Infected with something that the procedure would not remove.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fuelman, Oct 25, 2008.

  1. Fuelman

    Fuelman Private First Class

    OK folks, this thing has been plaguing me for several days now.
    I ran the malware removal procedures for XP, to no avail.

    This problem started when I noticed I could no longer run diskeeper lite or Super Anti Spyware. I got to run SAS by renaming the file to SAS.exe and it found a bunch of stuff.
    I rebooted the machine after letting SAS fix the problems and the machine would only boot into safe mode.
    I tried to reboot it into normal mode by both using the feature in SAS and msconfig, nothing worked, it still boots into safe mode.

    Needless to say, all of the malware removal procedures were performed in safe mode since I could not get into normal mode.

    Just so you know, I have had AVG free, SAS and Spybod S&D for quite some time and whatever the problem is that infected my machine, slipped through all that.

    I thank you in advance for your assistance.

    Brian
    aka Fuelman
     

    Attached Files:

  2. Fuelman

    Fuelman Private First Class

    The remaining attachments from the removal procedures.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You ran SAS multiple times in the last week. Please attach the below two logs from it.
    Code:
    "C:\Documents and Settings\Brian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Oct 22 2008  1586  "SUPERAntiSpyware Scan Log - 10-22-2008 - 15-14-33.log"
    Oct 22 2008   880  "SUPERAntiSpyware Scan Log - 10-22-2008 - 00-20-13.log"
    Did you forget to accept the TrendMicro HijackThis license agreement when you ran MGtools? It did not get installed and did not produce a log as it should have.


    Uninstall the below old versions of software:
    Spybot - Search & Destroy 1.5.2.20




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! If you still cannot boot into normal boot mode, I suggest that you use System Restore to return to a point in time before the problem with booting in normal mode began and then only run MBAM and C:\MGtools\GetLogs.bat again to get new logs showing your status after the System Restore.
     
    Last edited: Oct 29, 2008
  4. Fuelman

    Fuelman Private First Class

    Thanks for the help Chaslang.

    -I removed the old version of Spybot S&D.

    -I can not click on the HJT acceptance button, screen resolution in safe mode will not allow me to see the buttons to accept. I tried changing resolution but it will not let me and I can not move the acceptance window far enough up to click on it.

    -When I turned off the restore points in the "read and run me first" section, safe mode will not allow me to turn it back on and will not allow me to restore anything. It will also not allow me to remove the old Java version and install the new one.

    -Here are the SAS logs you asked for.

    I will post another message as soon as I finish running the remaining suggestions you have.

    Thanks again for your help.

    Brian
     

    Attached Files:

  5. Fuelman

    Fuelman Private First Class

    I was able to mess around a bit and get to hit the HJT "accept" on the licence agreement screen, then it ran.

    -When running HJT, it did not come up with any of the lines you asked me in your message to delete, so I did nothing but save the log.

    -the other logs you asked for are attached plus the HJT log.

    Still in safe mode, urgh....

    Thanks for your continued help.

    Brian
     

    Attached Files:

  6. Fuelman

    Fuelman Private First Class

    Chaslang,
    I tried the system restore so I could boot into normal mode. When the screen opened up there were no restore points in there!
    Now what do I do?

    Thanks
    Brian
     
  7. Fuelman

    Fuelman Private First Class

    Chaslang,
    I did what you suggested and still not able to get it into normal mode.
    I'm not sure all the malware is gone either.

    Any help at all is appreciated.

    Thanks
    Brian
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you know that each time you post a message you delay getting an answer to previous messages? If you kept doing this, you would theoretically never get an answer. Have you read this sticky?

    Don't Bump! It Only Hurts You!!!


    Please look at your C:\boot.ini file and copy and paste the contents here.
     
  9. Fuelman

    Fuelman Private First Class

    OK, I did a search for the C:\boot.ini file(s) and found two. They are both attached in a .txt format.
    There is two more under my docs and settings user account also, they did look the same, I will paste them in the next post.

    Thanks again and sorry about the bump.

    Brian
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We only care about the c:\boot.ini file.

    In this file you have the below line:

    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /safeboot:network

    Notice the last part of that line which I highlighted. This is why you are stuck in safeboot mode. Delete that part to make this line look like below:

    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    Then reboot your PC and see if you can get into normal boot mode.
     
  11. Fuelman

    Fuelman Private First Class

    Chaslang,
    I previously found the c:\boot.ini file by doing a search and then clicking on it which it opened in .txt format.

    I can not find it by using explore in the "C-drive".

    Using the windows search to find it, I've tried editing the line you mention in notepad but it will not save because the file already exists and is read only.

    Is there a box somewhere I need to check or uncheck to be able to view this boot.ini file and then be able to edit and save it?


    I guess I need to be able to get back into normal mode before you can see if my machine is still infected?

    Thanks again for your help.

    Brian
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you no longer have the viewing of hidden and system files enabled as requested in the READ & RUN ME step 1. Do this and you should be able to see and edit the file.

    Once you can see it in Windows Explorer. Right Click on it and select Properties and then uncheck the READ ONLY option. Alternatively, do the below which will make it visible and will remove the protection.

    Click Start, Run, and enter cmd and click OK. This will open a command prompt window. At the command prompt enter the below black bold print commands. Note there is a space between cd and C:\. Also there are spaces after attrib, -r, -h and -s.

    cd C:\
    attrib -r -h -s boot.ini

    Now see if you can find and edit the file.
     
  13. Fuelman

    Fuelman Private First Class

    Wow,
    That worked. Now I'm back in normal mode!!!
    I still could not find it in explore regardless of how the boxes were checked to view hidden files. Anyway its a mystery to me about how all this code stuff works. I'm a chemical engineer, not a software engineer.

    Thank you.

    ...Now, back to the malware stuff.
    The computer seems to be running a bit quicker so there must have been some good cleaning going on while it was runnning in safe mode.

    Should I reperform all the procedures outlined in the stickey to be sure?

    Once again, thank you for all your help.

    Brian
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just run SUPERAntiSpyware, Malwarebytes, and MGtools. Make sure you update SAS and MBAM before running a scan. Attach these 3 new logs.
     
  15. Fuelman

    Fuelman Private First Class

    OK Chaslang,
    It looks like it is clean if I'm looking at the logs correctly, but I'm no expert.

    The other problem I have is that XP's SP3 will not install. I do have an AMD 2600+ processor but have no idea of the motherboard setup. I've heard that SP3 and a few AMD processors have a conflict or something like that.

    Again, thanks for your assistance, its appreciated a great deal.

    Brian
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You should address problems with Windows Update in the Software Forum.


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds