Still have malware after running instructions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lorn, May 13, 2008.

  1. Lorn

    Lorn Private E-2

    I have run the Run and Read Me First instructions and included the logs.


    This problem started about two days ago. My boyfriend was using my computer and from what he told me, he clicked on an advertisement from badassbuddy.com and caused a flood of malware to come in my computer. When I got there, I disconnected the internet, deleted temp files, cookies, and the history and ran the two programs that I have on my computer, SpySweeper and Spyware Doctor (free version). The two reports brought back over 150 infections including multiple trojans, rootkits, and other assorted adware. I printed out the reports and put my computer into safemode and attempted to delete the files. However when I tried to delete the files, they reappeared the next time I opened the window. When I tried to delete the registry keys, I got a message saying there was an error deleting the key. When I tried to use Add/Remove programs, it would shut down the control panel and reopen the desktop folder.

    After that I came to this site for help. I ran the Run and Read Me First instructions. When I completed that, my computer seemed to run a lot better, no popups (which I had been getting even when disconnected from the internet), no slightly obscene advertisements plastered on my desktop, and it ran a lot faster. However, I reran SUPER Anti Spyware and it brought back that I still had 14 infections including a Trojan and Rootkit.

    I will include the last report in the next post.

    So, I want to know what I should do now?

    And thanks for helping me out in advance :)

    Lorn
     

    Attached Files:

  2. Lorn

    Lorn Private E-2

    I would also like to add that after running SAS for the first time, my computer would not boot properly and I had to return it to last good start up or whatever that is called.

    Also, now I was typing that post while letting SAS run, and when it restarted to fix the problems, it won't restart past the blue screen that says "HP Invent" in the middle and has the F-key options at the bottom, but it won't let me press any of the keys either.
     
  3. Lorn

    Lorn Private E-2

    Many apologies, it didn't let me attatch that last file. Here it is.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears as though you have no anti-virus program installed -> which may suggest the reason that your system was so infected.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 5"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5
    Viewpoint Manager (Remove Only)"
    Viewpoint Media Player

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Did you set this policy :
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  5. Lorn

    Lorn Private E-2

    And I'm not using that computer to read this, I have a laptop which I'm using right now.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Am I to understand that the computer that is infected will now not startup? If so, where did the log come from?
     
  7. Lorn

    Lorn Private E-2

    correct, I cannot get it to start past the blue screen and it will not let me press any keys.


    The logs I provided were all from the Run and Read Me First instructions, I did not give a log from the second time I ran SAS.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So pressing the actual f8 key does nothing?

    You may have to do a repair install as the malware may have infected some system files and rendered the machine unbootable.....do you have your xp cd?
     
  9. Lorn

    Lorn Private E-2

    My computer came with XP already installed on it, and I do not think it came with a CD. I am going to look through my stuff to make sure.


    And yes, pressing f8 does nothing, nor does pressing esc or f10 which are the instructions at the bottom of the blue screen: f8-safe mode, esc-boot options, f10-system recovery. I tried restarting it and pressing f8 while it was starting, but this did not work either.



    does doing a repair install mean I will lose everything on my comptuer? =\
     
    Last edited: May 13, 2008
  10. Lorn

    Lorn Private E-2

    no, I do not have an XP cd
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Doing a repair install will not make you lose anything....do you have your product key on the back of the computer...if you do, then you could borrow someones xp cd (as long as it is the same version as what you have - pro/home, etc) and do the repair with that. :(
     
  12. Lorn

    Lorn Private E-2

    I will see what I can do, I think my brother has the same version on his. I will try and post back later tonight about what happens.

    If I can get the CD, do I just put it into the computer and let it start, or do I have to press a certain key or something to make it run the CD?
     
  13. Lorn

    Lorn Private E-2

    Alright! I got my desktop (the broken comp) to start working again without reinstalling windows. I had to pull it out of my desk space to get the serial number off the back, but to do that I had to unplug it. I decided to check to see if any of the cards in the computer had come loose (this has happened to me before and caused a computer to have similar startup problems) After plugging it back in and restarting it, it started right up.

    I have attatched the second log from after running the Run and Read Me First instructions that I was originally going to attatch before I had the whole start up problems.

    Would you still like me to continue with the instructions in your post, or do something different?
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the fix in my previous post....and then attach the two logs asked for.....;)
     
  15. Lorn

    Lorn Private E-2

    okay,

    step 1: Completed deleting programs, no problems

    step 2: I do not know what this is, or what it means?

    step 3: Completed, no problems

    step 4: Completed, no problems

    step 5: Completed Avenger, got the file. When I restarted my computer though, I had a Rundll error come up.

    step 6: downloaded Java

    step 7: deleted all files except a file called ladHide5 which was from today

    step 8: Ran the MGtools


    Logs are attatched.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...just a few things left to do:

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    After doing the above..tell me how things are running. :)
     
  17. Lorn

    Lorn Private E-2

    Both were completed successfully, and it seems to be running fine...is there a way to make sure?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will gladly take another look at your logs if you have doubts:

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file. :)
     
  19. Lorn

    Lorn Private E-2

    I ran all the antispyware programs I had (seperately) and here's what I got back from them:

    SAS returned nothing,

    Spyware Doctor returned "13 threads and 85 infections", most of which are Registry values or keys and a couple are Browser cookies.

    SpySweeper I listed them, is there a way to get rid of them completely, I have them in Quarantine? I understand it doesn't hurt my computer to just have them sitting there, but I'd rather they not.
    These are the new programs it found
    -zeno search assisant
    -trojan-phisher-metafisher
    And these were already in Quarantine
    -2nd-though
    -toolbarcc
    -searchhere hijack
    -surfassistant
    -NoSpyName

    And of course, I've attatched the MGlogs.

    :) Thanks for your help
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually, none of the fix was successful.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  21. Lorn

    Lorn Private E-2

    I got this while running Avenger

    Error: Invalid registry sntax in command: "[HKEY_LOCAL_MACHINE\spftware\microsoft\currentVersion\Run]"
    Only registry keys under the HKEY_LOCAL_MACHINE hice are accessible to this program. Skipping Line (Registry key deletion mode)

    Then it asks to continue or abort. Which should I do?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue.....and if it still will not run....though it should, just without that line....

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    Files::
    C:\WINDOWS\system32\tcntqkdm.exe
    C:\DOCUME~1\Lorn\\LOCALS~1\Temp\2006326135530_mcinfo.exe
    C:\DOCUME~1\Lorn\\LOCALS~1\Temp\2006326135530_mcappins.exe
    
    Folders::
    C:\Documents and Settings\Lorn\Application Data\Deskbar_{F95ECDF3-794F-4030-A2CB-A01B7B504FD4}
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "{5f569256-8768-2c77-6996-d25c5839f603}"=-
    "Cleanup"=-
    "msci"=-
    "dbar_starter"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now attach all the logs I have asked for:
    Combo
    Avenger
    MGLogs.zip
     
  23. Lorn

    Lorn Private E-2

    okay, I got an error with everyline that had " " around anything while running Avenger. Otherwise everything ran okay.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds