Completed "READ AND RUN ME FIRST", but computer is still misbehaving!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ds11com, Feb 1, 2008.

  1. ds11com

    ds11com Private E-2

    I was thrilled when I found MajorGeeks, because of all the excellent help you give. Thanks in advance.

    The problem I'm having is that there are random I.E. popups, the virtual memory is always low, and internet explorer is working poorly. And basically, I'm concerned I will lose my data.

    I recently noticed that there are 2 links on my desktop that I never placed there. One is called "windows update" and the other on is "help and support center." Both are linked to the website storageprotector.com. Everytime I delete them, they reappear, but now they are reappearing with no icon picture.

    I ran AVG Anti Virus Free Edition, before and after the "READ AND RUN ME FIRST" and both times I got the following errors:

    AVG Anti-virus Test Result:

    OBJECT:
    Partition table (MBR)
    Boot Sector of disk C:
    C:\Windows\system32\Kernel32.dll
    C:\Windows\system32\wsock32.dll
    C:\Windows\system32\user32.dll
    C:\Windows\system32\shell32.dll
    C:\Windows\system32\ntoskrnl.exe
    C:\Windows\system32\drivers\etc\hosts

    For all of the above, the result is a “reading error”

    OBJECT:
    C:\

    For the above object, the result was “cannot open; not checked!”

    While I was following the directions of "READ AND RUN ME FIRST" I ran into the following issues:
    -I couldn't complete the scan with Spybot, because I received multiple errors saying virtual memory was low. I then ran Spybot after AVG Anti-Spyware and received an error message saying SpyBot was changed and another message that said it had failed.
    -When I ran AVG Anti-Spyware, I changed the settings that were required during the scan, so the report generated may not be complete (?)

    To be honest, I don't know how this problem came to be. My family uses this computer, but I make sure that they go on legitimate websites. I'd greatly appreciate it if you could also tell me what the source may have been.

    If you need ANYTHING else, I'll be checking back often. (By they way, I'm on a different computer I borrowed)

    Thank you greatly for your help!!
    -Dmitry
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Normally not a malware issue. This would be a topic for the Software Forum but you can try the below first.

    When your system is low on virtual memory, allow Windows to automatically manage the virtual memory. In Windows XP, follow the below instructions:
    • Click Start, then open the Control Panel.
    • If you have your system set for Category View
      • then click Performance and Maintenance, and then double click System.
    • If you were in Classic View just double click System.
    • Now on the System Properties form, click the Advanced tab.
    • Under the Performance area, click Settings button.
    • On the Performance Options form, click the Advanced tab.
    • Under the Virtual memory area, click the Change button
    • Now on the Virtual Memory form under Drive [Volume Label], click the drive that contains the Paging File Size (virtual memory) settings that you need to change. In most cases, this will be your C drive. It will also normally be already selected by default.
    • Click to select the System managed size option, then clickthe Set button.
    • Click OK three times and restart your computer.
    Normal results!


    It is impossible to truly say how because there are many different ways to pick up these kind of infections. However in most cases it is from accessing questionable sites or downloading things that should not be downloaded, or just being to click happy without reading what something says. It can also easily occur when a PC is not properly protected or is out of date with updates for all software. It is quite possible that your problem was no protection an no updates based on your logs.

    MGtools did not run properly. Did you accept the license agreement that popped up for TrendMicro HijackThis as was instructed in the READ ME? It does not look like it since I do not see it installed in your registry. Goto C:\MGtools and double click on analyse.exe and when you get the pop up license agreement, make sure you accept it. After doing this, you can just exit HijackThis.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. ds11com

    ds11com Private E-2

    Hi Chaslang!
    Thanks for the quick response.
    Here's my reply to what you requested:

    1) "allow Windows to automatically manage the virtual memory"
    I see how to change it, but should I do it right off the bat or wait until the "virtual memory low" window reappears? This just recently started happening, which I think is a result of the malware. It happened again today.

    2) You wrote "normal results!" under my AVG Anti-virus Test Result. Is that normal because of this malware, since I figured any reading error is a bad sign.

    3) You're right about no protection for my system. As soon as I clean everything out, I will immediately start protecting it. Do you suggest I follow the "How to Protect yourself from malware!" thread you wrote? I've lost 2 computers from Malware in the past, and I don't want to make anymore mistakes! I'm willing to pay for the right software as long as it will be the best protection, so I was thinking about the Symantic AV and Firewall combo.

    4) I attached the Avenger Log and MGLogs.zip. When running GetLogs.bat, at the end, an error popped up called "ProcessDLL.exe - Application error" that said "The application failed to initialize properly (0xc0000135). Click OK to terminate the application."

    Once again, THANK YOU GREATLY for taking the time out of your day to help me with this!

    Dmitry
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It you do not have it set to allow Windows to manage it for you then change it now.

    No! It is normal to not be allowed to access these file because they are protected Windows system files.

    We will get to the How to protect yourself thread in a moment. But no I don't recommend that you use Symantec. In fact you even need to uninstall the below which Symantec never properly uninstalled:

    LiveUpdate 2.0 (Symantec Corporation)

    This error message is explained in the Using MGtools link given in the READ ME. You don't have the Microsoft .NET Framework software installed from Microsoft Update.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
    Last edited: Mar 9, 2008
  5. ds11com

    ds11com Private E-2

    Hi chaslang,
    Everything seems normal when the computer starts, but the "virtual memory" issue is definitely new and worse. I lost a word document, because MS word just randomly disappeared, I'm assuming due to low memory. When I open task manager, "PF Usage" is almost at it's highest. I've already changed it to allow Windows to manage.

    "No! It is normal to not be allowed to access these file because they are protected Windows system files."
    -Maybe I'm not getting this, but I ran AVG Anti-Virus, and the test took about 45 seconds to run. It's probably because, for the object C:\, it says "cannot open, not checked." I'm not understanding how this could be normal?

    "In fact you even need to uninstall the below which Symantec never properly uninstalled: LiveUpdate 2.0 (Symantec Corporation)"
    -If it's not in Add/Remove programs, how would I uninstall Symantec?

    "This error message is explaing in the Using MGtools link given in the READ ME. You don't have the Microsoft .NET Framework software installed from Microsoft Update."
    -Do you suggest I install MS .NET?

    Also, I still can't run Spybot, because of the low memory.
    After it closed on it's own, I tried to re-open Spybot and couldn't. I get an error message, and it tells me Spybot has changed since the last time I used it, and I should check for malware.

    One quick general question, is it possible to start from scratch on the computer, if I don't have the original Windows XP CD for my computer (I'll obviously copy all documents beforehand to a cd).

    Thank you chaslang!!!!! This has been a huge headache, but I'm so happy there are other's who know what to do!
    -Dmitry
     
    Last edited: Feb 5, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please make proper use of quote boxes like I'm doing below.

    Post your problems and questions about Virtual Memory in the Software Forum.

    All you previously said was the below could not be accessed:

    Try this: Norton Removal Tool (SymNRT)

    You should or you will have problems running any applications that require .NET and each day many more are being written.

    Uninstall Spybot and wait until you get your Virtual Memory issues resolved before trying it again. But note that this is more than likely not malware. It is often cause by having multiple protection programs locking your hosts file. However it could also be due to the fact that your are running Spybot - Search & Destroy 1.4 which is not what we asked you to install in the READ & RUN ME. Uninstall the old version which did also have a bug that cause this problem to occur. There was an update that fixed this problem in 1.4 though.

    If you do not have a Windows XP CD, how do you plan on reinstalling. Do you have a Recovery Partition or a Recovery CD from your PC manufacturer?
     
  7. ds11com

    ds11com Private E-2

    Done!
    Thanks again for all your help. For virtual memory, I'll post on the software forum. But when I clear this up, do you think I'll be able to do a virus scan with AVG Anti-Virus; I checked today and it still says "Cannot open, not checked" when accessing the C drive, which essentially means I can't scan. Maybe reinstall AVG?

    Best,
    Dmitry
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Virtual Memory has nothing to do with AVG not being able to scan the C drive. Are you sure it cannot scan the C drive. Previously it did start scanning because you gave me the below output which means it was scanning. It just could not access certain files which is normal.
    Try scanning again and if you have problems, don't translate the messages into your own words. Give us the exact log of what AVG is saying.

    However in answer to your quesion, yes you could try uninstalling, rebooting, and reinstalling AVG.
     
  9. ds11com

    ds11com Private E-2

    Hi Chaslang,
    After I completed everything you mentioned, everything was returning back to normal up untill the following issues occurred: (keep in mind, I've only been using this computer recently to check email)
    -Internet Explorer doesn't load. It only loads after I've clicked on it a few times. But each click shows a running process in task manager.
    -When I insert a USB Driver, I can see it's being read, but it doesn't appear in My Computer.
    -The Computer is giving problems when shutting down> I get a bunch of "end program now" requests.

    I went back to "READ AND RUN ME FIRST" and through each step, up until I reached the installation and execution of COMBOFIX. When I pasted ""%userprofile%\desktop\combofix.exe" /killall" and combfix loads, my computer automatically restarts. I tried twice and it keeps shutting down and restarting.
    I also ran VundoFix just in case and nothing came up.

    Thanks again Chaslang
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It has been a month snce you last posted here. Even in a 2 week time frame it is necessary to start the READ & RUN ME process all over again since so much can happen. Your current problems (at least some of them) may not have anything to do with malware but the only real way to know is if you run all steps and attach all new logs. Make sure you follow the current version of the READ ME and download tools again since you would be out of date if you use the ones you previously downloaded. We no longer use AVG Antispyware. Make sure you run SUPERAntispyware before trying ComboFix. You can try running ComboFix in safe mode and if it does not work, just skip it and continue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds