Cannot run any software!!??

Discussion in 'Malware Help (A Specialist Will Reply)' started by trase80, Dec 30, 2007.

  1. trase80

    trase80 Private E-2

    I was infected with a virus or malaware or spyware yesterday that is really driving me crazy.

    I cannot run any removal tool for example AVG, Spy Sweeper, Spybot. Only one that is working is Spyware Doctor. It found many things but did not seem to do anything. I also cannot run any online virus scan. My task manager is disabled. My taskbar is locked and I cannot see it. There is a note saying that I am infected with a syware and when i click on it it takes me to gomyhit.com. If I'm not mistaken before running Spyware Doctor it was also taking to a site avscan.com or something like that.

    I also cannot cut, copy, paste or move anything.
     
  2. trase80

    trase80 Private E-2

    I tried running hijackthis but when i double-click it nothing seems to happen.
     
  3. trase80

    trase80 Private E-2

    Update

    I decided to follow the Malware Removal Guide. After running ComboFix like it asked and restarting windows after the scan Windows is no longer working.

    Can someone please help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Update

    Welcome to Major Geeks!

    What error message do you get when trying to load Windows? How far do you get?

    Can you boot in Safe Mode?
    How about Safe Mode with Command Prompt?
     
  5. trase80

    trase80 Private E-2

    I don't know how i did it but Windows is booting again. Once it booted ComboFix said that the log is unavailable. I was able to run Spybot, AVG anti-spyware and MGtools. Now when I tried to attach the logs I realised that there was no option to do so. Very weird. I feel like this thing has taken over everything. It has removed any important link for example any button to start online virus scans and now the attach button on MajorGeeks. Maybe if I use a different browser?

    If I have to just let me know and I will save the logs on a usb drive and post them through my laptop.
     
  6. trase80

    trase80 Private E-2

    After running Super Anti-Spyware I am no longer able to get into Windows through Normal mode. Once it get to the Windows loading page it loads for a bit and then restarts automaticly. Safe mode is working.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try using another browser to attach your logs. Also you can try flushing your browser cache and clicking refesh a couple of times. This will often work. Otherwise post them using your laptop.

    Why did you run SuperAntiSpyware? It is not part of the READ ME.

    Is your copy of Spyware Doctor a paid version or free trial? If free, uninstall it now.
    Is your copy of Spy Sweeper a paid version or free trial? If free, uninstall it now.
     
  8. trase80

    trase80 Private E-2

    Hey Chaslang, i just installed Firefox and it works fine. Attachments option is there. :)

    I uninstalled Spyware Doctor, Spy Sweeper and all the rest of the anti-spyware I had installed except for SuperAntiSpyware, i was not able to uninstall it.

    I have attached the logs from AVG and MGtools. The AVG log is from a new scan that I just did because I hadn't saved the log from the first scan I had done.

    If it is necessary I will try and run ComboFix one more time and maybe it will work better this time around. Please let me know
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure we will be able to fix all of your problems. Your log shows many of the required service for Windows to be either missing or just plain broken. Let's fix what we can a see what happens.

    Make sure that you have uninstall Spy Sweeper and Spyware Doctor before continuing.

    Now we must disable Windows Defender's realtime protection:

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2
    Mozilla Firefox (2.0.0.2)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis. And click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\shovth.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [sis32] C:\WINDOWS\system32\winsos.exe
    O4 - HKLM\..\Run: [winroot] C:\WINDOWS\system32\winsn.exe
    O4 - HKLM\..\RunServices: [MSRT] svcmon.exe
    O4 - HKCU\..\Run: [Gsxlpzip] "C:\Program Files\Common Files\??crosoft\tracert.exe"
    O4 - HKUS\S-1-5-21-1614895754-838170752-682003330-1004\..\Run: [Gsxlpzip] "C:\Program Files\Common Files\??crosoft\tracert.exe" (User '?')
    O20 - Winlogon Notify: hggffda - hggffda.dll (file missing)
    O20 - Winlogon Notify: jkhfd - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. trase80

    trase80 Private E-2

    I was just about to start when I realized that I can't open Windows Defender. When I try I get the following error: 0x800106ba.

    Can I go ahead with the rest of the steps?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can uninstall it via Add/Remove programs. Either way just continue.
     
  12. trase80

    trase80 Private E-2

    I was not able to uninstall Windows Defender or Java.
    I did go on with the rest and I attached the logs as asked.
    Unfortunately I do not see any improvements.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because only some of the problems actually got fixed completely. Some of the malware came right back. Also remember what I said, "we may not be able to completely fix your PC due to the state that it is in". Your OS is really messed up.

    I going to work up a fix using a different method than with Avenger. I'll post it in my next message.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must download combofix.exeto your Desktop. The fix will not work otherwise. Previously you said ComboFIx did not work and I do not see ComboFix.exe on your Desktop and that could be why it did not work.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [sis32] C:\WINDOWS\system32\winsos.exe
    O4 - HKLM\..\Run: [winroot] C:\WINDOWS\system32\winsn.exe

    After clicking Fix, exit HJT.


    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    • Then attach the below new logs:
      • C:\ComboFix.txt
      • C:\MGlogs.zip
    Do you have your Window XP boot CD?
     
  15. trase80

    trase80 Private E-2

    We forgot one thing: I can't copy,cut,paste or move anything. So I typed the text in the box and when i got to the step where i had to drag it into ComboFix... Yup, I couldn't. This things got me by the balls and it's not letting go. If you tell me it's hopeless I'm just gonna try and see if any burning software works, backup everything I need and format. That's IF they work.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not mentioned this before. How did you complete the instructions in message # 9? If could be a better idea to copy and paste the information to a CFScript.txt file on another PC (to avoid possible typing mistakes) and then copy to this PC.

    You mean your mouse cannot drag and drop????

    Try running the steps in safe boot mode.

    If you get to this point (and you probably will even if we remove the malware), you have to be careful that you do not back up anything that could be infected.

    You did not answer my question about having your Windows XP boot CD. Do you have a WinXP SP2 bootable CD?
     
  17. trase80

    trase80 Private E-2

    For message 9 I had also typed the text myself because I cannot cut,copy or paste anything. Sometime I am able to copy but it won't paste. In Notepad I was able to copy and paste within Notepad whatever was already in Notepad.

    My mouse does not drag or drop anything.

    I am now going to try and do the steps in safe mode and let you know what happens.

    I think I do have a Windows XP SP2 boot CD. I'm not sure but I can get one if I don't. How do I know if it is SP2.
     
  18. trase80

    trase80 Private E-2

    It did not work in safe mode so i tried something else.

    In normal mode, I right-clicked on CFscript.txt and clicked on open with combofix.exe. It worked.

    Here are the 2 logs.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay based on what I'm seeing from all of your logs accumlated thus far, this infection keeps regenerating itself after we fix things we are seeing. I now believe that part of the reason is the below.

    Here are things I have observed
    • the infection creates at least one EXE file in every folder (or almost every folder) on your hard disk.
    • the EXE file will have the same base name as the folder it is created in. For a few examples:
      • in C:\Windows it created Windows.exe
      • in C:\WINDOWS\PCHEALTH\HELPCTR\Binaries it created Binaries.exe
      • in C:\ it created .exe ( Since C:\ has no basename the base is blank and you just get .exe ) This root folder also has a CCC9DE8D.exe infected file.
      • in C:\Documents and Settings\All Users.WINDOWS it created All Users.WINDOWS.exe
      • and so on for all folders. It probably creates it in folders as they are accessed so some folders may not initially have an EXE.
    • these EXE files are always 89088 bytes in size and have a creation date of 2007-12-29
    • in some folders more than one infected file exists and it is not using the name of the folder. Like in C:\Windows\system32 where shovth.exe, winsn.exe, and winsos.exe are all being seen.
    • I also noticed references to infected files on drive D and drive G . Which drives are these? Are they builtin hard disk or removable media? They are infected to and YOU MUST AVOID using them for anything and do not put them into another computer. If you have other computers, you need to check them ASAP for this infection. Also if you have use a removable device it is more than likely infected and you must clean it too before putting it into another PC where it can infect it.
    You could have literally thousands of these files on your harddisk and the only way you may be able to fix this infection may be for you to disconnect from the internet, boot in safe mode, and locate every file fitting the descriptions given above for file size, naming convention, date....etc and delete all of them manually. This means you will have to thru every single folder on your hard disk one at a time to locate the infected files and remove them. And also while in safe mode you would then have to run the fixes given to remove the entries from the registry by running the HijackThis and ComboFix procedures.

    Now comes the decision of whether you want to spend the time doing the above especially since you appear to have other major problems within your Windows OS that is causing many services not to run. And this does not seem to be part of this infection. Thus even if you can manage to find and remove all of these infected files, registry keys....etc, your PC will still be in pretty bad shape.


    Notes on additional things you can try if you wish to continue


    1) BitDefender Online Scanner

    I was just thinking about a possible online scanner name BitDefender which could possibly help in finding and removing many of these infected files. You may want to give the below a try just to see what it finds and removed.


    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.

    • Click on this link Bitdefender
    • agree to the license and then select Scan.
      • DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.
    • Once Bitdefender completes the scan:
      • Click-on the Detected Problems tab. Then select Click here to export the scan report
      • When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt)
      • and then in the File name box enter change to bdscan then click save.
      • This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
    If you do not follow these steps properly, you will have an incorrect log or worse a log summary which is useless to us.

    Attach the bdscan.txt file as an ATTACHMENT. It could be very large if lots of infected files are found. If this happens, you will probably have to compress the log file into a ZIP file to attach it here.


    2) SDfix Scanner

    Download SDFix and save it to your Desktop.
    • Run the SDFix.exe by double clicking on it.
    • Allos it to install into the default location which is c:\SDFix
    • Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode )
    • When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Attach the Report.txt file to your next message.
     
  20. trase80

    trase80 Private E-2

    I do want to format my drive. But some things I need from the drive C. Mostly the things that i need are in my DC++ downloads folder which are folders with mp3s and a few other files for school and work.

    Drive D is a partition of drive C. Most of it is also folders with mp3s and folders with compressed .img files. I would also like to keep this.

    The most important thing for me is drive G which is an internal hard drive which is also 99% folders with mp3s. It is very important for me. Another drive that is very important to me is drive H which is an external hard drive which hasn't been appearing since the infection, it is connected through USB. I will do pretty much anything to clean and save these 3 drives: D,G and H.

    I have attached the SDfix log. I was not able to run BitDefender because it does not work with Firefox and my IE won't open most links.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be very careful backing up anything that can be considered an executable file including MP3s. You should have them scanned on a CLEAN PC.

    It may be infected just like drive C.

    Every drive could be infected. There are no guarantees.

    Did you notice all of the files it located that were of that 89088 files size I mentioned? They are all infected and you can delete all of them yourself but I doubt it will help.
     
  22. trase80

    trase80 Private E-2

    I have decided to format Drives C and D. Drive D is a a partition of drive C.
    I have backed up everything that I need from those 2 drives onto DVD-R. Now the question is once I have the pc formated what are the procedures I have to take before connecting my computer to the internet. And what should I do to scan and clean, if necessary, the DVD-Rs, drive G and drive H ,which I havent backed up and am leaving them as they are, once my pc is formated (G is internal and H is external).
     
  23. trase80

    trase80 Private E-2

    After taking a quick look at the DVD-Rs where my data from drive C and D is backed up on, I know that at least 2 of the discs have those executable files.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before connecting to the internet, your PC should have the below installed
    • an antivirus
    • realtime antispyware blocking
    • additional protect from Spybot's Immunize feature and also Spyware Blaster
    • a real software firewall (the one in Windows XP is not adequate)
    • in short see this: How to Protect yourself from malware! Obviously you cannot get updates for Windows and some other items until ater being connected but you need to have protection in place.
    None of these are trust worthy and your newly formatted drive is at risk if these other items are connected. You cannot clean a DVD-R since it is not rewritable. You could try scanning drives G & H with your antivirus and antispyware tools and also tools mentioned in this link Alternative Scans but you need to be very careful that you do not reinfect you system by opening or accessing infected files from the the other drives and DVDs. You can look for and manually delete all the EXE files like I mentioned. However none of this is guaranteed to get you clean especially if the antivirus programs do not properly detect and remove this infection. Your only truly safe option is to dump everything.
     
  25. trase80

    trase80 Private E-2

    Okay, I formated my pc and everything seems to be fine. I actually found a way to delete all the .exe from my G and H drives.

    I have installed like suggested in "How to Protect yourself from malware!":
    Anti-Virus
    1)AVG Free Edition
    2)a-squared (a²) Free edition

    Firewall
    1)ZoneAlarmFree

    Realtime AntiSpyWare
    1)Comodo BOClean Anti-Malware

    After the fact AntiSpyWare
    1)AVG Anti-Spyware Free Edition
    2)SpyBot-Search & Destroy
    3)SUPERAntiSpyware Free Edition
    4)SpyWare Blaster
    5)Ad-Aware Free Edition

    I would like to know which of these programs should be running all the time. Also are the paid versions of the free programs worth getting or will all of this do the job. One more thing, is AVG Anti-Spyware's "guard.exe" necessary?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Things that should always be running:
    • AVG Free Edition
    • ZoneAlarmFree
    • Comodo BOClean Anti-Malware
    a-squared (a²) Free edition is not is a necessary item to install. It just gives a background scanner as additional support for what your antivirus does. It provides no active protection unless purchased.

    After you run the free versions of the tools for awhile, decide whether you like them or not. If you do, it would be worth purchasing the full versions to get addition features and also full support. It also supports continued development of programs like this. However, it is not necessary to purchase them as the free tools due work quite well. It is just a matter or limited or no support, and some features will be missing.

    The guard.exe service that is part of AVG Antispyware is required for full functionality of the free program even after the 15 day trial is over. You can stop the service from loading and the program will still run to do scans and remove malware but some features of the free tool may not work. Many people do choose to terminate it.

    I find strange that you ask about this but did not ask about the processes and service that SuperAntiSpyware also loads. And if you installed Ad-Aware 2007 (which I don't recommed) it will also install a service. You don't reall need to have both AVG AntiSpyware and SuperAntiSpyware installed. One or the other is more than enough with the others that are installed and in fact you don't really need to have either of them since they are only after the fact scanners.
     
  27. trase80

    trase80 Private E-2

    The reason why asked about guard.exe is because it does not allow me to terminate the process which I do for Ad-Aware's service and SuperAntiSpyware's.

    Anyway I really appreciate the help Chaslang. Thank you!!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Ad-Aware 2007's service cannot be terminated. It will come back. And in fact so will SuperAntispyware's. Services are not normal processes. To stop a service from reloading, you must remove the service entry from the registry. Otherwise some small amount of time after stopping the service, it will just automatically startup again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds