can't go beyond the first step in windows xp cleaning procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rvillanv, Feb 22, 2010.

  1. rvillanv

    rvillanv Private E-2

    Hi.

    I was able to download all the tools (superantispyware, malwarebytes, combofix, rootrepeal, and mgtools) and put them on the proper folders. it took a while before i was able to finally install malwarebytes but i got it installed.

    i am able to run superantispyware, and even encountered the internet connectivity problem. the "repair" button won't run because of some error but i was able to finally repair it through winsockxpfix.exe

    the problem comes when i run malwarebytes. i am able to get as far as clicking the "scan" button sometimes but it just stalls. i've tried several times but it still just stops. sometimes, it displays the error "malwarebytes is already running" but it really isn't. i tried running exeHelper before malwarebytes, as recommended by an article in bright hub but it still didn't help.

    i tried running the other tools - combofix, rootrepeal, and mgtools - but they don't run either. after a bit, they just stall and i'm back on the screen with the wallpaper again.

    attached is my SAS log.

    thanks in advance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.

    Then try running these instructions: Using MGtools

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. rvillanv

    rvillanv Private E-2

    thank you in advance. will try those steps ASAP :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ok. I will be here waiting :)
     
  5. rvillanv

    rvillanv Private E-2

    uh-oh. can't download any of the Rkill files - all four of them.

    tried the online scan but connection keeps timing out :(
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ...and are you able to complete anything in safe mode?
     
  7. rvillanv

    rvillanv Private E-2

    i tried running avira (i load avira and avg alternately cause after i close the PC and then open it again, i usually end up with a corrupted anti-virus program) and it kept detecting a number of trojans and trojan droppers. when i restarted the computer, the program was not working again so i uninstalled it. i try running SAS which is usually the only program (out of the five that was recommended) that would run and it would detect around ten or more spyware every single time i boot the computer.
     
  8. rvillanv

    rvillanv Private E-2

    will try safe mode, but the last couple of times i tried going to safe mode, it won't go to safe mode. it just keeps restarting. whenever i select safe mode it restarts and the only way i can start is to go to normal mode :(
     
  9. rvillanv

    rvillanv Private E-2

    hi. i tried safe mode but it really won't open. it kept restarting and when i select safe mode, it would restart again, so i was forced to open using normal mode.

    i tried downloading rkill through other sites but my browser kept timing out on these sites.

    thanks so much.
     
  10. rvillanv

    rvillanv Private E-2

    i've downloaded avast and so far it detected one trojan and another thing. it cannot update though, neither can i register it, but so far, it seems to be working okay. i'm still trying to download Rkill anywhere i can get it, or to boot in safe mode, although none of my attempts has yielded anything. oh well. will be waiting for more instructions from you ... and thanks.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    tell me what happens when you rename combofix and MGTools.exe.

    Rename combofix to 123.com > also rename MGTools.exe to MGTools.com and let me know the results. Try in normal mode first and then safe mode if normal is unsuccessful.
     
  12. rvillanv

    rvillanv Private E-2

    hi. combofix seems to be running after the rename, but i don't exactly know how to disable my avast so that combofix will run. uhm, how do you do that?

    also, do i need to start from the beginning again? (run all the steps in the read and run stuff?) thanks!

    truly, your support is the best, and thanks in advance. my computer (which to my mind has been in virtual hell all this time) thanks you too.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good, and hopefully MGTools will run too, those are the most important logs of all as well as combofix.
    which version are you using? If version 5... locate it's icon in your notification area, right click > and disable until next reboot. If using version 4 then right click the blue icon and disable on access scanning (If I remember correctly) Then just a case of right clicking and re-enabling afterwards. :)
    Just concentrate on Combofix and then MGTools for now, then once we have made some progress, I will have you try with SAS and MBAM too, and whatever other tools we may need.

    You're very welcome :)
     
  14. rvillanv

    rvillanv Private E-2

    hey :) i sorta figured it out. avast is running again and i was able to run both scans.

    attached are my logs :)
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good. We're making progress now:

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode, if you haven't done so already.

    2. Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 16
    • Java(TM) 6 Update 17

    3. Now we need to use ComboFix to be rid of some malware and also clear up remnants from the avg you were using before you switched to avast.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    NetSvc::
    qikrv
    wyiey
    
    Driver::
    qikrv
    wyiey
    butdxzpe
    gcdvhman
    
    File::
    c:\windows\system32\drivers\avgntflt.sys
    c:\windows\system32\01.tmp
    c:\windows\system32\zcuqf.dll
    c:\windows\system32\butdxzpe.sys
    
    Folder::
    c:\documents and settings\Atty.Villanueva\Application Data\AVG8
    C:\$AVG
    c:\documents and settings\All Users\Application Data\avg9
    C:\Program Files\AVG
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\butdxzpe.sys]
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\qikrv]
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\wyiey]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    5. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    6. Let us know of any problems you may have encountered with the above instructions and also let me know how the machine is behaving now!
     
  16. rvillanv

    rvillanv Private E-2

    here are the new logs.

    i don't know if i did the mgtools properly, because it showed an error message, although i can't remember it now (i'm sorry i forgot to write it down). it was something about a dll file. i checked the log and i think this is the new log cause the date stamp is about a couple of minutes ago only.

    thanks again.
     

    Attached Files:

  17. rvillanv

    rvillanv Private E-2

    incidentally, i never did the MSConfig to put it back to normal start up mode since it always ran on normal, so i didn't have to "go back to normal start up mode" ... or was i wrong and it was starting on safe mode and i just didn't know about it?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. :) Those logs are looking great now.

    Rename 123.com back to combofix.exe.

    Now open up MBAM > update > run a scan > fix all it finds and attach the log it creates into your next reply here.

    Do the same for SAS.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You must have something controlling start up's then if not msconfig.
     
  20. rvillanv

    rvillanv Private E-2

    what i meant re MSConfig was that i skipped that part :)

    will run the additional instructions now. you're the absolute best :)
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem! :) Getting real close to my sleep time now though, 3.30am :zzz So gonna get settled down shortly, but if I don't get back to you tonight, for sure in the morning.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ok, but dont confuse safe mode with "using msconfig to put your pc back into normal mode" as they are two different things. :)
     
  23. rvillanv

    rvillanv Private E-2

    hello.

    i'm not sure if you're asleep already or not but thanks in advance.

    i was able to run all the stuff you told me to do. except that i got the same error with the mgtools

    it said that the processDll.exe "the application failed to initialize properly 0XC0000135)" on the error box.

    attached are my logs :)

    thanks so much again.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The error message was explained here:

    Using MGTools

    The logs are clean. :) Just ensure you keep MBAM and SAS for scanners as they are two of the best out there. Run them regularly and surf safely,files like the below are to be avoided. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  25. rvillanv

    rvillanv Private E-2

    downloaded dotnet fix :)

    will follow the other procedures you recommended.

    as for me and downloading, i think i will have to stop getting free stuff online, unless i'm sure it's clean.

    thanks so much again.

    by the way, yesterday, even after running the processes you recommended (the source of the clean logs), avast detected a new malware trying to open itself (i'm not sure if that's the right word for it). anyway, it was able to stop the process so i'm happy for that. but i'm not sure if i should do the same cleaning procedures i did for this PC with the other PCs in the network. there's around 9 other computers on the network, and our outsourced IT person installed AVG on most PCs except that after a day or two, AVG will have lost all of its components (for some reason) but then since no one really scans their computers (we're not a techie bunch), no one knows the extent of malware infestation. the only reason why i became so concerned was that my USB kept acting up when i did this one lecture and the PC i used there detected the problem. then, when i started cleaning things, that's when all the effects got worse (AVG stopped running, can't access internet, etc). thank goodness my googling led me here and now i have a perfectly functioning PC.

    anyway, that's my story, and if you can recommend what i could do for the other PCs, i'd be glad for your help.

    thanks again for your time. you are an angel :)
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Majorgeeks is a great site that hosts LOTS of software which is all thoroughly tested for malware before being offered out to the public.

    I'd need the exact file path to the "threat" being found. It could have just been a FP and detecting Combofix or such as.

    I take it you are referring to a business network then. If the IT guy is not a "techie kinda guy" then why is he the IT guy may I ask?

    He is employed and paid for what we have done here for free. I'm very happy to have helped you with one machine but servicing 8 or more also besides that... not too sure about :( I think it is against our policies here, and if I was to undertake cleaning all of those PC's on your network, it would mean home users would have to wait for help and they do not have technicians employed to troubleshoot for them.

    No problem. :)

    Especially if this is a work machine!!
     
    Last edited: Feb 25, 2010
  27. rvillanv

    rvillanv Private E-2

    oh we outsource our IT stuff but it just dawned upon me - after four or more days of cleaning this PC - that he didn't really do anything when i complained before about my PC problems. see, i complained about conficker, which was the first one i detected (using the eye chart) and guess what he did - saved my files on drive d, formatted the PC, then returned all my old files after scanning them with avg 8.5. it didn't take long before all my problems returned full force, if not worse :)

    and promise i won't "abuse" your help (or the site's help) by cleaning all nine PCs through this support forum. what i meant was i was going to run the read and run me stuff, but then again, i will most likely encounter problems there and would have to run here and you're right, that would take away time from home users. needless to say, i am very happy with your help (now i can work in peace :) and bring home files in peace. i haven't done that in a while out of fear my home computer (i just got a new lenovo laptop, happiness) will get the same infections. come to think of it, the old one probably does already.

    thanks again, and hopefully, i don't have to be back asking for help again. i wil be back to read all the other questions though. i think i've grown interested in figuring out my own computer problems now. tried reading the logs yesterday although they didn't make any sense to me.

    all the best to you and the other guys at major geeks :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep, that's why I got tired of hiring out technicians at 25 quid a throw! came here and started learning!
     
  29. rvillanv

    rvillanv Private E-2

    hi again. i don't know if i should start a new thread or what, but anyway.

    i haven't had any problems since you found my logs clean and i did do the stuff you recommended to make sure that my computer remains clean. i haven't downloaded stuff online and have basically stuck to gmail, and social networking sites, as well as just reading stuff online and doing research.

    anyway, i try to do an avast scan everyday and it always detects a threat. the file name is c:\Documents and Settings\Network Service\Local Settings\Temporary Internet Files\Content.IES\JF0FOVEM\ovkgtpfe[1].bmp and the status states "Threat Win32:Confi[Wrm] the file name changes but the threat basically remains the same. i've scanned my phone and usb and they've been detected with the same threat even if i've cleaned them too before.

    does this mean there's still something wrong with the pc? thanks!
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try deleting the below bold file by using windows explorer.

     
  31. rvillanv

    rvillanv Private E-2

    windows explorer couldn't find it anymore. probably cause avast moved it to chest already after the scan?
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes quite possibly. I take it avast is no longer detecting the threat?
     
  33. rvillanv

    rvillanv Private E-2

    ran avast again and it was no longer detected. it couldn't scan some avast dll files though but i'm guessing that's just okay?

    thanks again!

    p.s. it's my birthday today. :)
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes! That's normal. Some files are locked by the system or are password protected which an anti-virus program cannot scan.

    You're welcome.

    Happy Birthday to you! [​IMG] Have a great day however you spend it!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds