Can't run any security scan.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by igrushka7, Apr 6, 2009.

  1. igrushka7

    igrushka7 Private E-2

    Hi All.
    Just joined the forum, which makes me a newby, which in turn proves the proverb about never late to learn. I am retired and consider my computer literacy about 4/10.
    And yes, I do have a problem!
    The last couple of weeks, about the time when I have downloaded a couple of Opera DVDs using uTorrent (I still don't know if uTorrent is a bad guy, and can it be safely used at all), I can't run any scans (SpyBot S&D, SuperAntyspyware, Malwarebits). The WINDOWS autoupdate does not work and I can't Download Updates manually.
    The PC is slow on boot up. Sometimes it freezes, only the mouse pointer is alive-have to switch off power.

    I have run the Windows XP Cleaning Procedure as suggested.
    Here are the trouble:

    1. Couldn't reinstall SuperAntispyware, error message attached
    (SAS error.jpg )

    2.While checking SET PREVENTION POLICY , got another error (SetPrevent.Policy.jpg attahced)

    3. MBAM- reinstalled But doesn't run neither from the shortcut icon nor .exe file directly.

    4. Could not run COMBOFix. (ComboFix.jpg )

    Looks like a resident bug has thrown the proverbial spanner in all kinds of security on my PC.

    5. MGtools installed and ran OK, MGlogs.zip attached. The only one !!!

    6. Ad-Avare installed OK, but couldn't update.

    Any help will be greatly appreciated.

    Regards.
    Boris.

    I use: WINDOWS XP Home SP2, COMODO FireWall, NOD32 for AV. Also SpyBot S&D + TeaTimer, SuperAntispyware, WINDOWS Defender (FireWall off)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    The infection you have may infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. After doing this, continue with on with the below.


    Download HostsXpert and then follow the below steps.

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by double clicking on it.
    * Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    * Click Restore Microsoft's Hosts File and then click OK.
    * Click the X to exit the program

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  3. igrushka7

    igrushka7 Private E-2

    Hi TimW,
    I've done everything you suggested.
    Things started to look up already.
    Thank you very, very much.
    Here is MGlogs.zip

    Now concerning the virus:
    1. What was it?
    2. Could I pick it up through uTorrent?
    3. Is it safe to use uTorrent?

    Best regards,
    Boris
     

    Attached Files:

  4. igrushka7

    igrushka7 Private E-2

    Hi again TimW,

    After sending the last post I managed to update Windows, which I could not do before removing the "017's".
    Unfortunately, still can't run SuperAntispyware, Spybot S&D, MalwareBites.
    Am I jumping the gun?

    I attach the new MGlogs after updating windows.

    Regards,
    Boris
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You at one time had Norton? But I am not seeing any anti-virus software installed!!

    You need to install an AV program!

    What happens when you try to run any of the other scans? Have you tried renaming them? Have you tried running them in safe mode? I see that you had been able to run both SAS and MBAM.
     
  6. igrushka7

    igrushka7 Private E-2

    Hi Tim,
    Following your advise, I managed to run both SpyBot S&D & MBAM in Safe Mode with the files renamed. (I attach what I found)
    After that I was able to reinstall SAS, and now I can run SAS, MBAM, SpyBot S&D from normal boot as usual.

    Concerning Norton. I had Norton years ago, Now I am running NOD32 for AV.

    I am very greatfull to you for helping me out. Thanks a lot.

    One thing though, ComboFix runs, but doesn't create a log and comes up with an error (Attached). Tryed to SEARCH, nothing comes up.

    Thanks again,
    Boris.
    Windows XPHomeEd.SP3, COMODO Firewall, NOD32 - AV
     
  7. igrushka7

    igrushka7 Private E-2

    Oops...

    Forgot the Attachments!

    Try Again.

    Hi Tim,
    Following your advise, I managed to run both SpyBot S&D & MBAM in Safe Mode with the files renamed. (I attach what I found)
    After that I was able to reinstall SAS, and now I can run SAS, MBAM, SpyBot S&D from normal boot as usual.

    Concerning Norton. I had Norton years ago, Now I am running NOD32 for AV.

    I am very greatfull to you for helping me out. Thanks a lot.

    One thing though, ComboFix runs, but doesn't create a log and comes up with an error (Attached). Tryed to SEARCH, nothing comes up.

    Thanks again,

    Boris.

    Windows XPHomeEd.SP3, COMODO Firewall, NOD32 - AV
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good...that shows a possible problem.

    The infection you have is known to infect router hardware. If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup. After doing this, continue with on with the below.


    Download HostsXpert and then follow the below steps.

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by double clicking on it.
    * Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    * Click Restore Microsoft's Hosts File and then click OK.
    * Click the X to exit the program

    Then see if you can run any of the other scans. Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  9. igrushka7

    igrushka7 Private E-2

    Hi Tim,
    I do not have a router, just the old Motorolla SB5100 between the Cable & my PC. I can run now SAS scans, MBAM scan & Spybot S&D.
    But SAS found TROJAN. BHO and removed it twice.
    Now, I have done everything according to your instruction.
    I also tried to run GMER, but it doesn't run to the end. I attach the file which is what I could get.
    I tried to run RootKitReveal. Again it keeps crashing, hence the snapshot which I am attaching.

    Thanks,
    Boris
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you remove ComboFix from your desktop? Please download it to your desktop and see if it will run ( if ness., rename or try in safe mode).

    In the mean time, download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and the combo log if you can produce it.
     
  11. igrushka7

    igrushka7 Private E-2

    Hi Tim.
    Done what you suggested.
    1. ComboFix does not run (even renamed) in Normal windows, but I managed
    to run it in Safe Mode (see attachment).
    The rest has been done without any drama.
    Thanks,
    Boris
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you tell me what these are:
    c:\program files\tow.bat
    c:\program files\team.bat
    c:\program files\lib.bat
    c:\program files\round.bat
    c:\program files\objective.bat
    c:\program files\ffa.bat

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now use windows explorer to find and delete:
    c:\huadio.tmp
    c:\windows\system32\babcbbab_r.dll
    c:\windows\system32\cfddbccc8_z.dll

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip fil and see if you can run Combo in normal mode.
     
  13. igrushka7

    igrushka7 Private E-2

    Hi Tim.
    I did: 1. The six ".bat" files-I don't know what they are, just in case scanned them with Spybot S&D, Malwarebytes, NOD32-nothing found. Could be some leftovers???
    2. Windows Messenger - uninstalled.
    3. Added fixME.reg to the registry. Confirmed.
    4. Ran fix.bat.
    5. Could not locate c:\huadio.tmp, search found nothing. "babcbbab_r.dll & cfddbccc8_z.dll" have been located and removed.
    6. Still can't run ComboFix in normal mode. "Error" attached.
    MGlogs.zip is attached.

    Thank you very much.
    Regards,
    Boris.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....your logs are clean. If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  15. igrushka7

    igrushka7 Private E-2

    Hi Tim,
    have been out of town for a few days.
    The PC runs OK, but I would like to run some scans before we close this thread.
    Thanks a lot, you have been a great help.
    I'll let you know about the scans I will run.
    Best regards,
    Boris.
     
  16. igrushka7

    igrushka7 Private E-2

    Hi Tim again,
    It looks like my PC finely started to behave.
    Thanks a great lot. :-D
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds