is difficult for me to do on this pc. Will await a response.

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#9 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 07 November 2015 - 07:11 PM

Since I can find no way to copy and paste from within a thumb drive I will attach the log. If needed I have several other log files from other programs run on this Vista computer if needed.

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#10 nasdaq

nasdaq

  • Malware Response Team
  • 39,926 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:02 AM

Posted 08 November 2015 - 09:35 AM

The Tweking tool log only shows these fixes. Did you include the complete list I gave you?

01 - Repair Registry Permissions
03 - Reset Service permissions
04 - Register System Files
05 - Repair WMI
09 - Repair HOSTS File
10 - Remove Policies Set By Infections


If by any chance you can get the CD driver working
No 18 - Repair CD/DVD Missing/Not Working <- my fix.

Do you have the Vista CD from which you can reinstall the Operating System?

#11 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 08 November 2015 - 10:04 AM

My apologies I normally open and actually read the logs my self before posting. I did not do so this time until a few hours ago. I saw that it was incomplete.

I did have all the items checked off in your list but like I said in an earlier post the scan may have aborted. At about step 6 I had to leave the computer for a few minutes and when I came back the computer had shut down. I rebooted and I was back into regular mode so I thought it had completed and it did show a log that I did not open to read. My bad otherwise we would not have wasted so much time.

I tried re-running it with the same results. I may have to uninstall the tool reinstall and re run it. What do you think?

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#12 nasdaq

nasdaq

  • Malware Response Team
  • 39,926 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:02 AM

Posted 08 November 2015 - 10:10 AM

Run the fix but do only one at a time.

It may just be that you have some bad RAM causing this interruption.

#13 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 08 November 2015 - 10:18 AM

Ok will do but this is going to take awhile it will probably be much later before I am done. Lol

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#14 dannyboy950

dannyboy950
  • Topic Starter

  • Members
  • 1,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:port arthur tx
  • Local time:12:02 AM

Posted 08 November 2015 - 10:41 AM

First individual scan log.
Warning Security Info <MsMpSvc> Failed with Access is denied.
Shall I continue?

HP 15-f009wm notebook AMD-E1-2100 APV 1Ghz Processor 8 GB memory 500 GB Hdd

Linux Mint 17.3 Rosa Cinamon


#15 nasdaq

nasdaq

  • Malware Response Team
  • 39,926 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:02:02 AM

Posted 08 November 2015 - 11:40 AM


If Windows_OneCare_Live is enable please stop the process via MsConfig

http://www.systemlookup.com/search.php?type=name&client=malwaresearch-chrome&search=MsMpSvc




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users