Antivirus sites blocked, updates disabled, W.Explorer malfunctions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RisenWarrior, Nov 23, 2009.

  1. RisenWarrior

    RisenWarrior Private E-2

    Hi.

    Malwarebytes crashes 4 seconds after opening. I cannot install any anti-virus; anti-malware as it will also crash after trying to update definitions. Most Trend Micro products will not even open like Cwshredder and Rootkitbuster. Google searches redirect to odd sites. Windows explorer folders are not functioning properly.

    I need help. Here are some log files from Hijackthis; Gmer; and Dial-A-fix attached. Nothing in Gmer came up in red during its scan.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please try doing the below:

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. It does not save a log.

    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. RisenWarrior

    RisenWarrior Private E-2

    Thank you for your reply!!

    Here are the log files you wanted attached. Superantispyware only found a few tracking cookies, nothing else.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue you must put this machine into normal start up as requested per the R&R using MSCONFIG. Once that's been done carry on with the below:
    __________



    I am seeing the below in your logs:
    Why were you using Combofix on your own?

    Can you attach those two logs for me.

    C:\Documents and Settings\Kelly\izunlr151.exe <--- what is this?


    What are you using the below files for?

    Go to this link and download a fresh copy of Combofix before we move onto the next step:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    2c00587c.exe
    
    DirLook::
    C:\_OTL 
    
    File::
    C:\WINDOWS\system32\kfsgg
    C:\DOCUME~1\Kelly\LOCALS~1\Temp\kwpdqkod.sys
    
    Folder::
    C:\Documents and Settings\Kelly\Application Data\AVG8
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach all the logs I requested from Combofix. ( three in total)

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. RisenWarrior

    RisenWarrior Private E-2

    Hi, Kestrel13! I ran msconfig and it says it is in 'normal startup mode'. I did not have to change anything.

    About your inquiries about combofix and the other programs, I posted in the Malwarebytes forum as well as here. Someone responded there first, and I am desperate to remove this malware/rootkits. I have followed all his instructions without question. In the last 11 years I've been using computers, I've always been successful at removing infections on my own. This time I can't. I'm spending alot of money on an internet connection that I currently can't enjoy.

    Here is the link thread for the other forum malwarebytes.org/forums/index.php?showtopic=31554

    All the requested logs are there. Perhaps you can offer a fresh perspective on the findings.

    I fully understand if you don't want to help me any further. If I broke any of your forum rules by doing this, I apologize. The other person who helped me is very busy, and seemed confident that I was clean now & uninfected. I am not. So, I answered your post to see if you could help where he could not.

    Your suggestions of using avp.bat; exehelper; superantispyware; and MVGtools are helpful & new because they were not asked to be used by me earlier in the other forum.

    I do not know what 'izunlr151.exe' is. I don't know what 'C:\WINDOWS\REGKEYNT.INI' or 'C:\WINDOWS\winstart.bat' are either.

    Will you look at the other forum link, and still offer your help to me? If you say that the other helper has been doing me a disservice and you have a better strategy, then please let me know. I am not anywhere near as computer experienced as either of you.

    I still cannot open Malwarebytes for more than 4-5 seconds. My Google searches STILL redirect at random. I cannot open Media Player Classic [I can open VLC, but I like the settings better in MPC]. The only only online virus scan that was somewhat successful was Trend Micro Housecall. The first 2 times I used it on my own, it found a couple of trojans and a rootkit. The last couple of times I've used it, it found nothing. Any other antivirus program I tried to use will install fine. As soon as I try to update the defintions, I get 404 & 405 forbidden errors.

    This all started a couple of days ago when I did a Google search for the band Sonic Syndicate. I clicked on a link that took me to what looked like a normal web page, but then my internet and computer froze. I rebooted and now I'm in this mess.

    Please let me know either way what you decide. Thank you very much for your help so far! -Kelly.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    You should refrain from cross posting across multiple forums because this is such a waste of resources. Instead of just having one person who volunteers there time to assisting you, you now have two of us, and we are very busy in our lives offline too ;)

    I wouldn't be able to continue to help you until you decide upon which of the two forums you wish to receive help at. If you wish to work through it with me then you must now go to the Malware Bytes forum and request that you wish the thread to be closed as you already started receiving help at another forum and are going to continue there...and vice versa.

    Let me know what you want to do, and if you do work thru with me then you must follow my previous instructions which I posted above.
     
  7. RisenWarrior

    RisenWarrior Private E-2

    Hi again. I thanked the volunteer in the Malwarebytes forum for his help. I then requested for the thread to be closed, as I was receiving help from someone in another forum.

    I downloaded a fresh copy of Combofix from the link you provided. When it ran it displayed a 'Not enough memory to complete sort'. Came up twice while Combofix was running. Never saw this error the previous times I ran it.

    The logs you requested are attatched. I did not include the log from the first time I ran Combofix on my own. I only included the 3 you requested where a CFScript was used. My computer has not improved any yet.
     
  8. RisenWarrior

    RisenWarrior Private E-2

    Sorry. I uploaded the attachments but not sure why they didn't attach to my previous post. I will try again now.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, that's fair enough :)

    Now let's do the below: (whilst I am working with you please do not install anything other than what I request you to install, please do not make any changes until I have given you final steps) The script below is partly the same as what was in one of my previous posts, but I added some files, so let's get started...

    We need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Driver::
    2c00587c.exe
    
    DirLook::
    C:\_OTL 
    
    File::
    C:\WINDOWS\system32\kfsgg
    C:\DOCUME~1\Kelly\LOCALS~1\Temp\kwpdqkod.sys
    C:\Documents and Settings\Kelly\izunlr151.exe
    C:\WINDOWS\REGKEYNT.INI
    C:\WINDOWS\winstart.bat
    
    Folder::
    C:\Documents and Settings\Kelly\Application Data\AVG8
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach all the logs I requested from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  10. RisenWarrior

    RisenWarrior Private E-2

    Here are the 2 new logs you requested. Is it ok for me to download & install Windows Updates that keep popping up, or should I ignore them for now?
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes by all means grab your windows updates.

    Now your combofix log is incomplete and the script didn't work, so all the files and folders I wanted deleted still remain.

    We must now download another fresh copy of Combofix to your desktop and then follow the steps of my post # 9 again, including running the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also attach the C:\combofix.txt file. Hopefully this time round we will achieve what we need to do! :)
     
  12. RisenWarrior

    RisenWarrior Private E-2

    'Not enough main memory to complete the sort'. This is what displays when Combfix first runs. Then it begins to scan files. When finished the computer reboots on its own.

    Once it has restarted Windows, Combofix opens to prepare the log file. Again the 'Not enough main memory to complete the sort' appears.

    I'm not sure what link I used on the other forum for Combofix, but it never shown those errors before. He provided 2 links for Combofix. The first is identical to yours : www.download.bleepingcomputer.com/sUBs/Combofix.exe

    The other link was: www.forospyware.com/sUBs/Combofix.exe

    I do remember that when I last used Combofix on the old forum, it asked to 'update'. I said 'no'. I thought it might interfere with the scan. Now, everytime I've run Combofix for you, it doesn't ask about the update. Did I put something in memory that is now preventing Combofix from running & updating properly? Is there a way to 'clean' Combofix off my computer before running a new copy?

    I have followed your instructions exactly. I am only using the Combofix link you provided and saving it to my desktop. I am careful to copy all the text you require to save to CFScript.txt.

    Help please!
     

    Attached Files:

  13. RisenWarrior

    RisenWarrior Private E-2

    Haven't heard from you in 3 days now. Have you given up? Do you have a new strategy? Or is it time to reformat?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No. I haven't. I don't give up. Please find it in your heart to be patient with me, I have been working and I shall get back to you with a set of instructions as soon as possible. I have some things for us to do, as I said, just be patient, we have lives that extend outside of the malware forum too :)

    Edit: Also read this: Don't Bump! It Only Hurts You!!!

    Thanks
    Kes13!
     
    Last edited by a moderator: Dec 1, 2009
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's try this as combofix doesn't appear to be running properly.

    1. Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    2. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    3. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  16. RisenWarrior

    RisenWarrior Private E-2

    I reformatted the computer and reinstalled. It's running great now.

    Thank you for trying to help. This thread can be closed now.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry to see you didn't apply my fix, but glad to hear you're all up and running again now! Safe surfing ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds