keyboard is disabled when OS boots

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sublimleylimey, Mar 29, 2010.

  1. sublimleylimey

    sublimleylimey Private E-2

    delete this message

    delete this message
     
    Last edited: Mar 29, 2010
  2. sublimleylimey

    sublimleylimey Private E-2

    Here are the logs , I hope .
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. C:\Documents and Settings\Grant Anderson\Desktop\MGtools.exe <--- Delete this.

    2. Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 17

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Now we need to use ComboFix to be rid of some malware and also some prevx and eset remnants.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    CSIScanner 
    ionl
    OBQQSVKBOIDHGU
    pxrts
    pxkbf
    esihdrv
    
    File::
    c:\windows\isRS-000.tmp
    C:\Documents and Settings\Grant Anderson\Local Settings\Application Data\20xYJkS83BHk4
    C:\Documents and Settings\Grant Anderson\Local Settings\Application Data\4jU185
    C:\Documents and Settings\Grant Anderson\Local Settings\Application Data\8Kc67
    C:\Documents and Settings\All Users\Application Data\20xYJkS83BHk4
    C:\Documents and Settings\Grant Anderson\Templates\20xYJkS83BHk4
    C:\WINDOWS\system32\SET11.tmp
    C:\WINDOWS\system32\SET7.tmp
    C:\WINDOWS\system32\SET8.tmp
    C:\WINDOWS\system32\SETA.tmp
    C:\WINDOWS\system32\SETB.tmp
    C:\WINDOWS\system32\SETC.tmp
    C:\WINDOWS\system32\SETF.tmp
    c:\windows\system32\drivers\olhrhlt.sys
    c:\docume~1\GRANTA~1\LOCALS~1\Temp\OBQQSVKBOIDHGU.exe
    c:\windows\system32\PxSecure.dll-upgrade1778718.tmp
    c:\windows\system32\drivers\pxkbf.sys
    c:\windows\system32\drivers\pxrts.sys
    c:\docume~1\GRANTA~1\LOCALS~1\Temp\esihdrv.sys
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    6. Please attach the mbam log that you neglected to include.

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    8. Let me know how the machine is behaving!!
     
  5. sublimleylimey

    sublimleylimey Private E-2

    kestrel113, thank you so much . log att
     

    Attached Files:

  6. sublimleylimey

    sublimleylimey Private E-2

    An attempt to change the hosts file was blocked by WINPATROL after cfix was all finished. The keyboard is not detected but the drivers are loaded . Keyboard works fine on my other pc. It's frustrating this thing it is ! I am very grateful to you for giving your time skills to help with this :) What next ?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. This may be a problem that you can get resolved in software as we here in the malware forum are limited to only removing malware. :)

    Now your MBAM log reveals that you took no action on the threats it found. Did you indeed fix them afterwards? If not please do so now, as I go through your last set of logs.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. sublimleylimey

    sublimleylimey Private E-2

    Found a file masquerading as a .wav in some DnB samples it is not a .wav labelled sucker when clicked on. Not detected by any AV but has reappeared after deletion . It is in sandbox right now . Is it safe to just delete the sandbox ( losing the other files in there) or does it have to be overwritten, how should we proceed? What about the embedded nulls in the registry ?
     
    Last edited: Mar 31, 2010
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Unfortunately I am not familiar with Sandboxie, should there not be an option to delete a single file if so desired rather than everything that's in the box? Perhaps this is something you should also discuss in the software forum. I do not know what else you have of importance in the box.
    What embedded nulls?
     
  11. sublimleylimey

    sublimleylimey Private E-2

    Well it is potentially malware . Sandbox is "ringfenced" if you will in its own space on the drive . Previously deleting the offending file has failed, sorry to be insistent but I think I need to get rid of whatever it is "properly" .
    The reg issue was detected by sophos prior to your assistance but it is still there. Thanks for help so far we're almost there now c'mon Kestrel13 lets kick the little bugger out permanently.:tas but if you want me to hit up the software forum thats okay . What'll it be pal?:cool
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But if the file only exists in the sandbox and not on the main system then I do not know what to suggest. Is there anything that you actually want in the sandbox? Can you not move out what you need to another location and then because the file in question refuses to delete, how about an uninstallation and reinstallation of Sandboxie?
     
  13. sublimleylimey

    sublimleylimey Private E-2

    Okay I'll do that . Delete Uninstall reinstall , let you know how it goes.:)
     
  14. sublimleylimey

    sublimleylimey Private E-2

    :crap can't delete the sandbox contents access denied
     
  15. sublimleylimey

    sublimleylimey Private E-2

    Eerything fed to the shredder apart from reported errors. "confirm delete write protrected file " YES" " system cannot find specified path or does not exist" . This happens about 6 times . SandBox properties 0 bytes . Will not delete as file in use by another program. File left behind is lost season 6 ep7
    video_ts . I believe this file was the start of the problems. hope this helps
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No idea. As I said, I am not familiar with SB, I used to mess around with a virtual machine. Any crap that got on there I didn't want, I just had a fresh .vhd to play with, and then I got rid of the previous.

    This is very much something you can discuss in software. I only have the time to figure out malware removal. Sorry :(
     
  17. sublimleylimey

    sublimleylimey Private E-2

    Okay then thanks , anything else to do , do I need to clean anything up ?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you need to follow my final steps in post #8 if you haven't done so already. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds