All experts to Malware ER.. vital signs deteriorating.. (please help)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RedLips, Oct 1, 2009.

  1. RedLips

    RedLips Private E-2

    Hi,

    This forum's great, I hope one of you lovely people can help.

    I borrowed my sister's laptop a couple of months ago. It was working fine but has since deteriorated. It takes very long to load, and programs keep freezing and crashing, in particular Internet Explorer (sis is not a fan of Firefox unfortunately and doesn't want it on her machine), with the error message "this programme has encountered an error and has to close"

    The last time few times I've turned it on, it tells me my firewall is not turned on (but appears to be on when I check) and today after booting up:

    Generic Host Processes for Win32 has encountered a problem and has to close

    followed by:

    DCOM server process launcher service terminated unexpectedly. Shutdown initiated by : NTAUTHORITY/SYSTEM

    and the laptop then restarted. Worried now because I don't know much about computers but I know Win32 is important somehow.

    I've been slowly working my way through the READ AND RUN ME FIRST in order, and have finally finished doing it today, so I'm attaching the logs. SuperAntiSpyware found a load of malware and I thought the problems would stop after it cleaned them up but the laptop issues appear to be getting worse and rootrepeal appears to have found a rootkit and I don't how to get rid of it..

    Please please help!
     

    Attached Files:

  2. RedLips

    RedLips Private E-2

    MGtools attachment

    MGTools
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    GMER's MBR.exe

    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.


    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\etymec.dat 
    C:\Documents and Settings\Sal\Local Settings\Application Data\girifipif.lib
    C:\WINDOWS\fumy.lib
    C:\WINDOWS\iqipixa.db
    C:\WINDOWS\orijib.lib
    C:\WINDOWS\Temp\$$$dq3e
    C:\WINDOWS\Temp\$$yt7.$$      
    C:\WINDOWS\Temp\$67we.$ 
    C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
    
    Folder::
    C:\Documents and Settings\Sal\Local Settings\temp\WER1da7.dir00
    C:\Documents and Settings\Sal\Local Settings\temp\WER9350.dir00
    C:\Documents and Settings\Sal\Local Settings\temp\WERa394.dir00
    C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * Gmer Log
    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. RedLips

    RedLips Private E-2

    yay thank you for responding! here's mbr.log
     

    Attached Files:

    • mbr.log
      File size:
      551 bytes
      Views:
      2
  5. RedLips

    RedLips Private E-2

    second
     

    Attached Files:

    • mbr.log
      File size:
      576 bytes
      Views:
      2
  6. RedLips

    RedLips Private E-2

    had a bit of a problem shutting down AVG before the combofix scan, but i managed it eventually
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The temp files are gone, but I want to make sure the MBR infection is also gone. You will need to boot to the Recovery Console if you have installed it (perhaps when you installed ComboFix) to remove this infection.If not, then you will need to boot to the xp cd.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  8. RedLips

    RedLips Private E-2

    Hey Tim,

    Thanks for your help so far. Got a problem, though. I don't have an XP cd, and when I tried to run fixmbr on Recovery Console I got this message:


    Caution
    This computer appears to have a non-standard or invalid Master Boot Record.

    FIXMBR may damage your partition tables if you proceed.

    This could cause all the partitions on the current hard disk to become inaccessible.

    If you are not having problems accessing your drive, do not continue.

    Are you sure you want to write a new MBR?



    What d'you reckon?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That message often comes up depending on the manufacturer.....it is ok to go ahead and run it.
     
  10. RedLips

    RedLips Private E-2

    There you go...
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good....your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. RedLips

    RedLips Private E-2

    Hey Tim,

    Thank you so much for your help. I was just wondering if there is any reason why the laptop is still running slow despite the lack of malware and anything else I could try to amend this problem?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....add more RAM:

    Total Physical Memory 512.00 MB
    Available Physical Memory 153.63 MB

    You also need to use add/remove programs to uninstall:
    Norton WMI Update"

    Then please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.
     
    Last edited: Oct 24, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds