Cleaning an infected Time PC desktop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by 3spirit, Aug 9, 2008.

  1. 3spirit

    3spirit Private E-2

    I have completed the Major attitude removal guide. I have attached the 2 reports for someone to provide feedback on what is wrong with my desktop PC. My infection occurred when I upgraded from the internet security suite Kaspersky 6 to version 7 which is still active now. Please can a qualified person interprete the reports that I have attached?


    Cheers!
     

    Attached Files:

  2. 3spirit

    3spirit Private E-2

    Attached is another log file that was too big to attach in my original post.

    The desktop PC still appears to be infected because the machine still operates slowly and prompts PID error messages from Kaspersky 7. Any help I can get is appreciated!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Next time please install and use the proper versions of the tools and update them as requested. You are way out of date with both Malwarebytes and SUPERAntiSpyware. The current versions may have removed more of your malware.

    Also you are way out of date with MGtools too.

    Actually it is my guide. Major Attitude just started the original thread years ago. But I have maintained it ever since.;)

    It was not too big. As stated in the cleaning procedure, you can only attach 3 logs to a single message.

    While you still have a load of malware to be removed. Some of your issues with running slowly may be due to what you are running and not having uninstalled some applications (namely Norton/Symantec) properly. It is still wasting resources on your PC. We will resolve this below. Please complete all instructions in the order given.

    First I suggest that you uninstall A-squared to avoid wasting resources on it and it is too prone to false positives.

    Now run the below, reboot and then run it again to be sure all of Norton was cleaned up.

    Norton Removal Tool (SymNRT)


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now download the proper version of MGtools from here: MGtools.exe Save it to C:\MGtools.exe overwriting your old version. Then run it and allow it to finish running.

    Then attach the below logs:
     
  4. 3spirit

    3spirit Private E-2

    A big thanks for setting the record straight on who has provided the current anti malware guide. I have spent the last month trying to apply your advice but have 2 problems. 1st the combo fix application freezes (over 7hrs) at step 8 of its cleaning processes when I follow your advice below. The various CF logs created are attached below but I had to reboot the desktop by ctrl alt del each time.
    The 2nd problem relates to the java download not loading properly and the fixme. reg only being successful after running the current version of Malware Bytes.

    I hope this all makes sense and that based on the above facts you can still help me. By the way, I am still getting Kaspersky process warnings and Opera is the only web browser that will load and work so I appreciate any further advice you have.:major
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have told us of your problems sooner. I would have given you another method to fix it.


    Those are not ComboFix logs. Those are copies of the CFScript.txt file I had you make.

    Before I workup a new fix, please uninstall the old version of SUPERAntiSpyware and download and install the below one. Get any updates too. Then run a scan and attach the new log:

    SUPERAntiSpyware

    Then download and run the new version of MGtools.exe Attach the new C:\MGlogs.zip

    After this I will give you a new fix to remove any remaining problems. We will avoid ComboFix since you are having a problem with it.
     
  6. 3spirit

    3spirit Private E-2

    After uninstalling SAS with Revo uninstaller I had the error messages shown in the 1st 2 attachments below and had to reboot. Every time I downloaded the new SAS software my PC terminated my internet access and it refused to run any programs so that I had to reboot.

    This is the error message that I now get every time I press enter or double click an application "2008-08-30 09:19 C:\WINDOWS\system32\wuauclt.exe Attempt to load a new or modified module C:\WINDOWS\system32\wucltui.dll into process."

    The error log you requested is also attached ( well it is the only text file created today). Please let me know your thoughts on all this and thanks again.
     

    Attached Files:

  7. 3spirit

    3spirit Private E-2

    I have just managed to save the MGtools.exe to my root c drive. The application has been re -run and the correct logfiles now attached. This replaces the previous MGtools logfile that I sent.:major
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have just used Add/Remove Program or SAS's own uninstall. According to your logs, SAS is still installed and running.


    Not sure what has happen now. Let's continue with malware removal and see what happens. You may have to work problems with your Windows Operating System in the Software Forum if they continue.


    I did not request any error log and this is not an error log and you don't need to attach it anyway. It is already in MGlogs.zip. You also should not be attaching newfiles.txt logs or any other logs from the C:\MGtools folder. They are already in the MGlogs.zip file and that is all you have to attach when we request it.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 30, 2008
  9. 3spirit

    3spirit Private E-2

    Thanks again for your advice. The attachments you requested are (I hope) added below.

    The KIS 7 error message I now receive every 30 secs when I type is:
    "2008-08-31 11:33 C:\WINDOWS\system32\userinit.exe Attempt to run process as a child of \\?\C:\WINDOWS\system32\winlogon.exe (PID: 972)."

    After using Avenger and rebooting, I got the following message so I clicked on ignore and started sending this message to you :

    "16 bit MS-DOS Subsystem
    drive:\program path
    SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers. VDD. Virtual Device Driver format in the registry is invalid. Choose 'Close' to terminate the application. "

    BTW
    SAS is still active as per your last advice and I interpreted your last request as me needing to send a log and a Zip file:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    userinit.exe and winlogon.exe are both valid Windows processes so I'm not sure what this is in reference to. Perhaps you just need to tell Kaspersky to allow it and to always allow it. This message and the one you mentioned back in post # 7 are not malware problems. They are valid Windows processes.

    This error message is same as one mention in error type 2 of Using MGtools You can use the fixed given there to correct this problem within your operating system.

    Delete the below folders that are named like they are files:
    C:\WINDOWS\system32\wiatwain.dll
    C:\WINDOWS\system32\replmap.dll
    C:\WINDOWS\system32\cz.dll
    C:\WINDOWS\system32\drct16.dll
    C:\WINDOWS\system32\hz.dll
    C:\WINDOWS\system32\vdmt16.sys
    C:\WINDOWS\system32\winlow.sys
    C:\WINDOWS\system32\wz.dll


    Other than the above folders, your logs are clean. Are you having any malware problems?
     
  11. 3spirit

    3spirit Private E-2

    No problems so far. I am now able to install and run my preferred software like Mozilla. The other Windows issues can be sorted out separately so its a big thanks from to you as I have avoided a re-install!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds