Unable to clean infected computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by JT1, Aug 11, 2007.

  1. JT1

    JT1 Private E-2

    Hi

    I've spent all day running all the different programmes, trying to clean my sons computer from malware/spyware/viruses. I have just found out that at least two of the suspicious errors present at the beginning of this adventure are still present!

    On start up I have two dialogue boxes informing me that REGIST~1.exe is unable to locate REGDATA.dll and Instant~1.exe cannot find CSH.dll. At some point during the cleansing process, these did go away for a while but now their back.

    Now I need help please

    I've run A2 squared, Adaware, vundofix as well as online scanners and the little bugga's are still there. I think the computer has been partially cleaned but now it is being slowly infected again.

    One other thing: While running the bitdefender online scanner, towards the end of the scan the computer reported that it had encountered a problem and had to close. I wasn't able to get a log of the scan. I know it deleted a lot of items before it crashed. Not sure if its related though
     

    Attached Files:

    Last edited: Aug 11, 2007
  2. JT1

    JT1 Private E-2

    Further logs:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because you have been doing things on your own and have deleted files for software that you still have installed. These are not malware.

    Where is the requested CounterSpy log.
     
  4. JT1

    JT1 Private E-2

    Hi Chaslang

    If I have been "doing things on my own" I would have told you. All I did was to follow instructions. I haven't deleted anything.

    As for the counter spy log, here it is:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A2 Squared is not part of the READ ME. While it is not typically an issue to run it, it is not something we asked for so I assumed based on it and also on the statement
    you made that you were doing other things than what we requested. You also said you ran Ad-Aware which we also do not ask for in the READ ME.


    The below user account should be delete! It makes no sense that anyone have an account named like this.
    Code:
    "C:\Documents and Settings\"
    FFFFFF~1       3 Jul 2005              "ffffffffffffffffffffffffffffffffffffffffffffffffffff"
    Now uninstall the CounterSpy trial since we are finished with it

    Now download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {2224DF4A-DBB6-4E0C-81B1-18364F3010DC} - (no file)
    O2 - BHO: (no name) - {35CE5966-4E12-455F-A639-B096436004C5} - C:\WINDOWS\system32\ykmjnytf.dll
    O2 - BHO: (no name) - {58E3F0E5-0104-497C-A44C-0D5B8DB91470} - (no file)
    O2 - BHO: (no name) - {F503024B-0859-467A-9DBE-2633F8196F0C} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - Winlogon Notify: qomnoli - qomnoli.dll (file missing)
    O21 - SSODL: drivers - {59D05DEE-38D1-40F9-8317-3A13111010E1} - (no file)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way does your son use a scanner or OCR software TextBridge software which the below lines are for and these are part of where your error messages are coming from.

    O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
    O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h


    If this software is not use or not installed anymore, you can fix the above lines.
     
  7. JT1

    JT1 Private E-2

    Chaslang

    Thank you for all your help but the computer that was infected failed to boot this morning. Whether it was infected and caused the computer to fail or just a coincidence I don't know, but I can't get past "starting XP screen" .

    Everytime it tries to boot it gets to the "installing XP screen" and then shuts down. Even starting in safe mode fails. There is some writing at the bottom of the post screen but it disappears too fast for me to read.

    I have resurrected an older machine to find info on how to fix the dead one. Not holding out much hope though.

    JT
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. JT1

    JT1 Private E-2

    Hi Chaslang

    Sorry for the delay in replying. Got busy in work.

    I hadn't started to do the tasks that you suggested. I shut down the computer as uasual that night but it wouldn't start again next morning.

    Gonna look at the link shortly
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if that does not help, do you have your Windows XP bootable CD and also another question would be can you slave the infected hard disk to anothe PC and manually remove the files I listed (in the Avenger part of the fix) from it and then try putting it back into the original PC and booting.
     
  11. JT1

    JT1 Private E-2

    Hi chaslang

    Thanks for your continued support.

    I hope you don't chew my head off but I opened another thread with your colleagues in Hardware Problems and I have managed to get my computer back online. I thought that as I couldn't start my computer, that I must have a hardware problem, hence starting the thread in that department.

    I think you and your colleagues do a wonderful job for people like myself (where a little knowledge is sometimes dangerous!).

    I have managed to get my computer up and running again but I couldn't have done it without all you guys passing on your considerable experience.

    Thank you all

    Should I again need assisstance I shall surely know where to come!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your thread in hardware it sounds like you reinstalled. Is that true?
     
  13. JT1

    JT1 Private E-2

    Hi Chaslang

    Yes I did do a clean install. It seemed the best option. All seems to be going well at the moment.

    Would you suggest doing a check on my system even after a clean install?
     
    Last edited: Aug 15, 2007
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Not if you reinstalled from uninfected original media. What I would recommend is that you follow the steps in the below (even the first step with Windows Update to be sure you are updated):

    How to Protect yourself from malware!
     
  15. JT1

    JT1 Private E-2

    All updates installed and everything seems fine

    I'm going to spend the next few hours doing most of the other suggested tasks in your link.

    Thanks again for all your help

    JT
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds