cannot d/l or run the programs from the 'Do this first' list. I do have a HJT though.

Discussion in 'Malware Help (A Specialist Will Reply)' started by x337x, Aug 14, 2009.

  1. x337x

    x337x Private E-2

    As stated, whatever has got a hold of my system is blocking 90% of programs from running. I can get the programs from another machine, put them on a flash drive and copy/paste them, but the .exe is still affected. I did all of the cleaning sticky I could, but here we are. what next?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Welcome to Major Geeks!

    Are you 100% sure that you tried to run ALL programs including the last one mentioned which is MGtools.exe? Did you also try to run them in safe boot mode?


    If you don't give us any logs to get started on then there is not much we can do for you except say:
    • take the hard disk out and scan it in another well protected PC
    • use another PC to make a CD like UBCD4Win and use it to boot your problem PC and scan it.
    • reinstall
    Also note that if you are impying the EXE files are getting infected as you copy them to your PC, then you may have a Virut or similar PE file infected and you will need to reinstall anyway. In addition, the flash drive you were using and any PCs it has been plugged into, could be infected now.
     
  3. x337x

    x337x Private E-2

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Actually I was able to run MGtools. I just couldn't post until I got a response. The bug seems to get worse the longer the machine is on, so as soon as I boot I can run a program or two if lucky. I have not been able to get it to boot into safe mode though, which is odd in itself. I'll attach the MGtool log. Thanks.

    Also, this is my work computer with all my files which were about to be backed up, then this happened. I'm a graphic artist and there are way too many hours in this machine to chance a reinstall. Thanks for helping.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    You need to delete the below files and you must stop downloading and saving files here. This folder is for Windows not for you. ;) In addtion, we specifically stated the MGtools.exe needs to be save to the root folder as C:\MGtools.exe
    Code:
    C:\WINDOWS\
    ccsetu~1.exe  Aug 15 2009     1033448  "ccsetup222_slim.exe"
    mbam-s~1.exe  Jul 10 2009     3561744  "mbam-setup.exe"
    mgtools.exe   Aug 15 2009     1343913  "MGtools.exe"
    supera~1.exe  Aug 15 2009     6881824  "SUPERAntiSpyware.exe"
    
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: C:\WINDOWS\system32\gsf83iujid.dll - {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - C:\WINDOWS\system32\gsf83iujid.dll (file missing)
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [PPMemCheck] K:\OLDPRO~1\PESTPA~1\PPMemCheck.exe
    O4 - HKLM\..\Run: [PestPatrol Control Center] K:\OLDPRO~1\PESTPA~1\PPControl.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [CookiePatrol] K:\OLDPRO~1\PESTPA~1\CookiePatrol.exe
    O4 - HKCU\..\Run: [NTSystem] C:\Program Files\Common Files\Microsoft Update Engine\services.exe
    O4 - HKCU\..\Run: [net] "C:\WINDOWS\system32\net.net"
    O4 - HKCU\..\Run: [] C:\DOCUME~1\Owner\LOCALS~1\Temp\qvu3rbvgl4.exe
    O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\Owner\LOCALS~1\Temp\csrss.exe
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: ,C:\DOCUME~1\Owner\LOCALS~1\Temp\420392156634mxx.dll
    O22 - SharedTaskScheduler: rtasgvfu76ew8ndkfno94 - {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - C:\WINDOWS\system32\gsf83iujid.dll (file missing)
    O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
    O24 - Desktop Component 0: (no name) - http://extras.mnginteractive.com/live/media/site525/images/backgroundgray.gif

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    See if you can run SUPERAntiSpyware, Malwarebytes, ComboFix and RootRepeal now.
     
  5. x337x

    x337x Private E-2

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Well, it took some fiddling to get this far. (restarting, trying safe mode, etc..) I was unable to open my "Unistall Programs", the list just never populated, so I just deleted all the Java folders I could for now. I realize it's not the same function, but it's all I could manage.

    I seriously appreciate your time. Thank you.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Bad idea. You should only do what we ask you to do. Now you will not be able to uninstall them at all. Sometimes shutting down your antivirus program will speed up loading of the add/remove programs list; however, your problem may be due to something else blocking the list from showing since it is not showing in the logs either. I do see a little more to remove which we will do below.

    Why did you rename MGtools.exe to MGtools(2).exe . You should rename it back properly so that final instructions will work properly.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now try to run SUPERAntiSpyware, Malwarebytes and ComboFix per the cleaning instructions.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • the logs from SUPERAntiSpyware, Malwarebytes and ComboFix if they ran
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. x337x

    x337x Private E-2

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Alright, things seem to be back to normal. I think the last avenger run may have opened the door, as soon as it rebooted I was able to run Mbam, Combofix, and SASW for the first times. Here are the logs.

    I can't seem to locate SASW's log, if you need it, I'll run it again.

    A million thank yous!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Your SUPERAntiSpyware log is as show below. Please attach it.
    Code:
    "C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Sep  2 2009    5792 "SUPERAntiSpyware Scan Log - 09-02-2009 - 14-59-31.log"
    You need to put Combofix.exe on your Desktop as requested or you will not be able to follow the below instructions. In fact, make sure you download the current version to your Desktop and just delete the old file.

    Also you are way out of date with Malwarebytes. You need to run it and first select Update. Then run a new scan and fix anything it finds.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • the SUPERAntiSpyware log
    • the new log from Malwarebytes
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. x337x

    x337x Private E-2

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Combo fix stalls at 23. I was careful to exit all other programs, and I followed instructions to the letter. It's the newest version also. I even opened both the task manager, then msconfig to check if there were anything running that may have been hidden. Tried it on a fresh restart a couple times, etc... always stalls at line 23.

    Let me know what I should do next. Thanks.

    I'll attach the three other logs requested in case they might be of help. Thanks again.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Okay let's try a different fix.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now since your copies of SUPERAntiSpyware and Malwarebytes are out of date, let's do the below to be safe.

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.


    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Owner\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. x337x

    x337x Private E-2

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    I really appreciate you taking time from your weekend to help.

    Everything from this session ran fine, the comp is running well, here are the logs:
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    You're welcome.

    Your logs are clean. Just delete the below left over file from ComboFix:
    C:\WINDOWS\system32\CF26434.exe

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. x337x

    x337x Private E-2

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    Thanks Chas. Things do seem to be normal again. At least I got to backup all my work, and I'm doing backups after every session now. All of my programs are on disc, so if something bad happens again I'm just going to write to zero's and start over :) I appreciate your time very much. Cheers.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: cannot d/l or run the programs from the 'Do this first' list. I do have a HJT tho

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds