Massive virus?? Possible google redirect?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Texasrebel, Aug 11, 2011.

  1. Texasrebel

    Texasrebel Private E-2

    I dont know what this file is: anshnmsv.dll

    Heres the properties for this file

    Company = axalto
    File version = 4.31.00.01
    Internal name = RCCIDW2K.SYS
    Language = English (United States)
    Original File Name = RCCIDW2K.SYS
    Product Name = Reflex USB V3
    Product Version = 4.31.0.1

    Downloaded Kaspersky

    On install it ran for 15 sec. or so and quit. No extra Icon or logs. Looks like the install to my computer did not work.

    Files inside c:\_OTL
    Folder - "movedfiles" inside that folder is another folder titled "08182011_201341" inside that folder is another folder titled "c_programfiles" inside that folder is another folder called "spy bot search and destroy", inside that folder is 1 file titled "sdhelper.dll" 1.6.2.14 SBSD IE protection

    Running analyse from command prompt results in error message: Access is denied
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try this one more time with another change to the fix. Also I suggest that to avoid having to keep redownloading OTL.exe, just save a backup some where that you can recopy from.


    Double-click OTL.exe to start the program.
    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code
    Code:
    :processes
    :otl
    @Alternate Data Stream - 816 bytes -> C:\WINDOWS\1151866976:2682738619.exe
    @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:DFC5A2B2
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (IMVU Inc Toolbar) - {90b49673-5506-483e-b92b-ca0265bd9ca8} -  File not found
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} -  File not found
    O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} -  File not found
    O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} -  File not found
    O3 - HKLM\..\Toolbar: (IMVU Inc Toolbar) - {90b49673-5506-483e-b92b-ca0265bd9ca8} -  File not found
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} -  File not found
    O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} -  File not found
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} -  File not found
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (IMVU Inc Toolbar) - {90B49673-5506-483E-B92B-CA0265BD9CA8} -  File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} -  File not found
     
    :services
    6018a844
     
    :files
    C:\WINDOWS\1151866976
    C:\ComboFix
     
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Texasrebel

    Texasrebel Private E-2

    Did as you asked.

    It ran about a millisecond and shut off. No logs etc.etc.

    Problem is...I now have to rename OTL as I already have it on my desktop and it will not let me get rid of it. Now...I cant get rid of LTO (this is the rename I made for OTL) When I try to get rid of it, this is what my desktop looks like with message. Notice ICONS are gone on most programs.

    Thought this might be useful.
     
  4. Texasrebel

    Texasrebel Private E-2

    Okay screen shot didnt work. This is what it says when I try to delete basically anything

    Error deleting file or folder
    Cannot delete OTL: Access denied
    Make sure the disk is not full or write -protected
    and that the file is not currently in use
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you right click on the file and select Properties, what do you see as far as file attributes show?

    Also look at the Security tab and see if you have full permissions on the file.


    Do you have all of your important data backed up? It may be necessary to reinstall this PC, but I want to try making a CD to run scans while Windows has not been booted. While this can sometimes help to get us started, it can also remove system files that have become infected which could result in a PC being unbootable.
     
  6. Texasrebel

    Texasrebel Private E-2

    File Attributes for the OTL show:

    There are 2 things: Read only & Hidden. Both are unchecked.

    There is also an advanced attributes button.

    There is no security tab.

    Nothi9ng important on this computer.

    In refernce to your making a CD: Since the computer became infected, my CD drive is not accessable. It does not show in my computer or anywhere else, and does not work when I put a CD in.

    I do not have an XP boot disc.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! You may be in big trouble. Since nothing seems to run properly and you cannot even use a CD, we are running out of options. Perhaps you could make a bootable USB flashdrive and boot from it. You would have to purchase one though since you stated in a previous message that you do not have a USB flashdrive. The below instructions from BitDefender are for making a Rescue USB device.

    BitDefender Rescue USB



    Also please do the below right now before even looking into this Rescue USB stuff.


    Download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1

    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      6018a844
      1151866976
      2682738619
      1151866976:2682738619.exe
      :dir
      C:\_OTL /s
       
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. You can just close this notepad window since the log is already saved on your Desktop. Be patient! It may look like it is not doing anything, but it takes awhile for this to scan thru your whole system look for matches.
    • Please attach the SystemLook.txt log found on your Desktop to next reply.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also please try to run McAfee Stinger as per the below.


    Please download McAfee Fake Alert Stinger to your desktop.
    See the download links under this icon: [​IMG]

    Double-click stinger.exe to run (Vista and Win7 right-mouse click and select Run as Administrator)

    [​IMG]

    Stinger opens
    Note: Double-check that your C: drive is in the Directories to scan: area.

    [​IMG]
    Click the Scan Now button

    When the scan is complete, at the top of the Stinger window..
    go to File > Save report to file
    stinger.txt will be created on your desktop
    Attach stinger.txt to your next message.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And here are a couple more things to do that may help us to find some additional info.



    Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes).
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.
     
  10. Texasrebel

    Texasrebel Private E-2

    Ran system look. Log is attached.

    Ran mcafee fake alert stinger would not run

    Ran win32kdiag. Log attached

    Junction.exe will not run. Screen flashes and no log
     

    Attached Files:

  11. Texasrebel

    Texasrebel Private E-2

    FYI: I now have a Cruzer USB 2.0 Flash Drive 4gb
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those two new logs provided us with some key information on this infection. Let's see if we can start to fix those items. Odds are that once we get a few of these removed that many other tools will be able to run.


    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now rerun SystemLook, Win32diag and try Junction again with same instructions as previously given.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • new logs from SystemLook, Win32Diag, and Junction if they ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 24, 2011
  13. Texasrebel

    Texasrebel Private E-2

    Ran Avenger log attached.

    Ran system look and Win32kdiag...logs attached

    Junction did not run. It flashed and went away.

    Ran MGtools...log attached

    Thanks
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Quickly give the below a try.

    Now run the C:\MGtools\FixACLS.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then see if Junction.exe will run.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do the below.
    • Delete any copies of ComboFix.exe that you have
    • Also delete the C:\ComboFix folder
    • Now redownload combofix.exe and save to your Desktop
    • Try to run ComboFix. Let me know what happens.
     
  16. Texasrebel

    Texasrebel Private E-2

    Bat file ran

    Junction still wont run. It flashes real quick and thats it
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, did you see message # 65. I want you to do that and see if ComboFix will run.

    If not, please reboot into safe mode and see if ComboFix will run.
     
  18. Texasrebel

    Texasrebel Private E-2

    Ran Combo Fix

    Log attached

    First thing it said was I was infected with Rootkit.

    Thanks
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Excellent. It was able to get some of the things we needed to get and I was adding to another fix. While I work up another fix to try with ComboFix. Please run TDSSkiller right now and attach a new log. If it finds anything, fix it and then immediately reboot. And then come back for the next fix.
     
  20. Texasrebel

    Texasrebel Private E-2

    Still having a problem deleting the old programs. However, I am able to run programs by re uploading them and naming them with bogus names.

    Here is the log files for tdsskiller

    Thanks
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what this infection does. It will sometimes allow you to run a program only one time and from then on it is blocked. You will notice in the below that I'm deleting everything related to Junction. You will have to download it to try again. ;)


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now please also download MBRCheck to your desktop.


    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  22. Texasrebel

    Texasrebel Private E-2

    Everything ran

    Combofix still gives AVG warning, but ran it anyway :eek:)

    Logs attached
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below little fix with ComboFix will address this by removing the security center entry for AVG.

    You need to remember to tell me how things are working. Your logs are looking pretty good now.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (file missing)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll (file missing)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    Also redownload Junction now and see if you can get it to run.
     
  24. Texasrebel

    Texasrebel Private E-2

    Ran analyse.exe (highjackthis log attached)

    Ran Combofix. Log attached

    Ran getlogs.bat. Log attached

    Junction will not run. Quick flash and thats it.

    The computer seems to be running good, however, on every reboot, I get this: "Found new hardware wizard"

    Im not sure what its trying to reinstall or??

    The re-direct seems to be gone now!

    My "D" drive is back, but I havent tested it to see if its working. Waiting on instructions and a clean bill of health :^)

    Thanks
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete all files/folders related to Junction. Redownload and then retry.

    Possibly your D drive. Let it install.
     
  26. Texasrebel

    Texasrebel Private E-2

    did a search for Junction. Found 5 references to Junction in the "Qoobox" folder. Deleted Junction.exe from C drive in safe mode, could not delete anything in the Qoobox folder related to Junction. downloaded Junction again, ran it, and same results>>>>> screen flashed

    Told "founf new hardware" to install but it said no software was found. It did not say what it was trying to install.

    Also.....I was able to delete some of the old malware downloads from the beginning, howevedr, I cannot delete the following: tdsskiller.exe, OTL, and also we renamed OTL.exe to LTO and cant delete it either, and cant delete stinger.exe

    Other than that, system is running good, but cant delete all these old programs on my desktop

    Thanks
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to assume that you have junction.exe in your root folder so try the below.


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    C:\junction.exe <-- Tell me what error messages, if any, you see. You should just see instructions on how to use.

    Right click on them and select Properties, then click the Security tab. In the security tab make sure that your user account has full permissions.
     
    Last edited: Aug 26, 2011
  28. Texasrebel

    Texasrebel Private E-2

    Yes junction is in root folder

    followed instructions

    The license agreement window agreement came up, I clicked "agree"

    Then this message attached in the prompt window came up with flashing curser. I let it run for over an hour and it seemed to never do anything. Should I have let it run longer? Heres the message:

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\Owner>c:\junction.exe

    Junction v1.06 - Windows junction creator and reparse point viewer
    Copyright (C) 2000-2010 Mark Russinovich
    Sysinternals - www.sysinternals.com

    The first usage is for displaying reparse point information, the
    second usage is for creating a junction point, and the last for
    deleting a junction point:
    usage: c:\junction.exe [-s] [-q] <file or directory>
    -q Don't print error messages (quiet)
    -s Recurse subdirectories

    usage: c:\junction.exe <junction directory> <junction target>
    example: junction d:\link c:\windows

    usage: c:\junction.exe -d <junction directory>

    C:\Documents and Settings\Owner>

    Also...when I right click on the items I cant delete, there is no security tabs.

    Ps: I was out of town over the past 3 days.

    Thanks
     
  29. Texasrebel

    Texasrebel Private E-2

    Also I noticed everytime I run junction, or try to, it creates an empty log.txt on my c drive.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It can take a long time to run while check all files and folders on your PC.

    Reopen the command prompt window and this time enter the below command and wait for the scan to finish ( you will see the prompt return ). Observe the space before and after the -s and also a space before the >.


    C:\junction -s c:\ >C:\log.txt
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please tell me exactly which items you mean.
     
  32. Texasrebel

    Texasrebel Private E-2

    I think Im running the Junction now, Im not sure.

    I click start, run, and type in cmd and hit enter

    Then I get prompt window with curser flashing, I paste in c:\junction -s c:\ >C:\log.text

    Then I hit enter.

    I get the C:\Documents and Settings\Owner> listed twice, and flashing curser at the end of the arrow.

    Am I suppose to leave this be and wait for hours or am I doing this wrong?
     
  33. Texasrebel

    Texasrebel Private E-2

    FYI: evrytime I run junction, this log text appears on my C drive. I have the junction log attached. Dont know iof this is what you need or not. Funny thing is, the programs listed in the log text are the programs I cant delete and have no security tabs.

    Thanks
     

    Attached Files:

    • log.txt
      File size:
      1.3 KB
      Views:
      4
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is what we are looking for and it is the reason that you cannot delete the files.

    Hangon while a think about an attempt to fix this.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, first I need you to get the new version of MGtools on your PC so do the below while I continue to prepare the next stage of your fix. Just do what is shown here. I do not need a new log from MGtools right now.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now make sure that you have installed the new version of MGtools as requested before doing the below.



    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  37. Texasrebel

    Texasrebel Private E-2

    did as asked.

    Heres the mglogs.zip

    also...I never got a license agreement, but the "ok" pop ups occurred. FYI: Still cant delete anything and there is still no security tabs
     

    Attached Files:

  38. Texasrebel

    Texasrebel Private E-2

    Oopps ...my bad. I was able to delete 3 of them I deleted tdsskiller.exe mbrcheck, and another we renamed. I still cant delete OTL.exe, LTO.exe(just a rename we did for OTL) and stinger.exe

    Sorry about that

    Thanks
     
  39. Texasrebel

    Texasrebel Private E-2

    This is weird. Just tried to delete OTL.exe and it deleted it. Why the delay? Still cant delete LTO.exe or stinger.exe...but maybe it will in a minute. Real strange
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now let's do the below with WIn32Kdiag as we have done a few other times:

    Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r


    I also want to try uninstalling a few programs if they are still installed. Are any of the below still installed? If yes, then uninstall them. If not we will try deleting what we saw of them.

    SUPERAntiSpyware
    Spybot



    Now uninstall ComboFix using the below (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
      • Notes: The space between the combofix" and the /uninstall, it must be there.
    Now run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).





    Then attach the below logs:
    • the new Win32kDiag log
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  41. Texasrebel

    Texasrebel Private E-2

    okay did as asked.

    avenger log attached and glog attached.

    Also...after reboot all programs I couldnt delete are now gone.

    You are the shadowputerdude! Hahaha Cool name :)
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the last log from Win32kDiag. I'm suspecting that at least that one folder ( C:\WINDOWS\$NtUninstallKB14243$ ) is still going to be there and hidden and locked.
     
  43. Texasrebel

    Texasrebel Private E-2

    couldnt find the log...I may have deleted it by accident. I went ahead and re-ran it. Log attached. If that didnt work, let me know what to do.
     

    Attached Files:

  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent! That folder is gone now too.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  45. Texasrebel

    Texasrebel Private E-2

    tried to install trend micro, however, there seems to be a part of ad-aware still on the computer not allowing us to install trend-micro. Ad-aware is listed in my add and remove programs, but it wont let me delete it. Seems its gone but theres something still there maybe registry? Thanks for any help to this!
     
  46. Texasrebel

    Texasrebel Private E-2

    FYI: Ad-aware is listed in my add and remove program and it is keeping me from installing any protection. It wont let me delete it. I did a search for "ad-aware" on my computer, nothing found. I did a search on my computer for "lavasoft" nothing found. What in the world?

    Also....computer is working great, but I cant go online until I get some protection or Im gunna be right back in here :)

    I do appreciate all you have done for me and have no problem contributing to the cause if you will also direct me to that place as well. Your help has been much appreciated.

    I do have a question....why would all my desk icons turn into "short cuts"? and also have .lnk at the end of all programs? This just happened on my main computer >> Kids were on it :(

    Thanks
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will use ComboFix to try and force it out.

    You are talking about a different PC?? Shortcuts are .lnk files. However there are infections that can add .lnk to the end other file types. If you think this PC is having a problem due to an infection. Run the cleaning procedure on it, and start a NEW thread for it.


    Since we removed ComboFix, redownload and save the below current version to your Desktop:

    combofix.exe



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Then attach the C:\ComboFix.txt log
    Did that help?
     
  48. Texasrebel

    Texasrebel Private E-2

    Before we saw your post, we did a "regedit" and got rid of anything that said lavasoft or ad-aware and was able to install Trendmicro Titanium.

    We went ahead and ran your instructions with combofix, log attached.

    Yes the other problem is with my other computer that has all my important files etc. on it. I will do as you asked and start a new thread if needed.

    By the way...what kind of virus or malware did this computer have if you dont mind me asking.

    Also....I live on the Texas coast ;) and usually we are the ones getting the hurricanes. I truely hope you guys are doing alright up there. I know oh to well what you guys just went through.

    Thanks
     

    Attached Files:

  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix removed more that was remaining. ;)

    Names are not always that useful since every scanning tool can use different invented names. But one of the names being used to reference the type of infection you had is ZeroAccess which is a recent form of infecton using rootkit type processes to hide and block removal.

    Thanks! We have varying amounts of damage and flooding depending on where you live and the elevation. Many people are still without power and quite a few are without homes due to flooding.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds