Unable to run malware removal procedures

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dstern, Mar 14, 2010.

  1. dstern

    dstern Private E-2

    I am trying to heal a laptop running XP (SP3) with 2GB RAM. Before booting, I get an error message that CMOS settings are wrong/CMOS date/time not set. I'm instructed to press F1 to run setup, but it does not respond. F2 loads default values and continues the bootup. Though the machine will boot to Windows, I can not get anything to run, not even the start button.

    I am able to boot in safe mode, and began the "read & run me first" procedures. In safe mode the computer is so slow that it is almost disabled, but I was able to open and launch CCleaner. However, it has been running for some 4 hours now, and is still showing that it is 0% complete, though it has moved through a number of IE temp internet files.

    I have downloaded SuperAntiSpyware onto a flash drive using a functioning computer, but the sick laptop does not recognize the USB drive. It recognizes the flash drive as "new hardware," but not as drive with files.

    Any advice would be appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suspect that your error message about the CMOS not being set may mean your CMOS battery is dead or dying. You might want to try replacing that.

    I suggest that you try transferring the scanning tools to a cd and see if you can't then move them over while in safe mode.

    Let me know what you can do.
     
  3. dstern

    dstern Private E-2

    Thanks. The very first thing I did, before posting here, was to change the CMOS battery, but it didn't make a difference.

    Here's a summary of my status, all done in safe mode. I've given full details in hopes that there is something that will help you figure out what I should do:

    1. Downloaded all of the tools to CD and transferred to the sick laptop.
    2. Could not install SAS. It will not install under safe mode, as I experienced and as confirmed at
    http://www.superantispyware.com/supportfaqdisplay.html?faq=50. The computer will not run in normal mode.
    3. Mistakenly installed MB without renaming. Have tried to delete the program using Control Panel, but without success. It did install and created a shortcut on the desktop.
    3. Tried to reinstall MB renaming from MBAM to MB. Could not install MB. Error message said "unable to create a temporary file. Setup aborted. Error 23: Data error (cyclic redundancy check)."
    4. Tried to run MBAM. Failed. Error message" Malwarebytes' Anti-Malware has encountered a problem and needs to close. We are sorry..." The details indicate an "Error signature. EventType: InPageError P1: c000009c P2: 0000003"
    5. Followed instructions to install ComboFix. Double clicked on icon, but the process did not follow the one in the tutorial. It opened a very small window with a progress bar, which finished. Then the "open with" window opened, asking me what program I want to use to open a file named "nircmd.cfxxe" Unsure what to do, I chose combofix.exe as the program to use.

    5.b It again opened the very window mentioned above, and the sequence repeated. This time, however, I did get the "disclaimer of warranty" screen, clicked "yes," but then the program closed.

    5.c Ever persistent, I tried a third time, double-clicking on the ComboFix.exe icon. During the third installation, two blue screens appeared, one with a message "The process cannot access the file because it is being used by another process" and the second with the message "A subdirectory or file C:\Qoobox\LastRun already exists." When the third small ComboFix window/progress bar closed, a "date error" message appeared saying "Date Error: 2002-01-01. check your settings." At this point I abandoned ComboFix.

    6. Ran RootRepeal.exe. It opened, and after it initialized, it showed "C:\32788R22FWJFW\" but then froze and did not finish. I repeated it but with the same abortive result.

    7. Ran MGtools. Got Registry editor error: Cannot export c:\MGtools\tmpUnKey.txt: Error opening the file. There may be a disk or file system error " and another "Cannot experot C:\MGTools\temp\xlmsysccsa.txt"
    Logs were saved as expected as MGlogs.zip but despite repeated efforts I've not been able to copy them to a CD or USB so I can send them from a working computer. I will continue to try and will attach if I am successful. An online search suggests that what I've found in step 6 above may be virut. I'll await your advice.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do as much of this as you can.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the avplog.txt file that is will hopefully be created on your Desktop as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post)

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.
    * If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    If you already have them installed, be sure to update Malwarebytes and SUPERAntiSpyware before the scan!

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: SUPERAntiSpyware - running & getting a log

    Now run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans

    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  5. dstern

    dstern Private E-2

    I'm stymied. I've succeeded in running several of the processes (details follow), but cannot get the logs from the sick computer onto something so I can move them to my healthy computer to attach them here. I can put the files onto a CD, but cannot succeed in writing them to the CD. The computer does not recognize a flash drive (it sees it as new hardware, starts the new hardware wizard, but there is no software driver for the hardware...)

    Here, for what it's worth are the details of what worked and what didn't.

    1. AVPFind.bat ran and saved its log to the desktop. I don't believe it finished, however, as the avplog.txt files doesn't contain any info beyond the OS and a message "Finding copies of eventlog.dll... Please be patient."
    2. Rkill.exe ran successfully.
    3. exeHelper ran successfully.
    4. MB failed.
    5. SAS failed.
    6. MGtools ran and saved its log in the C: drive, but again I can't attach it.

    Your advice appreciated.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you boot to safe mode with networking? Can you access your email account? Can you attach the C:\MGLogs.zip to an email? If you can, try emailing it to me timw at majorgeeks.com.
     
  7. dstern

    dstern Private E-2

    Tim,

    I can boot to safe mode with networking, but cannot get get a browser to open (tried both Firefox and IE) and so cannot get to my email. Is there any thing else I can try?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, then try doing this:

    Download Dr.Web CureIt and save it to your desktop.

    • Doubleclick the cureit-beta.exe file and allow to run
    • If it prompts you about getting any updates, get the update and then rerun the cureit-beta.exe installation.
    • When it finishes you will have a green window with a Start and and Update selection. Click Start
    • the Express Scan of your PC window will come up. Click OK to scan main memory to detect infected process in memory.
    • If anything is found in memory, click the yes button when it asks you if you want to cure it. This is only a short scan.
    • You may see a popup window to Buy or get a discount on the program. Just click the X at the top right to close this popup. The scan will continue.
    • Once the short scan is completed, click the Custom Scan radio button. Then Select each of your hard disk drives (that is if you have more than one). A red dot shows which drives have been chosen.
    • Click the green arrow at the right under the Dr.Web logo, and the scan will start.
    • Click 'Yes to all' if it finds any problems and asks if you want to cure or move the file.
    • When the scan has finished, look if you can click next icon next to the files found:
      [​IMG]
    • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
      [​IMG]
    • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
    • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
    • Save the report to your desktop. The report will be called DrWeb.csv
    • Close Dr.Web Cureit.
    • Reboot your computer!! This is necessary because there could be files in use that will be moved or deleted during reboot.
    • After reboot, rename the DrWeb.csv file to DrWeb.txt so that it can be uploaded here and then attach the log from Dr.Web to your next reply


    Let me know how this goes.If you have a true virut infection, often the only thing to do is a reformat. :(
     
  9. dstern

    dstern Private E-2

    I have not yet run the Dr Web Cureit, but have retrieved the MG log, AVPFinder log, and Exehelper log. They are attached.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AVP didn't run completely nor did MGTools.exe. The only log in that zip of use was your runkeys log. It didn't show any malware or other issues.

    Try Dr. Web.
     
  11. dstern

    dstern Private E-2

    Thanks for all your help, but Dr. Web wouldn't run either. I decided to proceed with a reformat and clean install of Windows. The extremely slow response continues. After nearly 12 hours overnight, the reformat is only 12% done. (It does not appear to have stalled--it has made some progress since I checked it first thing this morning.) Can this be due to malware?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No. More than likely, you are having problems with your hard drive. That can act like malware symptoms. Let me know if you can get it to reinstall windows.
     
  13. dstern

    dstern Private E-2

    Thanks for all your help. The hard drive failed, and I've now replaced it.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds