Malware has locked me out of everything. Please help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Flaunt, May 25, 2010.

  1. Flaunt

    Flaunt Private E-2

    Hi everyone.

    Quick history:

    I originally got infected with 'Security Essentials 2010'. Nasty little thing. During my attempt to remove it I had to re-boot and then discovered I could no longer sign into Windows. I have a VERY helpful tech person who has been helping me on and off but he is not around very often and my home business is now suffering badly because of these problems :( So I just want to keep my options open by seeing if others can help too.

    So, he got me back into Windows eventually. Of course, the Malware is still active on the PC (whether it's the same one or I have more than one, not sure, I no longer get the same pop ups but I'm getting all the same 'fake' alerts etc). I can't run anything at all. No .exe files, no task manager, no regedit etc...nothing. Wierd things like the 'Folder Options' under 'Tools' in a windo has vanished. . Nothing I've tried from tons of help I've read is working. I have a list of instructions for the next step of removing the virus, the first of which was to run a file called 'exehelper.com' before we got started, but guess what? Yeah, I can't run that file either. I get the message

    "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item"


    And that's where I am now. I am reluctant to reboot in safe made to try things as I fear I am going to be locked out of Windows yet again and be back where I started. If anyone can help me get rid of this crap and stop me losing any more customers I would be forever grateful and indebted. I really aprreciate the help I am already receiving but time is no longer on my side.

    Thanks very much

    Jay
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try this in normal mode or safe mode with networking if it fails.:

    http://www.dougknox.com/xp/file_assoc.htm

    Scroll down to the ninth fix in the list the EXE File Association fix.

    Failing that you will need to try the below in normal mode, then if not then in safe mode.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. Flaunt

    Flaunt Private E-2

    OK, thank you. Quick update for you:

    I couldn't run the .EXE. reg fix so I started trying the 'Rkill' files.

    None of them worked so I just went mad and kept starting them over and over and EVENTUALLY one of them worked!.

    So, I tried to then run exehelper.com but I still got that "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" message.

    However, I already had download Malwarebytes so I've seized the opportunity of being able to finally run some .exe files and I'm currently running a scan now.

    Is this at least a good start? And should I continue to try the 'exehelper.com' file (perhaps download it again?). I'll also try the MGtools one when it's finished too. I don't wish to jump the gun so please just tell me what's best! Many thanks :)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes just continue on with what you can :)
     
  5. Flaunt

    Flaunt Private E-2

    Thank you. Do you need me to post any log results once I'm done? I noticed this advice in another thread.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please.
     
  7. Flaunt

    Flaunt Private E-2

    Hi,

    I've attached the results of Malwarebytes. It's telling me I should restart the PC for everything to take full affect. Should I do that now or run MGtools first? Sorry if they seem obvious questions but I just want to do everything right ;)

    Also, although I only downloaded Malwarebytes yesterday, I neglected to check for updates before I ran the scan. Is it worth me doing that also and performing another scan after the reboot?

    Thanks for your help so far :)
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes by all means perform a reboot and then let MalwareBytes update, re scan and let it fix what it finds.

    Then move onto using MGTools.exe and attach the C:\Mglogs.zip and the newest log from MBAM regardless of whether it found anything or not after the update.... :)
     
  9. Flaunt

    Flaunt Private E-2

    Well, I ran MGtools and nothing seemed to happen. I noticed in the window (briefly before it shut) that there was a list of error messages about not recognising loads of files and .bat processes?

    The only log result it produced in the MGtools folder was this:

    Code:
    ******************************************************************************
              MGtools installation folder and files at Start of Scans 
    ******************************************************************************
     Volume in drive C is HDD
     Volume Serial Number is 6811-AFE6
    
     Directory of C:\MGtools
    
    25/05/2010  13:29    <DIR>          .
    25/05/2010  13:29    <DIR>          ..
    25/05/2010  13:37               228 filelog.txt
    25/05/2010  13:37             4,376 sysinfo.txt
    25/05/2010  13:37    <DIR>          temp
                   2 File(s)          4,604 bytes
                   3 Dir(s)   7,382,044,672 bytes free
    ******************************************************************************
    
    ******************************************************************************
    *  File Versions Used:                                                       *
    *    GetLogs.Bat    - 05/03/2010 Version 2.31                                *
    *    32 bit Windows OS found                                                 *
    
    The only other info was some general system info. Has something gone wrong in running that then?

    I've updated MBAM and I'm currently running another scan.
     
  10. Flaunt

    Flaunt Private E-2

    MBAM found 8 more infections. I've attached the results.

    On a side note, during the last reboot I got these two 'RUNDLL' error windows pop up. (about not being found or couldn't run them or something)

    C:\WINDOWS\SYSTEM32\NvCpl.dll
    D:\DOCUME~1\JASONM~1\LOCALS~1\Temp\o4h8rer.dll


    Are these unrelated or after effects of the malware? And would my reg cleaner sort them out? Just curious ;)

    Let me know what's next and what I need to do about MGtools if at all. One other question, part of the fix from the other guy who helped me before was to run 'Combofix'. Will this still be a necessary step or do you think MBAM has done the job?

    Thank you so far, great stuff :)
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good.

    One relates to Nvidia, the other is more than likely malware. No, your reg cleaner should not be used to "fix this.

    The log from running MGTools.exe will not be found in the MGTools folder, as mentioned if it did produce a log then the zipped file will be located directly on your C Drive.

    Yes I would like for you to run combofix as per the instructions in the Read and Run me first procedures. Except the only difference being is that we will run it after first renaming it. Rename combofix.exe to kestrel.com before double clicking on it, on your desktop.

    Attach the C:\combofix.txt log into your next reply please. We will see what happens with this step before returning back to MGTools again.
     
  12. Flaunt

    Flaunt Private E-2

    Right, had some trouble getting Combofix going but it seemed to do its thing in the end.

    I've attached the log file results for you. Thanks :)
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you know what the below file relates to? Can you right click it and see what information can be gleaned from the properties?

    And what is this for?

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\Pfudev.bin
    
    DirLook::
    d:\documents and settings\jason mcdonald\Local Settings\Application Data\{1350C321-BDDF-4E67-8416-40AFA3380114}
    d:\documents and settings\jason mcdonald\Local Settings\Application Data\faaulraek
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now try to run MGTools.exe but before doing so let's rename it to 123.com.

    If successful please attach the C:\Mglogs.zip, otherwise just attach the combofix log for now.

    Don't forget to answer any questions that I asked you and also tell me how the machine is running now.
     
  14. Flaunt

    Flaunt Private E-2

    The first one says it is a 'video CD' file and it was created on the 20th May (same as original infection) so maybe related to that.

    I couldn't find the second file at that location. Even doing a search showed nothing.......rolleyes

    It's running great. Seems much smoother and quicker than it has in some time and no sign of any Malware at all :)

    I couldn't get MGtools to run even when I re-named it. I've attached the Combofix log file for you.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, let's do this:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    FileLook::
    d:\documents and settings\NetworkService\Application Data\wpcalv.dat
    
    File::
    d:\documents and settings\jason mcdonald\Start Menu\Programs\Startup\kill.bat
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now I want you to have another attempt at running 123.com (MGTools) this time in safe mode. Attach the C:\Mglogs.zip if successful, otherwise, try the below:

    Download and run OTL
    Download OTL by Old Timer and save it to your Desktop.

    • Double click on OTL.exe to run it.
    • Under Output, ensure that Minimal Output is selected.
    • Under Extra Registry section, select Use SafeList.
    • Click the Scan All Users checkbox.
    • Click on Run Scan at the top left hand corner.
    • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized
    • Please post the contents of these 2 Notepad files in your next reply as well as the log from combofix. :)
     
  16. Flaunt

    Flaunt Private E-2

    Right, I have attached the new combofix.txt and the 2 OTL files.

    I tried MGtools in Safe Mode but it still wouldn't run. The command window only pops open very briefly but I managed to see the error messages if it's any help to you. Basically there is a long list of file names associated with MGtools processes etc and each one is followed with the words "...is not recognised as internal or external command, operable program or batch file" :confused

    Anyway, files are attached.
     

    Attached Files:

  17. Flaunt

    Flaunt Private E-2

    I've attached the files for Combofix and OTL for you. Still couldn't get MGtools to run, even in safe mode.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  19. Flaunt

    Flaunt Private E-2

    Scan run and log attached :)
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do a system scan with HJT and place a checkmark next to the following lines:

    Click on fix once you have them both selected and then exit HJT.

    Now try this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.


    attach logs if successful.

    Now rescan with HJT and save a log file. Attach that also.
     
  21. Flaunt

    Flaunt Private E-2

    Sorry Kestrel, I'm an idiot. I was trying to run MGtools from my desktop all this time instead of the root C:\. rolleyes

    Anyway, I've run it and it seemed to work fine until it got to 'processdll' at which point I got some error messages about jit debugger or something and it all just stopped. Also said it couldn't run a process. However, it has produced a zip log which I have attached along with a new hijackthis one. Thanks
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now as I was working up another fix for you, I have just spotted that you have been working with me and one of our own malware fighters here who also works at another forum!

    You will be creating much confusion by working in two seperate forums for yourself, me, schrauber, not to mention that it is a waste of resources. Please choose where you wish to work at, and leave a note for whoever you decide not to work with. :)

    I realise you admitted this in your first post but I wasn't sure if you meant a friend of yours was helping you. ;)

    Thanks
    Kestrel13!
     
    Last edited: May 26, 2010
  23. Flaunt

    Flaunt Private E-2

    Hi there, yes I did start with Schrauber! He has also been fantastic but sadly wasn't too active (not a problem, of course and I really don't wish to sound ungrateful for FREE help!) but seriously, time isn't on my side due to my business which was suffering do to my problems. So I posted here around the same time as there to see what help I could get. I was actually going to post there tonight to let him know I was working with you (and still make a donation to them as I promised him ;)

    Other than originally getting back into Windows at the very start (with his help), I have only followed your instructions since starting this thread so nothing else has been done other than what you have instructed :)

    I will stick with you, please and, as I said, make my thanks and donation to the other place later. Sorry, for any confusion!
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, fair enough. Then we will continue on later, as I am spending some time with my Father now. I'll post back with a fix later on this evening.
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. First of all, let's have you rename kestrel.com back to combofix.exe and 123.com back to MGTools.exe.

    2. Why are you not using any anti virus currently?? I see remnants from you once using avg8 which I will get rid of at the same time as removing some malware with combofix.

    3. Please go to Add/Remove programs and uninstall the following software:
    • J2SE Runtime Environment 5.0 Update 4
    • Java(TM) 6 Update 18
    • Java(TM) 6 Update 7

    4. Before we continue you need to put this machine into normal start up mode by using msconfig.

    5. Now we never did try SUPERantispyware so now I want you to download and install it. Run it as per the instructions in the Read and Run Me first procedures.

    SUPERAntiSpyware - running & getting a log



    6. Now we need to use ComboFix to remove some malware and kill off old avg remains.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    Driver::
    AvgLdx86
    AvgTdiX
    avg8emc
    avg8wd
    File::
    c:\progra~1\AVG\AVG8\avgwdsvc.exe
    c:\progra~1\AVG\AVG8\avgemc.exe
    c:\windows\system32\drivers\avgldx86.sys
    c:\windows\system32\drivers\avgtdix.sys 
    C:\WINDOWS\cctcsq48.ini
    c:\windows\system32\avgrsstx.dll
    D:\Documents and Settings\jason mcdonald\Local Settings\Application Data\313856482
    D:\Documents and Settings\jason mcdonald\Local Settings\Application Data\P4s1N5
    D:\Documents and Settings\All Users\Application Data\313856482
    D:\Documents and Settings\All Users\Application Data\P4s1N5
    D:\Documents and Settings\jason mcdonald\Templates\P4s1N5
    Folder::
    c:\progra~1\AVG
    d:\documents and settings\jason mcdonald\Local Settings\Application Data\{1350C321-BDDF-4E67-8416-40AFA3380114}
    d:\documents and settings\jason mcdonald\Local Settings\Application Data\faaulraek
    d:\documents and settings\All Users\Application Data\avg8
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "avg8wd"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    7. Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    8. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this & also attach the log from running SUPERantispyware.

    9. Tell me how the machine is behaving now.
     
  26. Flaunt

    Flaunt Private E-2

    Right, I'm doing all that now. Btw, the reason I have no anti-virus right now is that I just got rid of AVG a couple of days ago. It wasn't working properly and was annoying the hell out of me with all the processes it was running constantly :p

    I was going to ask you to recommend one for me once we've finished here!
     
  27. Flaunt

    Flaunt Private E-2

    Right, I've done everything you required except update to the latest version of Java Runtime. I was able to uninstall 2 out of the 3 you asked me to. I couldn't remove:

    Java(TM) 6 Update 18

    It gave me an error saying it couldn't find 'jre1.6.0_12-c-l.msi'

    I did a search for it but found nothing. I even tried to install it again and get around it that way but I got the same error message. I have the new version (from your link) ready to install but didn't want to do it yet until you advise what's best ;)

    Please find attached all the logs you requested :)

    To answer your final question, the PC is still running very well and smoothly. No problems at all that I've seen.
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    For the Java problem you can try this:

    JavaRA 1.15

    Otherwise you will have to hit up the software forum for advice.

    Now use windows explorer to find and delete the below bold file.

    • d:\documents and settings\NetworkService\Application Data\wpcalv.dat

    • Please double-click OTL.exe to run it.
    • Click on the CleanUp! button at upper Right corner. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTL attempting to contact the internet you should allow it to do so. After the list has been download you'll be asked if you want to Begin cleanup process? Select Yes.
    • This step removes the files, folders, and shortcuts created by the tools I had you download and run.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:

    Install some anti virus ;)
     
  29. Flaunt

    Flaunt Private E-2

    Kestrel, you're a legend. Can't thank you enough for your thorough and prompt help :clap

    If you guys except donations I'd be happy to contribute and I will certainly recommend the forum to others. You have saved me a lot of hassle and helped me get back on track with my business. Superb, thank you.

    If I could ask one more thing? As far as an anti-virus is concerned would it be sufficient to obtain the license for either MBAM or SAS for the real time protection features? I'd be more than happy to pay if you recommend them :)

    Thank you again and keep up the good work ;)

    Jay
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We do not accept donations as such, but if you wish to show your appreciation you could purchase some geekwear ;)

    Now SUPERantispyware and Malware Bytes are NOT anti virus. Even if paid for they are only anti spyware applications so you need to choose something else for AV. In our how to protect yourself from Malware link we have many reccommendations or you can post in the software forum regarding this. :)

    You're welcome for the help. Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds