Removal of malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by LeoB, Jun 19, 2013.

  1. LeoB

    LeoB Private E-2

    Hello everybody,
    I am new to the forum and I am happy it exists. I found the forum accidantally searching for help with the FBI Money Pack virus. I am reading on this forum to use safe mode with networking, I can go to safe mode with or without networking.However, as soon as I log in the laptop shuts down. I have tried using repair computer function using the available downloads on a USB stick........It does not seem to work, Can somebody please help be to get access back to safe modes without it shutting the computer down. I think that all the explanations and descriptions here are easy to follow and I could go there and look for help once I have access to safe mode again.

    Thank you very much in advance for your help,

    I truly apopreciate your efforts to help me.

    Leo
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. LeoB

    LeoB Private E-2

    Here is the txt.file you were asking for. Thyank you for helping
     

    Attached Files:

  4. LeoB

    LeoB Private E-2

    I am sorry, I attached I file that I downloaded from the forum. Here is the frst.txt file now
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt to your flash drive.

    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Running MGTools.
     

    Attached Files:

  6. LeoB

    LeoB Private E-2

    Thank you for your help thus far. I have attached the requested file to this e-mail.

    Thanks
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running???
     
  8. LeoB

    LeoB Private E-2

    I still can not go into safe mode. The virus is still there ....:-(
     
  9. LeoB

    LeoB Private E-2

    I can only copy the MGtools from my USB stick to my C:\ drive and run it from there. A econd DOS window pops up and runs something very fast which I hope is MGtools. It is a very short run. I am not able to go into Windows and disable Norton Internet security.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. LeoB

    LeoB Private E-2

    Thank you
     
  12. LeoB

    LeoB Private E-2

    Here is what I was able to do in the Dos level.
    I have attached the files.

    For Malwarebyte I received the message: " The program can't start because MSVBVM60.DLL is missing" ( As I said I ran it in DOS level

    For RogueKiller I can not find the txt file.
    Tdsskiller found nothing,,,,,???

    Thanks
     

    Attached Files:

  13. LeoB

    LeoB Private E-2

    Here is the Rkreport file that I did not find yesterday.
     

    Attached Files:

  14. LeoB

    LeoB Private E-2

    here is another hitmanPro file that seems different from yesterday's
     

    Attached Files:

  15. LeoB

    LeoB Private E-2

    Some good news today. I have scanned all partitions again with the recommended tools and now suddenly windows is string up in normal mode. The monitor is dim and hard to see but I can manage for now. .......
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry Entries : 4 ¤¤¤
    [EXT RUN][SUSP PATH] HKCU\Leo_ON_C:\[...]\Run : qcgce2mrvjq91kk1e7pnbb19m52fx (C:\Users\Leo\AppData\Local\Temp\ACh0XXd.exe [-]) -> FOUND
    [EXT RUN][SUSP PATH] HKCU\Leo_ON_C:\[...]\Run : qcgce2mrvjq91kk1e7pnbb19m52fx (C:\Users\Leo\AppData\Local\Temp\ACh0XXd.exe [-]) -> FOUND
    
    
    ¤¤¤ Startup Entries : 2 ¤¤¤
    [Leo][Rans.Gendarm] regmonstd.lnk : C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\regmonstd.lnk @X:\Windows\System32\rundll32.exe C:\PROGRA~2\9riofo.dat,XFG00 [-][7][x] -> FOUND
    [Leo][Rans.Gendarm] regmonstd.lnk : C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\regmonstd.lnk @X:\Windows\System32\rundll32.exe C:\PROGRA~2\9riofo.dat,XFG00 [-][7][x] -> FOUND
    Download OTL to your desktop.

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.



    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now reboot and rescan with RogueKiller and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. LeoB

    LeoB Private E-2

    For some reason JRT.exe pops up a DOS window quickly and disappears right then. Is this normal? I am not sure if I deleted the recommended lines in RogueKiller correctly. The file for OTL is attached.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the log from running RogueKiller.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  19. LeoB

    LeoB Private E-2

    Things are running well, very well actually :) Many thanks for your great help. I have attached the debug.log file and the Mglogs.zip file. May I have your opinion on which software should be installed on my computer to prevent this from happening again?
    Your expertise is greatly appreciated
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MG log was not complete. You will have to run it again. Plus you didn't attach a log from running RogueKiller again.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Users\Leo\AppData\Local\Temp\ACh0XXd.exe

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip
     
  21. LeoB

    LeoB Private E-2

    C:\Users\Leo\AppData\Local\Temp\ACh0XXd.exe
    This file I can not find. I assume it is not available or existing on this laptop.
    The fixme.reg file confirmed it had merged successfully.
    I have attached the RK txt files as you asked for.

    Thank you for helping, but I am unable to run MGtools since I am booting back up into normal windows. I have tried in Safe Mode and SafeMode with Networking as well as on dos level................It just does not run to create the file you are asking me to send
     

    Attached Files:

  22. LeoB

    LeoB Private E-2

    sorry
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and make sure all your protection software is disabled. Have it fix these items:

    Code:
    ¤¤¤ Startup Entries : 2 ¤¤¤
    [Leo][Rans.Gendarm] regmonstd.lnk : C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\regmonstd.lnk @X:\Windows\System32\rundll32.exe C:\PROGRA~2\9riofo.dat,XFG00 [-][7][x] -> FOUND
    [Leo][Rans.Gendarm] regmonstd.lnk : C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\regmonstd.lnk @X:\Windows\System32\rundll32.exe C:\PROGRA~2\9riofo.dat,XFG00 [-][7][x] -> FOUND
    Reboot and rescan with RogueKiller and attach the log.

    Then Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds