Need help with malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jtu50, May 14, 2008.

  1. jtu50

    jtu50 Private E-2

    I am trying to clean up a badly infected computer for a friend. I have tried following instructions in Malware removal forum. This machine is so badly infected that I could only download recommended programs in safe mode. However, I cannot install them in safe mode and normal mode is not working properly. I did run AVG which was on the machine already. This cleaned up some stuff, but I suspect there is lots more. What do I do next? Machine is running WinXP SP1, IE V6.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happens when you try to install programs in normal boot mode? You only said you had to download in safe mode. What exactly is wrong with trying to run in normal boot mode? Have you tried booting in normal mode with your internet connection unplugged?

    You need to try all steps in the READ ME. Some of them do not require installations. MGtools does not require a true installation. It is a self extracting ZIP file that just automatically runs the program. Have you tried ALL steps in the READ ME including MGtools?

    If you cannot run anything and cannot get us any logs, then the answer will be quite simple and that is reinstall since we cannot begin to help you without any information.
     
  3. jtu50

    jtu50 Private E-2

    I downloaded suggested programs, put them in a folder on C:. After booting in normal mode, I tried to open c: by clicking my computer, system never seems to open Windows explorer so I can access files. Runs incredibly slowly in normal mode, multiple pop ups, IE freezes/crashes. Runs just fine in safe mode. After reading down suggested instructions, I found links to on-line scanners, which I will try in safe mode and then get back to you unless you indicate otherwise. If I can run these scanners I will then follow remainder of instructions for cleaning.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should try to run MGtools.exe as requested. It does not require a Windows install.
     
  5. jtu50

    jtu50 Private E-2

    Got to downloaded files. Had to leave machine on overnight. It is running so slow it takes FOREVER to load pages. Will follow directions posted, get back to you if any problems. Thanks
     
  6. jtu50

    jtu50 Private E-2

    Chas,

    Followed all instructions. Machine working better. Please reivew logs attached and let me know if I'm clean. Second reply with last attachment to follow. Thanks

    Jeff R
     

    Attached Files:

  7. jtu50

    jtu50 Private E-2

    Here is the last attachment
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is why we want those steps followd. ;)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the software as requested in step 1 of the READ ME:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 3
    SelectRebates


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
    O2 - BHO: (no name) - {5EF6C73F-368A-4547-BEBB-BE119C8FD852} - C:\WINDOWS\System32\awtsRkJC.dll (file missing)
    O2 - BHO: (no name) - {A8A7FF51-B059-4B41-A3F5-2601A3B52420} - C:\WINDOWS\System32\kHARIBSI.dll (file missing)
    O2 - BHO: (no name) - {D1EA5E0F-BFF7-4314-8127-485EE8C81AD9} - C:\WINDOWS\System32\urqQklME.dll (file missing)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [msxct] msxct.exe
    O4 - HKLM\..\Run: [stuu8sp4] C:\WINDOWS\System32\stuu8sp4.exe
    O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINDOWS\RUNDLL16.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [08cab29f] rundll32.exe "C:\WINDOWS\System32\qxtpgfod.dll",b
    O4 - Startup: PowerReg Scheduler V3.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O20 - Winlogon Notify: mljjggf - mljjggf.dll (file missing)
    O20 - Winlogon Notify: xxyvTJCt - xxyvTJCt.dll (file missing)
    O20 - Winlogon Notify: __c0055D04 - C:\WINDOWS\System32\__c0055D04.dat (file missing)
    O23 - Service: Windows Packet Driver (packet) - Unknown owner - C:\WINDOWS\System32\packet.exe (file missing)

    And optionally I suggest you fix the below since they should not always be running. In fact I suggest that you uninstall Optimum Online net guide unless you really use it.
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
    O4 - Startup: LimeWire On Startup.lnk = C:\Documents and Settings\Christopher Camesas\My Documents\LimeWire\LimeWire.exe

    After clicking Fix, exit HJT.





    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. jtu50

    jtu50 Private E-2

    Chas,

    attached are the requested log files. Please be advised, that while waiting for your last reply I impulsively updated this machine to XP SP2 from a disk I had. This did not seem to have any adverse effects on performance. One or two of the entries you had asked me to fix in Hijackthis however, were not present (stuu8sp4 and I think msxct). Also, I deleted limewire completely.

    There is an entry in Add/Remove programs for something called Earthworm Jim, which I think is malware - it's still there.

    Lastly, I ran Mgtools from command line, as clicking on the exe did not bring up hijack this with the options you requested. Can you explain this for me?

    Machine now seems to be running normally as best I can tell. Will run it a while to make sure everything nominal.

    Thanks again for your help
     

    Attached Files:

  10. jtu50

    jtu50 Private E-2

    Chas,

    Machine still running very slowly. No crashes. Tried installing XP security updates that automatically download. All installs fail without any explanatation except "the following updates were not installed." Have replaced IE6 with 7. SP2 installed. Ran error checking on HD - OK. Defragging drive. Any suggestions?
     
  11. abri

    abri MajorGeek

    Hi jtu50,
    Could you repost to us and see if you have a log from your last Combofix run? It would be under C:\ Chaslang needs to see if all of those were actually removed that he set up for you.
    abri
     
  12. jtu50

    jtu50 Private E-2

    Thought I did, guess I didn't. Will send file on Monday as computer not at home. Thanks again for your help
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a kids game. Did one of your kids install it? If you don't need it then just uninstall it. You need to put the CD into the drive inorder to uninstall it.

    What exactly is slow? Boot up, shutdown, all normal operations, surfing, all websites or certain websites, downloading?????

    I need the ComboFix log as Abri stated? Do not run it again? I want to see the log from the last run. The MGlogs.zip file logs are clean.
     
  14. jtu50

    jtu50 Private E-2

    OK, yeah I figured out Earthworm was a game, I'll delete it. Also deleted a bunch of other stuff, got Windows update working properly - it wasn't. Machine was slow opening windows or programs such as notepad, or other windows explorer stuff,but since clearing out other stuff things seem better. boot up seems to be OK. I'll send combofix log tomorrow - machine is at my office, as I said, it's not mine. Also re ran combofix log after updating to sp2, installing all updates, I'll send that too labeled differently. Combo fix seems to take a LONG time to run.


    Earlier in this process, when I ran Mgtools, I had to run it from the command line, as clicking on the exe did not bring up hijack this with the options you requested. Can you explain this for me? I actually try to learn something from these experiences for future reference.
     
  15. jtu50

    jtu50 Private E-2

    Chas,

    Now I know why file didn't upload - it was too big. Will zip it and send. Have decided not to send cf log generated after I installed sp2 and reran cf. If you want it, let me know.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running MGtools.exe is not supposed to bring up HijackThis. My cleaning steps (in message # 8) said to double click on C:\MGtools\analyse.exe that is how you bring up HijackThis. Running MGtools.exe is a self extracting and executing program that installs all the tools and then automatically runs the C:\MGtools\GetLogs.bat programs which silently runs all of the scans and puts the logs into the C:\MGlogs.zip file.


    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  17. jtu50

    jtu50 Private E-2

    chaslang,

    Just wanted to thank you for all of your help. Your efforts are truly invaluable. The young man who owned this computer was thoroughly educated in how to help prevent further infections. Hopefully the lesson will stick!

    JeffR
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds