Virus Unable to Run Malware Removal Tools

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TonyV1692, Oct 5, 2011.

  1. TonyV1692

    TonyV1692 Private E-2

    Hello

    I've followed all instructions in "Read & Run Me First". I have the following results downloading and attempting to run the suggested tools for Windows XP operating system:

    SUPERAntiSpyware: downloaded but unable to run. No log created. While attempting to run, received the following message: Windows cannot access the specified device, path or files. You many not have appropriate permission to access item. (note - I am setup as administrator).

    Malwarebytes Anti-Malware: downloaded bu unable to run. No log created. While attempting to run, received the following message: Windows cannot access the specified device, path or files. You many not have appropriate permission to access item. (note - I am setup as administrator).

    combofix.exe: downloaded and ran, but did not complete. No log created. When attempting to run, I got a far as the blue screen C:\ ComboFix is preparing to run. I sat in that condition for 2.5 hours. I finally closed out.

    RootRepeal: downloaded and ran. It was basically a flash on the screen. Log generated but empty. See attached.

    MGTools: downloaded and ran. Log attached.

    My problem started 1 week ago when my Antivirus Program (F-Secure) stopped auto-updating the Antivirus and Malware components. I uninstalled and attempted to re-install (per F-secure's support) and was unable to install completely. I suspect the virus is preventing the install. I am currently do NOT have any Antivirus program running on my computer.

    Thank you in advance for your help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Java(TM) 6 Update 26 <--- uninstall outdated Java.



    Download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r




    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes). (How to attach items to your post)
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\WINDOWS\628322403
    C:\Documents and Settings\Tony\Application Data\ldr.ini
    C:\Documents and Settings\Tony\Application Data\A88ggTZqjYCwIVz
    C:\Documents and Settings\Tony\Application Data\DRZZ9hhYXwj
    
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: [​IMG]
    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the [​IMG] button.
    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message as well as any other requested logs.



    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run



    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Will SUPERantispyware, Malware Bytes and Combofix now run for you?


    Reboot
    your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. TonyV1692

    TonyV1692 Private E-2

    Thank you Kestrel13. I've followed all of your instructions. Attached to this message will be the first 4 logs. I will post another message with 4 remaining logs.

    A couple of notes:

    1. The junction tool ran but it was very fast and the log looks empty.

    2. OTL only produced the OTL.txt log. It did NOT create the Extras.txt log.

    3. SUPER antispyware .. could only run the online version - still cannot run the download version. However, MalwareBytes and ComboFix were now able to run.

    4. I have an AVGuard Online icon on my desk top. I do not see the program when I go to add/remove programs. Also, MalwareBytes appears to have found an AVGuard malyware and removed it. Not sure why the desktop icon is still there.
     

    Attached Files:

  4. TonyV1692

    TonyV1692 Private E-2

    continuing my post with remaining log attachments.

    Please let me know what else I need to do.

    Many, many thanks!!!!!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    Code:
    :otl
    @Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
    @Alternate Data Stream - 784 bytes -> C:\WINDOWS\628322403:2626653402.exe
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant_bak = http://www.couldnotfind.com/search_page.html?&account_id=1000940
    O4 - HKLM..\Run: [uS22ibbF38234A] C:\WINDOWS\SYSTEM32\WCCwkkIVrzONxAu.exe ()
    
    :files
    C:\WINDOWS\628322403
    C:\WINDOWS\SYSTEM32\WCCwkkIVrzONxAu.exe
    C:\Documents and Settings\Tony\Application Data\HgZhYCwkUlNx0c
    C:\Documents and Settings\Tony\Application Data\bPNyxA1uv2b4Hs
    C:\Documents and Settings\Tony\Application Data\DeIBrzPNx1v2b4
    C:\Documents and Settings\Tony\Application Data\IhhYtPyc1Dn4Q6W
    C:\Documents and Settings\Tony\Application Data\q0ycAivD3n4m
    C:\Documents and Settings\Tony\Application Data\QF3pnG5aQdKfZhX
    C:\Documents and Settings\Tony\Application Data\QF3pmG5sQ6EgZhX
    C:\Documents and Settings\Tony\Application Data\fkUVelOBt0c1b3n
    C:\Documents and Settings\Tony\Application Data\RZqYXwkUVlBx0c1
    C:\Documents and Settings\Tony\Application Data\hNyxA1uS2b4Gs7E
    C:\Documents and Settings\Tony\Start Menu\Programs\AV Guard Online
    C:\Documents and Settings\Tony\Application Data\rdEK8gRZ9YwUeOt
    C:\Documents and Settings\Tony\Application Data\nvS2obF3pGsJ
    C:\WINDOWS\System32\JQQJJ6ddE
    C:\dAAA0uvvS2bF3m5
    C:\dsssWJJ7fELgTqj
    C:\Documents and Settings\Tony\Desktop\AV Guard Online.lnk
    C:\Documents and Settings\Tony\Application Data\ldr.ini
    C:\WINDOWS\System32\WCCwkkIVrzONxAu.exe
    
    :reg
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uS22ibbF38234A"=-
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Have you an option to cure or delete this rather than quarantine, using TDSSKiller? Run it again and see. Or does it not show now?


    Please run OTL again now like you did in post number 2 without imputting a script. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. TonyV1692

    TonyV1692 Private E-2

    Thank you again Kestrel13. I've followed your instructions and attached please find the logs.

    Things seem to be running better. I do not see the AVGuard Icon on the desktop any more - this is good.

    When running TDSSKiller .. no threats found so no option to cure or delete.

    I did a quick look on C:\WINDOWS for the .exe file you noted, I could not find it.

    many thanks for your continued help. Let me know what else I should do.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything looks great. Ready for final steps? :)
     
  8. TonyV1692

    TonyV1692 Private E-2

    Yes, I am ready for final step. Many, Many thanks!!!!!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds