Please help with malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Axsca, Apr 14, 2009.

  1. Axsca

    Axsca Private E-2

    Well, where to start. My computer has been getting progressively more problematic the last few months. I can't specifically remember where or how it started. The earliest symptoms I remember are applications taking anywhere from one to 4 minutes to open, or just timing out completely. I would have to create tabs in my browsers and never close them to avoid this. This went on for a while, and every now and then it would clear up and act fine. After that my computer, namely the internet, started to lag constantly. Just recently it began to lag so bad that I couldn't load any pages without waiting up to 5 minutes. So I began to run some cleaners, CCleaner and MBAM. This resulted in my computer getting worse. Firefox would no longer open, so I had to uninstall it. Explorer kept giving me multiple pop-ups, so I uninstalled it.. although unsuccessfully. Automatic updates are turned off, unable to turn them on. I attempted the windows XP cleaning procedure in the sticky. SAS wasn't able to run at first so I ran it last when it allowed me to. My registry at first wouldn't allow me to edit, for a while my computer had created a separate administrator account. Both of these are fixed for now. Firefox is still not opening, my automatic updates are still not allowing me to turn them on. Some things are still lagging. Thank you for taking the time to read this. :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should NEVER attempt to uninstall Internet Explore (which is not the same thing as Explorer). You need Internet Explorer or you will not be able to get all of your Windows Updates and will not be able to access many websites that require it. Attempting to uninstall could break your ability to get updates.

    Uninstalling these programs would not help you anyway. The infections are the source of your problems and the infections need to be removed, not IE or FireFox. Your Windows Operating System files are infected and this can be problematic to remove. The first thing you should do is backup important personal data since the act of trying to fix these kinds of infections could cause your PC to become unbootable. Do not backup any executable type file since they may be infected.

    We will have to perform your fixes in stages to avoid make your PC unbootbable. So the below is only the first step. It is not a complete fix. From now on do not run anything except what we ask you to run. Do not download or install anything but what we request. Once we finish your malware removal you will be free to do what you wish.

    You are way out of date with your version of SUPERAntiSpyware.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now download this XPsp2bu.exe to your C:\ folder like MGtools was downloaded. Once you have it downloaded, just double click it to run it. It will extract some files we will need into your C:\MGtools folder. We will be using these in the next fix.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {FCE43167-3446-499F-A0DD-F7D0719B842B} - C:\WINDOWS\system32\bt2k_in.dll
    O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 17, 2009
  3. Axsca

    Axsca Private E-2

    Thank you for taking the time to help me with my issues. I'm really appreciative. I've done the things you've instructed, and attached the logfiles as requested. The first time I ran SAS my computer restarted itself, so I ran it with the altered settings mentioned in the Read and run me first thread and was able to complete the scan.

    After completing the procedure I've noticed that my automatic updates are now running properly, however, I'm still unable to run Firefox or my MS works Word Processor. That seems to be everything, as far as I can tell.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Round two begins. ;)

    Did you purchase RegCure or do you have just the trial program which is totally useless.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
    O4 - HKLM\..\Run: [Fwuqogod] rundll32.exe "C:\WINDOWS\ojuxazexowal.dll",e
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Compaq_Owner\reader_s.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\Compaq_Owner\reader_s.exe (User 'Default user')

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. Axsca

    Axsca Private E-2

    Well, I got all the way to Combofix, but now my computer will not boot up. After I ran the program, I left it to do its thing. So I'm not sure exactly what happened, but when I went to check on it, it was in the middle of restarting over and over. I shut it down and the same thing happens, it won't go past the loading screen without restarting. :(
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember I did say this could happen.

    Will it boot to Last Known Good Configuration?
    Will it boot in safe mode?

    During the installation of ComboFix, you installed the Recovery Console which appears on a menu when you start your PC. You just need to quickly select the recovery console but using your arrow keys and then press enter. Can you get into the Recover Console?
     
  7. Axsca

    Axsca Private E-2

    I was unable to boot the computer using the recovery console. Trying to boot with the 'last known good configuration' did not work either. I was able to boot in safe mode, wherein Combofix finished its process. Should I continue with your previous instructions in safe mode?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happened? Recovery Console does not boot to Windows. It boots to a command prompt?

    Yes.
     
  9. Axsca

    Axsca Private E-2

    My computer reboots itself again before the recovery console can load.

    I followed the rest of your instructions and have attached the logfiles you requested. :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of the infected Windows system files we replaced with good copies were reinfected. Possible there are other infected files causing this or ComboFix was interferred with somehow by the infection. Try doing the below from Safe Boot mode.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. Axsca

    Axsca Private E-2

    After running the script in safe mode I was still unable to boot into windows normally, so I rebooted into safe mood to let combofix finish and run Getlogs.bat.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You immediately became reinfected again. It may not be worth wasting anymore time on this. There are a few more things we could try but odds are the results would be the same. You have too many Windows system files and possibly other executable files that are infected and they are just reinfecting your system immediately.

    Your safest and most reliable alternative is to reinstall from scratch.
     
  13. Axsca

    Axsca Private E-2

    I don't have any discs to reinstall windows. There's a recovery partition on my HD I think. I was able to get into the recovery console after booting into safemode. And now it's asking me which installation of windows I wish to log onto. My options are:
    D:\I386
    D:\MiniNT
    C:\Windows

    Can I do anything from here?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you wanted to use the Recovery Console, you would choose the C:\Windows selection since that is where you have Windows installed. However there is no sense in doing this since too many system files are infected anyway and we don't really know all of them and also you do not have a CD to even copy files from anyway.

    You need to work with Someone over in the Software Forum who may be able to walk you thru reinstalling your PC from your HP Recovery Partition or from the Recovery CD/DVDs you should have made when you first setup your HP PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds