Malware messing with XP?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bgarten, Jul 27, 2008.

  1. bgarten

    bgarten Private E-2

    I am working on a friend's computer with Windows XP. It is a Dell Dimension 2400. When I got the computer, it came up with the message that this was not a geniune copy of Windows. I thought that maybe they had upgraded with a bootlegged copy of Windows, but it has a geniune Windows XP Home edition Dell sticker on it. I tried to run the suggested programs in the Read this first, but it keeps telling me that I don't have permission to run them. When I try to shut down the computer, it tells me that I don't have permission to shut down the computer. The only way that I can shut down the computer is to log off first and then shut down. Is this a malware issue? and if so how can I fix it if it wont let me run the scans. By the way, I have tried to run them in safe mode under the administrator, but it just says the programs are corrupted.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you actually try ALL steps in the READ & RUN ME? Make sure that you have at least tried to get MGtools to run and attach the log from it.
     
  3. bgarten

    bgarten Private E-2

    I tried but I will try again and let you know
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please make sure that you try all steps. Don't assume that if one step does not work that others will not. Also keep the following in mind, without logs, we cannot help you since all we can do is guess and guessing can lead to even worse problems.
     
  5. bgarten

    bgarten Private E-2

    I finally got all of the programs to run. I think part of the previous problems had to do with the firewall. I disabled it and had fewer problems. Anyway, here are my logs.
     

    Attached Files:

  6. bgarten

    bgarten Private E-2

    And the other one. I am still getting the message regarding windows, but otherwise everything else seems to be working okay.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Viewpoint Media Player as requested in step 1 on the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb005
    O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O21 - SSODL: DI0BAGHI - {06D8289F-02D4-4B4A-6B9E-60AB75D63616} - (no file)
    O21 - SSODL: mtklef - {0F3698C3-A993-4527-9BB5-BD7261C9638F} - (no file)

    After clicking Fix, exit HJT.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! Your Windows Activation issue will need to be discussed in the Software Forum.
     
  8. bgarten

    bgarten Private E-2

    I am not getting any errors now. Things seem to working well. Here is my log
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. bgarten

    bgarten Private E-2

    Thank you so much for your help. It very much appreciated :-D
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds