can't open programs suspect virsus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by whril, Jun 16, 2012.

  1. whril

    whril Private First Class

    Most programs, including the anti-virus will not open or run.
    Thinking it was an .exe problem i downloaded and ran the .exe fix on the Vista Forum. Still don't open. I then tried to run the Avast online virus tool. It will not run for me. I suspect the machine I am working on has numerous viruses. Truthfully I am at a loss as to where to start cleaning it at. Attached is the logs from the programs I could run. Malwarebytes would not run.
    Thank you for any assistance you can give.

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hello whril :)

    [​IMG] Delete items detected by RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    When the scan has finished, press the Delete button.
    Attach RKreport[3].txt to your next message. (How to attach)


    [​IMG] Now scan with Malwarebytes' Anti-Malware.
    Remember to attach your log from this scan. (How to attach)
  3. whril

    whril Private First Class

    Hi thisisu,

    Did as you asked. Logs are attached.

    After running the programs and restarting the anti-virus program finally started and missing items on the desktop have reappeared. This quite surprised me, don't believe I have ever seen that happen.


    Attached Files:

  4. thisisu

    thisisu Malware Consultant

  5. whril

    whril Private First Class

    Attached are the logs you requested.

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 7 (outdated)
    [​IMG] Please download OTL by OldTimer.

    • Save it to your desktop.
    • Right mouse click on the OTL icon on your desktop and select Run as Administrator
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the [​IMG] text-field.
      %windir%\system32\drivers\*.sys /lockedfiles
    • Now click the [​IMG] button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
  7. whril

    whril Private First Class

    Run and attached.
    Thank you for all your time in this.

    Attached Files:

    • OTL.Txt
      File size:
      170.8 KB
  8. thisisu

    thisisu Malware Consultant

    [​IMG] Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the [​IMG] text-field.
    SRV - File not found [Auto | Stopped] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
    SRV - File not found [On_Demand | Stopped] -- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe -- (McSysmon)
    SRV - File not found [Auto | Stopped] -- C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe -- (McShield)
    SRV - File not found [Auto | Stopped] -- c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe -- (McNASvc)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\athur.sys -- (athur)
    IE - HKLM\..\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}: "URL" ={searchTerms}
    IE - HKU\S-1-5-21-2551881464-2562418089-265775080-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
    IE - HKU\S-1-5-21-2551881464-2562418089-265775080-1000\..\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}: "URL" ={searchTerms}
    C:\Program Files\McAfee /d
    Now click the [​IMG] button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    [​IMG] Now install the current version of Sun Java from: here

    Let me know what problems remain after you have completed these steps.
  9. whril

    whril Private First Class

    Do I run the OTL with the instructions you posted prior or the default it opens with?
  10. thisisu

    thisisu Malware Consultant

    Reread my previous instructions. It is for a fix, not a scan ;)
  11. whril

    whril Private First Class

    ahhh.. so i see after rereading.

    Unfortunately it will not allow me. When I click on the fix it gives me a blue screen.

  12. thisisu

    thisisu Malware Consultant

    Hrm, we can skip it. It was mostly just to remove some McAfee remnants. Nothing malware related. How is the PC running?
  13. whril

    whril Private First Class

    Anything on the McAfee I should delete by hand or does it really matter?

    PC seems to be running well. I will run it for a couple of days, clean up some programs etc. before I return it to my sister.

    Is the machine now clean? I noticed that a quite a bit of the malware had mywebsearch. I am not familiar with the program. Should it be removed from the computer?

    Thanks..... you have been great!

  14. thisisu

    thisisu Malware Consultant

    We can try the manual way. I've attached a .zip file with two files inside of it.
    Extract both to your desktop and then run each of them (one at a time).
    For the fix.bat, right-mouse click it and select Run as administrator.

    Attached Files:

  15. whril

    whril Private First Class

    Thank you. Will try this tomorrow and let you know how it goes.

    I have run into another problem, described below. Not sure if you can continue or have me post somewhere else for this one.

    When I click on games this pops up:

    "An ActiveX control on this page might be unsafe to interact with other parts of this page. Do you want to allow this interaction."

    I know nothing about ActiveX. Way out of my league.

  16. whril

    whril Private First Class

    Yes! The fixes you sent worked. Thank you so much.

    Now it looks like the only major problem that needs to be solved is the ActiveX. Can you help with that or do I need to post in another forum topic?

    I can't thank you enough for you time.
  17. thisisu

    thisisu Malware Consultant

    Certain activeX installs are required in order to play some browser based games. As long as you know the game you are trying to play is legit, it shouldn't be an issue.

    Typically it just has to install once and then you won't get prompted again (unless you are playing many different games).


    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
  18. whril

    whril Private First Class

    There doesn't seem to be any more malware problems. Again I thank you for all your help.

    Still not sure about the ActiveX. Only a yes or no option. Will probably just delete the games.

  19. thisisu

    thisisu Malware Consultant

    I think that would be best. ActiveX type games are how many people get infected in the first place.
  20. whril

    whril Private First Class

    Thanks! I don't think i really knew that. You made up my mind for me. Deleted they are. After all you guys are as expert as they come.
  21. thisisu

    thisisu Malware Consultant

    No problem. Be safe :)

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds