Constantly getting corrupt files while installing anything

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mbam, Sep 8, 2011.

  1. mbam

    mbam Private E-2

    Hi,

    No offense, but I really wish I didn't have to find myself on this forum in the wee hours of the morning :(

    I know you guys are the best, so despite my misgivings about this situation, I am very glad this forum exists.

    Before I describe my problem, please note that I have tried running MBAM and SuperAntiSpyware, but I could NOT run any of them, even the portable versions, even after renaming them. With mb.exe, I get a "source file is corrupted" error. With the SAS portable, it won't even open at all.

    Also, as another quick fix, I tried doing this: http://www.bleepingcomputer.com/forums/topic415364.html

    because my problems seemed similar to the ones described. Nothing.

    An Avast quickscan found nothing, and spybot only found a few cookies which I deleted.

    Here's what's happening:

    I've been having some weird problems with 32-bit and 64-bit installs on my Win7 machine. Every time I try to install anything (I was trying to install Git when I noticed this) the installation comes up with an error saying that a file involved in the install was corrupted, and I must abort or retry. Retrying never does anything. Neither does restarting or re-downloading the files.

    I originally thought this problem was coming from 7-Zip or WinRar because I would get corrupted file warnings on perfectly normal looking archives.

    Then things became more diabolical. I was trying to update Malwarebytes to do a scan, so I had it download the update and install that. During that install, I got yet another corrupted file warning. As a result, I could no longer run malwarebytes. So at that point, I got scared that if I tried updating any of my AV/AMW programs, I was going to get totally screwed. Unfortunately, most of my AV programs are out of date-- long quiet periods get me off my guard I guess.

    Hoping that it was just bad luck, I downloaded and attempted to install the Tortoise SVN 64bit client. This install failed at the "copying new files" phase of the install. The error message was: "The cabinet file TSVN.cab required for this installation is corrupt and could not be used".

    Another weird symptom: I got an "unable to open file" message when trying to re-enable my DeFogger.

    I have no idea what I did this time. The only stupid thing I've done recently is drop my laptop 2 feet onto my carpeted floor. I'm probably being an idiot thinking that I am experiencing software issues due to dropping my laptop, but I was a bit scared I did some damage to my hardware because some keys on my keyboard were unresponsive on my initial restart...after a second restart, everything appeared to be normal.

    Also, I have never--not even once-- run windows update since buying this laptop in january. That could be seen as either completely stupid, or a rational move, not sure.

    Do you have any advice? Thanks in advance.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. mbam

    mbam Private E-2

    Attached: SAS log, exehelper log, (no mgtools zip file unfortunately)

    The first time i ran rkill, I falsely thought it had finished running, but my Avast was still trying to get it to shut off. So, before I figured out that it was not done, I ran exehelper...

    exehelper killed that process, as you will probably see in the log. So I re-did rkill, waited for it to finish, and then ran exehelper a second time.

    I tried running SAS online, but nothing happened after hitting "Run", in IE, Chrome, or Opera. Earlier today, I managed to download sas and run it (with updated definitions). It found nothing, and I attached that log too.

    Finally, I could not get MGtools to create the zip file. It went through its process, then, the cmd.exe window just disappeared without saying anything. There is no MGlogs.zip anywhere on my PC. I tried running MGtools again and the same thing happened.

    Please advise.
     

    Attached Files:

  4. mbam

    mbam Private E-2

    Just an update: I got Malwarebytes to run after saving the exe as something completely random. It took 4 hrs to run SAS earlier today on my 500GB hdd, so it may be awhile before I have any results...
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach the log once done.


    Also please run Combofix as per the instructions in the READ & RUN ME FIRST. Malware Removal Guide Attach the log please.


    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply as well as the other requested logs..
     
  6. mbam

    mbam Private E-2

    I've attached:
    mwb scan log
    combofix log
    mbrcheck log
    both OTL logs
    tdss killer log

    I'm going to split these files up in two posts

    Thanks for your help once again!
     

    Attached Files:

  7. mbam

    mbam Private E-2

    The 2nd OTL log file and the tdss killer log are here
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does this problem still exist? Are you able to install now? I assume so because obviously you eventually got Malware Bytes and Superantispyware run etc...

    Try this.


    Run this and attach the results.

    Using ESET's Online Scanner

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    • cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    • nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    • ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    • analyse <-- this attempts to run HijackThis. Be sure to click the Accept button twice in the license agreement popup or it will just sit there and wait.
    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  9. mbam

    mbam Private E-2

    ESET worked fine, but I had to re-download and reinstall MGtools to make it work--literally none of those command prompts worked because there were about 3 total files in my \MGtools directory before my re-install.

    I am slightly concerned that any exe I have downloaded during my period of infection is corrupt.

    So I'm attaching the ESET log and the mgtools zip file that came from just running MGtools exe straight up.

    ESET quarantined OrbitDownloader, which was a FF add-on. I uninstalled it after ESET quarantined it. Guess I should be wayy more concerned about browser addon security. I'm probably going to uninstall all of the ones I have for chrome and ff after this.

    Could you please confirm whether I'm in good shape now? Thanks.
     

    Attached Files:

  10. mbam

    mbam Private E-2

    Also, what does it mean if RKill.exe keeps randomly popping up and running? It never comes up with anything. Do I need to uninstall/delete it?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. The problem was on our end. And incomplete download file had been there. What you last downloaded was an older version that I temporarily put there as a workaround until I could fix the build of the new version.

    Please try it again now. There was a problem with the last file. I just updated it. Download and run the new MGtools Please attach the new MGlogs.zip file now. Thanks!
     
  12. mbam

    mbam Private E-2

    Here you go.
     

    Attached Files:

  13. mbam

    mbam Private E-2

    On a side note, I am unable to open KeePass (not good), -- error message is "A device attached to the system is not functioning." I can, thankfully, open my password database on a different machine using keepass...

    Is there a chance that all my passwords have been compromised?

    edit: fyi this happened even after I reinstalled keepass
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not topic for the malware forum. You can ask about this and any other issues you may have in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes there is a chance. We cannot tell for sure. It is always a good idea to change passwords peridically anyway. ;)
     
  16. mbam

    mbam Private E-2

    I did a lot more than that over the weekend. I'm leaving on an international business trip soon, and I needed my laptop to work today; so, I took some significant measures. I restored via a 3 month old image. Then, I ran a whole bunch of security tools listed on your downloads page, the most significant of which was Hitman Pro, which managed to find and delete several malware programs and two trojans. I've attached that log if you're interested.

    Since then, I've cleaned my registry, installed a firewall, run MBAM and SAS, and have come up with nothing. Looks like this system is about as clean as it can be short of a clean install of Windows.

    Is there anything else you recommend doing?
    Thanks for your help!
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not if everything is running well. You do have anti-virus installed though, right?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! There were no real issues in that hitman log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds