Backdoor Trojan, Disabled.Security Center Option,Can't Run RR

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mladyraven, Aug 5, 2011.

Thread Status:
Not open for further replies.
  1. mladyraven

    mladyraven Corporal

    Too many viruses to fix so I had to reformat HD. Have not put old files/pictures etc back on computer. First thing I put was my AV from Cox MaAFee Suite. Then I downloaded all the MS updates it took about 2 hours and three times I had to restart until I got back to SP3 and all my updates.
    Then I put SAS, Advanced System Care 4. I then loaded FF and Chrome. I had uploaded my bookmarks to XMark. I downloaded all my bookmarks. FF was fine, however, Chrome went would not work- for more information
    http://forums.majorgeeks.com/showthread.php?t=241893

    After doing all the things mentioned in my Chrome post ( getting rid of X Marks, cleaning computer again I SAS finds - Disabled.Security Center Option. I let it quarantine and things seemed OK.
    I had a Key from MG for Iobit Malware Fighter, I opened that and started to use it.

    Last night it was doing a smart clean when my computer was idle. It found BackDoor Trojan. I cleaned and then restarted the computer. I ran a full scan on Iobit- it said the Backdoor was still there. I ran this three times and shut the computer down each time. Finally after the third time it was gone.

    FF started to freeze, or get hung up, I would try to use CC Cleaner and it would say close FF still open but it was not. It was not in my Task Manager.

    I could not use RR. I downloaded from the link and it only gave me the option of a rar file. I had to download WinZip Quick Pick 45 day temp user to be able to open the file.

    I opened the file as directed, sent to file tab, then clicked scan it said, looking for hidden files... after 5 minutes the screen froze and then it said Root repeal was not responding. I did a hard shut down and then restarted to try again. I shut off all my AV, FW etc...

    I tried to use it again, this time after a few minutes I got a blue screeen

    It said A Process or Thread crucial to system operating has unexpectedly exited or been terminated. If this is first time you are seeing this message then shut down your computer.

    STOP
    0x000000F4
    ( Ox00000003)
    0X89D5A270
    OS89D5A3E4
    0X805C8D78
    This computer was reformatted several days ago with partial help from Dell. Service tag was up so he gave me some help.
    All my file, pictures , etc are on my friends external HD
    I do not want to put anything back on my machine until it is working correctly.
    I never had that problem with Chrome until I reformatted.
    If there is another way for me to run root repeal please let me know.

    As always I appreciate your assistance.
    Thank you
    Raven

    I am adding the Iobit files in case you need them.
     

    Attached Files:

  2. mladyraven

    mladyraven Corporal

    Iobit Malware Fighter logs ( re Backdoor Trojan)

    I am not going to try to install Chrome or anything else until I find out if the machine is clean, and why Root Repeal crashed the system.

    Thank you!
    Grandma Geek! Raven
     

    Attached Files:

  3. mladyraven

    mladyraven Corporal

    When I tried to used Gmer it gave me the same blue screen and error messages.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs look clean to me. Let's just do this.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. mladyraven

    mladyraven Corporal

     

    Attached Files:

  6. mladyraven

    mladyraven Corporal

    PS I was wondering why I could not run Root Repeal, first time freezing the computer and second time giving the error message I quoted.
    I also tried to fun Gmer and it froze the computer and then went to blue screen...
    Thanks
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have already seen a HJT log from you, it is included in the MGLogs.zip.

    Not a malware issue.

    You can ask about this in the software forum and I am sure it will not cost what Dell quoted.

    Do not worry about it, Rootrepeal does not run half of the time.
     
  8. mladyraven

    mladyraven Corporal

    Are you saying there are no malware issues on the computer now?
    That me not being able to put Chrome, Real Player , etc on the computer are not malware problems?

    It seems like the only browser that is working properly is IE and it was never like that before.

    Sigh, thanks for the help. I am totally confused and frustrated. Being a senior citizen I try to do things by myself , or with the help of MG...:) there is no way I can pay Dell 59 dollars for basic information. And forget about Geek squad it's obscene. Well, I will keep plugging away trying to figure this out. I appreciate your help.

    I am going to assume you are saying everything is clean and there are other problems going on that would explain why I cannot even open Real Player exe or Get Chrome to work.
    Thanks
     
  9. mladyraven

    mladyraven Corporal

    Help someone please.
    I cannot load Chrome, I cannot load FF, I cannot load Real Player.....
    Chrome will not install, FF installs but freezes and Real Player will not install at all.

    IE is the only browser working. Window's Media Player is the only player working.
    Could this be a reformat issue,
    Root Repeal did not work and neither did Gmer.
    I really cannot stand only using IE.
    I downloaded Opera and it will only work if I open one tab if I open more then one tab it does not work. It freezes, hangs up , does not show up in the Task Manger and then I have to close down with a hard shut down.
    I got a message went by to quickly but said someting lieke Ns...Event Window not registering. I am getting crazy messages like that and then it will not shut down.
    I am not sure what to do next. Any help would be greatly appreciated. If I need to post somewhere else please advise.
    Thank you
    Raven
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I said, I am not seeing any malware, no. We can have you do this to have one more check.


    Run this and attach the results.

    Using ESET's Online Scanner

    The issues you are having sound like operating system problems to me, which can be discussed in the software forum, as it is not topic for the malware forum.

    Root repeal always has just a 50-50 chance of running anyway. Same with gmer.
     
  11. mladyraven

    mladyraven Corporal

    Thanks, I will run this last program. I got a message from Iobit that the Backdoor Trojan was a false positive message and they have "fixed the problem". So, I reformatted for nothing..sigh. Could they have reformatted wrong and that is why none of the programs are working.
    I am trying to get help in software.
    I just want to make sure the machine is clean. Thanks for your help. Grateful.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just let me know the results of the scan when you are done. :)
     
  13. mladyraven

    mladyraven Corporal

    Thank you for suggesting the online scanner. I am glad I continued to follow up with this. I ran the program... it found 2 problems. At 89% McAfee came back on ( even though I set it for 45 minutes, it came on at 20) so the program stalled. I copied the log and ran the program again, the problem was still there.
    I have included both logs.
    Please advise what to do next if anything.
    Thank you
    Raven
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ESET didn't find problems. Nothing to worry about. This just about concludes our analysis I think. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:

    We are finished in this area of the forum now, you can continue to discuss any outstanding issues in the software forum. :)
     
  15. mladyraven

    mladyraven Corporal

    Win32.PrcView Information and Removal.
    Copyright © 2011 Sunbelt Software. Reproduction in whole or in part without permission is prohibited.

    Threat Name Win32.PrcView
    Category Trojan
    Level HighLevel information
    Advice Remove
    So, I assume being this was removed my problem is gone.

    I found info on Win32/OpenCandy application and it is confusing re what it actually is! LOL It seems to be safe.
    You stated the computer is clean so, I will follow the steps you included to close things out and then see if the anyone in software can help me with the other problems.

    Thanks for the help.........appreciated!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing. :)
     
  17. mladyraven

    mladyraven Corporal

    Thanks, I don't understand what is going on. I downloaded Open Office from the site yesterday. I open it today and it says that Java is now corrupted.
    A few minutes ago Malware Fighter found a virus. I have included the report.
    Just want to make sure before I put my files and photo's back on.. sorry, I think the OS install was not good.

    Is this another false positive from Malware Fighter?:-o
    Thank you
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's di a bit deeper then.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      2007176*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  19. mladyraven

    mladyraven Corporal

     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry, I went about it the wrong way, had you run systemlook when there was really no need! :)

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Does Malware Fighhter still detect the reg key or not?
     
  21. mladyraven

    mladyraven Corporal

    Sorry, I made a mistake and did not see the "all files" I was in a hurry to get to the Dr. So , I had to redo it and want to make sure I did it right before I click on it or should I just start over.
    Did you want me to fun Malware Fighter after I do what you suggested or before.
    Thanks for all your help and patience.
    fixme.reg will not attach it says invalid file.
    I am not sure if I should just delete what I have an start over being you cannot read the file.
     
  22. mladyraven

    mladyraven Corporal

    OK, I did it and information was successfully added to the register. Now I will run Malware Fighter.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know how it's next scan turns out then. We also have a few more items to take care of once you respond.
     
    Last edited: Aug 13, 2011
  24. mladyraven

    mladyraven Corporal

    Scan is now clear. I did a CKDSK and it found a few problems that it says are now fixed.

    Thanks for your help, ready for the next step. I was sick yesterday.
     
  25. mladyraven

    mladyraven Corporal

    I did some cleaning as suggested in a post by Chaz, I cleaned Java, IE, Cache and ran MBR here is the information
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No new items to take care of, I was thinking of another thread. :)

    We are done.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  27. mladyraven

    mladyraven Corporal

    Thank you. I will do all you mention. Software is trying to figure out why I cannot load Chrome, Real Player, etc.... however it is not Malware, I hope it was not a bad reformat!

    Thank you for all your assistance and patience. Greatly appreciate!
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. :)
     
  29. mladyraven

    mladyraven Corporal

    :cry I just returned home from the Dr. I turned the monitor on and Malware Fighter was on saying it found a Malware Guid in HKEY...

    Last night I ran Malware Fighter on the files and photos' that were on the external HD. It said they were clean.

    I put them in a folder on my desktop and then transferred them to another external HD a friend said I could use until I could learn how to put my files back on the computer the proper way.

    Before I put the files on the external HD, I ran Malware Fighter again.

    Then I come home to find this...Report attached, it this something serious and how is this happening. Rhetorical question....
    Sigh, I do not watch porn... LOL, so , it is not happening from that. :-D

    Thank you
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Start a new thread please. This one is WAY too long now. ;)
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But let me add a comment, what IObit found is just a left over registry entry from Weatherbug. It is not really malware. Nor is it really a problem. It has just long been considered adware. Software like this is really insignificant in the scheme of things these days the way malware has become so insidious. ;)
     
    Last edited: Aug 17, 2011
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds