Unsure if it's malware or something else..

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MichaelEmmerik, Jun 13, 2011.

  1. MichaelEmmerik

    MichaelEmmerik Private E-2

    Dear Chaslang,

    I have been following the Read and Run me first guide, but I am having trouble running the MGtools.. It did create a folder, with a lot of files in it. But the CMD prompt only showed up for a split second then vanished. Also I can not find any MGtools.zip. Not in the folder and not in C:\. There is a 'zip.exe' though.. Also the RootRepeal doesn't work for me even though I am supposed to have a 32 bit system.. RootRepeal did create a crash report which I have attached below. It strangly shows that I am supposed to run Windows Vista Sp1, but I got my laptop with Windows 7 Ultimate..

    Anyway, I am attaching the logs as I could find them below.

    My history:
    For a LONG time now I have been unable to make backups of my system, but I am unsure if this is a part of the problem.
    When a big soccer match was playing (Ajax Twente) I was searching for online broadcasts to watch the match, but I could only find something through 'sopcast'. After finally finding a download link for the program I downloaded it and I wanted to watch the match quick so I just did a regular instal without actually checking for 3rd party programs involved in the 'regular' instal. After installation I noticed that the installation also installed QuickPotato or something like that. And something else which were (so I believe) popup 3rd party programs. I imediatly tried to quarantine them as my Virusscanner (Microsoft Security Essentials) reported them as malware. Since then I've been having problems. My system began to slow down while starting up and I sometimes still get a popup message from my virusscanner that some malware was found but it was not able to quarantine them or remove them because the file was not found. Now 2 days ago I tried to follow a tutorial which a dutch computer magazine made to make your system faster by doing something with the DDR ram. At that point I thought it had worked and everything was as fast as before my problems started, but the next day my laptop started up MUCH MUCH slower.. I am actually not sure how to reverse my actions. It was something with PEA activation and creating a virtual RAM of 3g then downloading something about a kernel x86 or something. I am regretting every step I have made and I hope that you can help me in someway.

    I am aware of the fact that this is my own fault I should have been paying more attention, but I wasn't. If you are not willing to help me because this was my own fault then I understand and I will most probally have to find a way to reset my whole system. But because it was a laptop without a windows cd I think I might be screwed. The store said that it wouldn't be a problem, because I could just use system restore or something, but what if I want a clean installation..

    Anyway, thanks for your time!

    Yours sincerely M. Emmerik

    Edit: Oh I almost forgot! For a LONG while now I have been having trouble deleting certain entries in my software removal list in configuration centre. I have deleted: Age of Empires and Rhabot (not sure what Rhabot it hence why I deleted it) but they keep showing up in the list. When I try to delete them I get some error like the files can't be found or something. Is there some way you could help me with that aswell? Thanks in advance
     

    Attached Files:

    Last edited: Jun 13, 2011
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Got a C:\MGlogs.zip now?
     
  3. MichaelEmmerik

    MichaelEmmerik Private E-2

    I have followed your steps but the only output I get is:

    cd \MGtools <-- this indeed changed my folder to C:\MGtools
    ShowNew <-- ShowNew can not be recognised as command
    GetRunKey <-- same as above

    Hmm.. I just went to check on the MGtools program and what do I see.. Nothing.. It's vanished! Also some programs on my desktop that I used for scans are gone.. I uninstalled my virusscanner before I scanned because I couldn't disable it. Now after the scans I've put my User account control on and I downloaded the virusscanner again. Then updated and scanned my system. Nothing was found, all was clean but after a system reboot (because of the UAC toggle) the programs are gone?.. Should I attempt to download them again and try to run MGtools again?
     
    Last edited by a moderator: Jun 13, 2011
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, try to run MGTools again. Rename it so it is C:\123.com failing that you will have to run OTL

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. MichaelEmmerik

    MichaelEmmerik Private E-2

    Luckily it did not fail this time. The only thing different was that I right clicked and ran as administrator. This allowed it to run fully and create a zip. I have attached it to this post.
     

    Attached Files:

    Last edited by a moderator: Jun 13, 2011
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If the program was installed using Windows Installer, then you may use Windows Installer Cleanup Utility to remove the installer information for that program, and also the corresponding entry in Add or Remove programs.

    Add/Remove program Cleaner is a free and useful program that allows you to clean up the Add/Remove programs list in the control panel. It should only be used to remove entries that are broken and cannot be removed by running the uninstall program.

    NeoBux Toolbar <--- Is this something you intentionally installed? Do you use it? If not uninstall it.
    ShopperReports <--- Uninstall this.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?NL (file missing)
    O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=home (file missing)

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\users\Michael\AppData\Local\{EE628B0E-DD27-4BE9-BB03-14FF1E504BC6}
    c:\users\Michael\AppData\Local\{C882B87D-82FE-4DF5-858C-C45DBE4A866C}
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "DisableCAD"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. MichaelEmmerik

    MichaelEmmerik Private E-2

    I tried to download it but I couldn't run it.. I got an error.

    I wasn't able to download this file, because there was nothing on that page?

    Neobux Toolbar was intentionally installed so yes I use it=]
    ShopperReports is uninstalled. (well for the 2nd time now already (check below))

    Did that

    Somehow my system deleted MGtools again, so I downloaded it again and ran another scan so I could get the files. Then I ran it and all went fine. (Although I was in W7 I still had to run as administrator to have it work correctly, no problem there though)

    I had to also download ComboFix again. I made the txt file and dragged it onto ComboFix. The ComboFix scan started and at one point (not sure which, since I wasn't looking at my screen), the computer rebooted and I got back to a screen saying: "Loading windows files" and windows went into system repair. And I believe it loaded a system restore point.. So now I am back to where I started, no more MGtools and ComboFix present. Also I had to uninstall ShopperReports again. And I couldn't progress with this stage. Should I attempt again from the start? Also whenever I start my laptop I have 2 options to start:

    • "Windows 7 ohne kernel sphere"
      "Windows 7"

    I would like to get rid of that Windows 7 ohne kernel sphere, but I have no idea how to delete it.

    As stated above i couldn't complete this part.
     
  8. MichaelEmmerik

    MichaelEmmerik Private E-2

    I just wrote a big response post about how my computer somehow deleted the MGtools and ComboFix again and I had to instal them again. Than ran the tests in orde to be able to complete the stages above. But when I was in ComboFix my computer rebooted and had to repair system files and loaded a restore point. Thus leaving me at the beginning again. Without MGtools and ComboFix (and I uninstalled ShopperReports again.

    Neobux Toolbar is indeed something I use.

    Also whenever I start my computer I have 2 options:
    Windows 7 ohne kernel sphere (which I would like to delete)
    Windows 7

    I always use windows 7.

    Anyway, I could not progress with the steps above, should I retry?
     
    Last edited by a moderator: Jun 14, 2011
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, this is the cause of your problems. You will need to post in the software forum regarding this.

    Delete these folders:

    c:\users\Michael\AppData\Local\{EE628B0E-DD27-4BE9-BB03-14FF1E504BC6}
    c:\users\Michael\AppData\Local\{C882B87D-82FE-4DF5-858C-C45DBE4A866C}

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds