Malware, no Control Panel, AV disabled

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SpikeSpeedwell, Sep 16, 2007.

  1. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    I am trying to fix my daughter's very sick PC. By the time she called me, she already had lots of problems, and had responded to a pop-up to install bogus AV (I believe "AVSystemCare"). There are constant pop-ups ("Warning - Potential Spyware operation! ... click Yes to download Spyware Remover..."), Control Panel is gone, her McAfee AV is disabled, and many functions are not allowed ("This operation has been cancelled dut to restrictions in effect on this computer").

    I have read and followed as best I could the Malware Removal Guide. I say "best I could" because due to the #$%^ on the PC, I cannot do some of the recommended actions. This is what I have done/couldn't do (all actions done in Safe Mode - except where noted - with networking enabled when needed):

    No control panel, so couldn't remove anything via "add/remove programs".

    Installed, ran, in correct sequence, both ccleaner and Spybot S&D (over 100 problems found).

    Could not install Counterspy (got a pop up stating the Administrator does not allow installation).

    Ran AVG. Seven infected objects found, quarantined them. Though I had configured for reports after every scan, there was no report available in the reports section.

    Tried to install the latest version of Java. Got a pop-up: "System Administrator has set policies to prevent this installation."

    Went to Bitdefender website. During updating scanner process, updating virus signatures stuck at 67%, and never completed. Couldn't close session. Tried "ctrl, alt, del". Pop up - "Task manager has been disabled by your adminstrator."

    Had to power down PC. Got back to Bitdefender website, tried again. This time got stuck at 78%. Only way to close out was to power down.

    Since Bitdefender failed, I did NOT run Panda.

    I then re-ran CCleaner, Spybot (seven items found and "removed"), and AVG (seven Infected Objects again, quarantined again). Once again, there was no available report (though I double-checked that I had selected it as an option). The main file found was "Trojan.smal", with multiple instances of "Not-A-Virus.. [Winfixer, Renos,jh, etc.]."

    I then rebooted into normal mode. Ran GetRunKey. Dialogue box popped up: "Registry editing has been disabled by your administrator." Gave up.

    Ran ShowNew. Same thing happened.

    Installed and ran HJT. At least I got a log from that; it is attached.

    Please help!!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Let's see if we can make a few improvements and then I will have you go back and try to run the READ ME again because more could be hiding then we will find with HijackThis.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
    O4 - HKLM\..\Run: [DoNotDelete] C:\WINDOWS\system32\explore.exe
    O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
    O4 - HKCU\..\Run: [DoNotDelete] C:\WINDOWS\system32\explore.exe
    O4 - Startup: info.exe
    O4 - Startup: system.exe
    O4 - Global Startup: autorun.exe
    O4 - Global Startup: info.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey - see if you can run this now
    3. ShowNew - see if you can run this now
    4. HJT


    Make sure you tell me how things are working now!
     
  3. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    Thanks for the response!

    Followed your steps. Both GetRunKey and ShowNew ran. I will attach the Avenger, GetRunKey, and ShowNew logs to this message, and send a separate one with the new HJT log.

    Status of how things are working now:

    1) The approximately-every-five minute pop-up ("Warning - Potential Spyware operation!...") seems to longer happen.

    2) Control Panel still missing.

    3) Ontward restrictions still on computer (e.g., if I right-click on the desktop, select "Properties", I get a dialogue box that says, "This operation has been cancelled due to restrictions in effect on this computer...")

    Thanks again, looking forward to the next steps!
     

    Attached Files:

  4. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    Attached to this message is my latest HJT log, as requested.
     

    Attached Files:

    Last edited by a moderator: Sep 16, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew


    Make sure you tell me how things are working now!
    Also see if you can run the other scans (CounterSpy, BitDefender, and Panda) that you did not previously run due to your problems.
     
  6. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    How can I uninstall the old Java and Viewpoint software? Control panel is gone; I have no access to "add/remove programs".

    I looked in the folders of both applications, and didn't see an executable that appeared to be associated with unistalling.

    Even if I do a Ctrl Alt Del, a pop up comes up stating "Task Manager has been disabled by your adminstrator."

    Also, after you tell me how to remove the software (because I bet you know a way to do it), should that be done in Safe Mode?

    Should I skip the de-installation of these two software packages, and continue on with the rest of your steps (won't do anything until you advise).

    Thanks again!

    Spike
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Move that part of the fix to the end of the procedure just before getting the new logs.
     
  8. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    Ran Avenger. Copied quoted statements.
    Upon execution, saw a series of error messages ("Syntax error in line - does not appear to be a valid registry path, line will be ignored.") Pressed ok to continue, received another error dialogue box ("Error code 0: Line: ")

    This was repeated for "DisableTaskMgr", "DisableRegistryTools", etc.

    It looks like these error messages are in the attached Avenger log, so I won't repeat them here.

    Rebooted.

    Ran CC

    At this point, I was to try and uninstall the old Java and Viewpoint software. There still was no Control Panel (which would lead me to "Add/Remove Programs"), so did not try to uninstall.

    Ran GetRunKey and ShowNew

    Logs for all three are attached.

    Thanks!

    Spike
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay since Avenger failed to remove those registry keys, we need to do it manually.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure to tell me if you receive a success message on doing the above.

    Now try the uninstalls and install of the new Java. Then attach the same new logs if the above works.
     
  10. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    Successfully merged statements into registry.
    Rebooted
    Control Panel now there!
    Removed old Java, Viewpoint.
    Rebooted.
    Installed new Java (6.2)
    ran CC
    Ran Avenger. Wasn't sure on what to input, so repeated previously recommended statement (starting with "Files to delete C:\10.tmp...").
    Ran CC
    Ran GetRunKey and ShowNew
    Log files from all three attached.

    Thanks again!!!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  12. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    Well, it doesn't look like I am out of the woods yet...

    It appears that I still have some nasties hanging around.

    Ran CC.
    Ran Spybot S & D (came up with only two Microsoft "issues").
    Ran AVG Anti-Spyware (came up with 7 instances of Trojan.small, and once again no available report).

    Realized that I was in normal mode, so rebooted into safe mode, no networking.

    Ran CC
    Ran SB S&D (clean)
    Ran AVG Anti-Spyware (1 instance of Trojan.smal)

    Restarted in normal mode.

    Now ran Bitdefender. (3 viruses found) Log is attached
    Ran Panda Active Scan (5 viruses found, 1 Spyware; it looks like much of the "viruses" reference Avenger and Hijack This folders). Log is attached.

    I also noticed that the McAfee Anti-virus will not enable, no matter how much I try. I have already downloaded AVG Free Edition Anti-Virus, but thought I should wait to install it until after you give me a go-ahead (don't want to do something out of order that might confuse the issues).

    The McAfee Firewall seems to be functioning, but when I am done with cleaning up the system I will replace not only McAfee Anti-V with AVG, but will install Comodo FW.

    But first, onward to a clean system!

    What's next?

    Thanks for your help!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow my final instructions and thus have things laying around that are not problems but are detected as problems. Complete ALL of my final instructions and then tell me if you have problems. If you do have detections of anything, attach the logs that show the problems.

    There is one file that did not show earlier that you do need to delete though. Delete the below file:
    C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\system.exe

    Note: Bitdefender is incorrect! Those are backups of your hosts file created from running Spybot and using its Global Hosts immunization feature which also creates backups.
     
  14. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    Sorry about that - I thought an effective way to see if I "still had any Malware problems" would be to scan for them.

    I followed the final instructions, including toggling system restore, went through all of the steps on how to prevent Malware in the future, and everything is running perfect now. THANKS!!!!!!!!!!!!!!!!!

    One thing, I really tried to find it, but I could not find the file you recommended that I delete (C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\system.exe).

    I really, really looked for it, but couldn't find it.

    Once again, thanks!!!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem! ;)

    Then just to be on the safe side, run PandaActiveScan again and see if it still detects it since it did find it last time. If it does, it means the file exists.
     
  16. SpikeSpeedwell

    SpikeSpeedwell Private E-2

    I ran Panda again, and it came up with nothing! Yes!

    After it ended, there wasn't an option to view or save a report (unlike when I had viruses reported the first time), and I am assuming that it only gives an option to view reports if it finds anything bad.

    So with that, it looks like the PC is back in shape.

    Thanks again so much - you, and all of the great folks at Major Geeks ROCK!

    Spike.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds good! You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds