Badly Infected Laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cainabel23, Jun 11, 2008.

  1. cainabel23

    cainabel23 Private E-2

    I've been trying to fix my brother's laptop, which he somehow got infected with some major malware. I can connect to the internet, but cannot download or install any software or ActiveX (which makes doing scans pretty impossible). I can install some programs in Safe Mode, but the few programs I can install won't pick up anything in this mode. I am unable to run any of these programs from a Normal Start-up. I tried following your Malware Removal instructions, but was unable to install SAS (in Normal Start-up or in Safe Mode) because I get an error message that says something like the Administrator has forbidden it. I can install Spybot, but I can't update it so I can't run the scan. Malwarebytes Anti-Malware installed, but will only run in Safe Mode (in Normal Start-up I get the error message "Runtime Error 481: Invalid Picture." However, Malwarebytes won't detect anything in Safe Mode. I just don't know how to approach this anymore. Please Help!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download the MGtools.exe file as instructed in the READ & RUN ME. The boot into safe mode and try running it. If it runs then attach the MGlogs.zip file that is created. If you get the Runtime Error 481 message then go into the C:\MGtools folder and locate the GetLogs.bat file and double click on it to see if it will run without creating an error. Let me know what happens.
     
  3. cainabel23

    cainabel23 Private E-2

    Thanks so much...I had no problems and received no error messages running MGTools in Safe Mode.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not really seeing too much in the way of malware issues in those logs. You will have to try and get some real malware scanning tools to run. Possibly using another user account if necessary.

    I do have some things that you need to do though.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to PsExec
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Services (if you do not find them or get any errors, just continue):
      • Webroot Spy Sweeper Engine
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste PSEXESVC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
      • WebrootSpySweeperService
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=8T6d7hoKxNoMR_k_W8HYYGXKCUo
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
    O20 - Winlogon Notify: Fly - C:\WINDOWS\SYSTEM32\smart.dll

    After clicking Fix, exit HJT.





    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot (into normal boot mode), now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.




    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 12, 2008
  5. cainabel23

    cainabel23 Private E-2

    OK, so here's how things went:

    • Could not stop or disable Spy Sweeper
    • Could not uninstall any Java entries (in Safe or Normal mode)--received error message:
      Error 1711.An error occurred while writing installation information to disk. Check to make sure enough disk space is available, and click Retry, or Cancel to end the installation.​
    • Had to run Avenger twice because I messed up the entries in the Input Script Here: window
    • Had to run everything except CCleaner from Safe mode (Normal mode does not allow me to open any programs)

    Thanks again!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What happened exactly? Is Spy Sweeper showing in Add/Remove programs?

    Delete the below folder ( you may need to delete all files in the folder first)

    C:\MSI6b122.tmp

    Also look in the C:\Windows\Installer folder for any more of these MSIxxxxx.tmp files (where xxxxx is a random letter/number combo) and delete them if found.

    Now run this Windows Installer CleanUp Utility to see if there are any bad installs or uninstalls trying to run.

    Now try to uninstall all those old Sun Java versions.

    What happens when you try to run in normal boot mode?
     
  7. cainabel23

    cainabel23 Private E-2

    • Spy Sweeper does not show in Add/Remove Programs, and when I try to uninstall Spy Sweeper in Safe or Normal mode (going directly to C:\Program Files\Webroot\Spy Sweeper\unins000.exe), I get this error message:
      File "C:\Program Files\Webroot\Spy Sweeper\unins000.dat" does not exist. Cannot uninstall.​
    • There is also no longer an entry in services.msc to stop and then disable Spy Sweeper...however, last time I tried, when there was an entry, the options to Start or Stop were faded out so I could not select them and when I tried to go straight to Disabling, I got the message that I could not because the service was running.
    • C:\MSI6b122.tmp was empty and I was able to delete it in Safe mode.
    • I found 45 MSIxxxxx.tmp files in C:\Windows\Installer and was able to delete them all in Safe mode.
    • When I try to run Windows Installer CleanUp Utility in Safe mode, I get this error message (which is the same message I got when trying to run SAS):
      The system administrator has set policies to prevent this installation.​
    • When I try to run Windows Installer CleanUp Utility from Normal mode, I get no response.
    • For the most part, when I try to run any programs in Normal mode, I get error messages (sorry I wasn't more specific the first time)...
    • When I try to run MGTools.exe or Getlogs.bat in Normal mode, I get these error messages:
      Cannot export C:\MGtools\tmpUnKey.txt: Error opening file. There may be a disk or file system error.​
      and​
      Run-time error '481': Invalid picture​
    • I am able to open The Avenger in Normal mode, but I get numerous error messages along the lines of:
      Error: can't open file 'C:\xxxx' (error 5: access is denied.)
      and
      Error: Could not open script file. Aborting execution! (error 6: the handle is invalid.)
      and
      Error: Could not log error messages to file. (error 6: the handle is invalid.)​

    Let me know what you need next! Thanks!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This all really sounds more like problems in the registry and in the Windows OS. As I said earlier there really was no significant malware found in the logs. It would probably be a better idea for you to be posting in the Software Forum. Runtime errors could indicate registry problems. Something that may be worth a try if you can do it would be to create a NEW user account with administrator priviledges and see how the new account works. If you can create it and it works better, you could try running some scanners from this account to see if anything is found.

    Also see if you can do the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  9. cainabel23

    cainabel23 Private E-2

    I tried creating a new user account with Administrator privileges, but I'm still running into the same problems.

    When I double-clicked the fixme.reg file, I received the message:

    Information in C:\xxxx\fixme.reg has been successfully entered into the registry.​

    Should I try anything different now?

    If there's not much else I can do, I certainly understand. I knew from the beginning that this would be a difficult problem to tackle...and I really, really appreciate all the help you've given me.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please clarify! Did you try to create it or did you actually create one?

    I suggest that you post in the Software Forum since you problems do not appear to be malware. Sounds to me like you may be better off reinstalling.
     
  11. cainabel23

    cainabel23 Private E-2

    Yes, I was successful in creating a new user account, but I still was unable to run any scans using this account. I had the same error messages and restrictions.

    So, you're right, I'm probably going to format and start fresh. This will solve the problem, whether it's malware or software.

    Thank you so much for your help. It's been great working with someone so knowledgeable!:)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds