Mean Virus takes over Task Manager

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chala, Feb 2, 2010.

  1. Chala

    Chala Corporal

    A virus has taken over my Task Manager. The Task Manager ALONE is taking up 85 to 94% of the CPU in the Process tab. Machine is extremely slow i am trying to conform to the "READ & RUN ME FIRST" I cannot run in normal start up i get BSOD, RootRepeal gives me a BSOD in normal mode, i can run it in safe mode though.In safe mode my machine runs fine. Can somebody please help i attached a couple of logs including a log from Process Explorer. Thanks in advance!

    Specs

    O/S: Windows XP Professional 32-bit SP3
    Processor: 3.20 gigahertz Intel Celeron
    Mother Board: MICRO-STAR INTERNATIONAL CO., LTD MS-7104 20A
    RAM 1024 MB DDR
     

    Attached Files:

  2. Chala

    Chala Corporal

    When i try and run MGtools i get an error C:\MGtools.exe is not a valid Win32 application. I am getting this with a a few programs something the virus is doing.

    Attached is a combofix log.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    See if you are able to complete the below in normal mode without getting a BSOD. You may be successful, so let's see...

    1. Use Windows Explorer to locate and delete the below bold file:

    2. Please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r

    3. Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    4. We need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    5. Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    6. Attach the logs into your next reply.
     
  4. Chala

    Chala Corporal

    First off i want to thank you so much for posting, please stay with me i will be listening and following your instructions to the letter. I already deleted the c:\windows\S8E3AE380.tmp.

    I don't have a C:\MGtools\FixPerm.bat file searched all over C:\ drive. When i tried to run MTtools.exe i get that error again which i am getting with lots od Malware removal programs C:\MGtools.exe is not a valid Win32 application. Attached is the Win32Diag.txt
     

    Attached Files:

    Last edited by a moderator: Feb 4, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, we will not abandon you don't worry, we will work with you until we are sure your machine is malware free.

    My fault, I didn't mean to include that segment of text into my post. My apologies for any confusion caused.

    Now just to be sure, can you run MGTools.exe in safe mode or is this giving you the " xxx is not a valid Win32 application" error?
     
  6. Chala

    Chala Corporal

    Not a problem I am just so glad your helping me. Sorry for the delay (work) keeps me away from the PC unfortunately but after Saturday night I will be off for a few days and will be at the computer constantly and hopefully can get this issue resolved.

    Tried running it in safe mode got the same message. Then I thought to myself delete it and reinstall it, which I did, and low and behold it worked in normal mode. Logs are attached, hope the Zip file is not a problem.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing much to do really:

    1. Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    2. Your C Drive is in a rather awful mess I see. You should place all files you put there yourself into their own folders in your my documents folder for instance.

    3. What are you using for an anti virus?

    4. Please go to Add/Remove programs and uninstall the following software:
    • Ask Toolbar

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    6. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\All Users\Application Data\vsosdk
    
    File::
    C:\WINDOWS\lgfwup.ini
    C:\WINDOWS\lgfwup.txt
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    This maybe something you have to discuss in the software forum as opposed to the malware forum.
     
  8. Chala

    Chala Corporal

    I will try and rearrange my files once this is resolved, but right now fixing my PC is a priority.

    I don't have any real time AV at this time. I just uninstalled Kaspersky trial. (Was not detecting up to my standards) I usually use online scanners.

    Ask Toolbar was not in Add/Remove


    No problem with the instructions but no change either, still slow. Task Manager is still using 100% CPU Memory.



    I am starting to think you are right, I may not have a virus, maybe it's memory or something. My whole problem centers around my Task Manager being at 100% in safe mode it's only using 2% I understand in safe mode not everything is being loaded, but safe mode running properly should rule out hardware issue so I am really confused!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why am I seeing this in your logs from 5th Feb? (I know what it is, just curious as to why you were using it yourself)

    • OTL.exe

    You really ought to install some anti virus, as surfing without any will leave you wide open to infection, and may also possibly result in you being refused any future help if you still do not have AV installed. We have a list of anti virus to choose from in our "how to protect yourself from malware" link which will be included in my final steps.
    Well it certainly shows in your logs, however let's get rid of it manually.

    1. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.
    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    ZE
    
    Folder::
    c:\program files\Ask.com
    c:\documents and settings\All Users\Application Data\Viewpoint
    c:\documents and settings\All Users\Application Data\vsosdk
    C:\Documents and Settings\owner\Application Data\AskToolbar
    C:\Documents and Settings\owner\Local Settings\Application Data\AskToolbar
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    [-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Let's just get one final look of your logs before I give you all clear.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  10. Chala

    Chala Corporal

    I know you know what it is. I was very anxious at the time and was open to all the help i could get. OTL was something another IT person wanted me to do, hope your not offended, i appreciate your help more then you know.


    Will do and thank you.



    I really don't think i have anything now, i think it's memory, my two sticks of 512MB is just not enough anymore. As soon as you give me my clean bill of health i am getting two 1Gig sticks of RAM!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not offended at all, however it does make life difficult for both the OP and me when new stuff is being installed and messed about with when in the middle of reviewing your machine. This is why we ask you specifically not to make any changes until we are done.

    Anyway :) We are done, and I can give you final steps. You can visit the software forum or wherever appropriate to work out what issues remain.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. Chala

    Chala Corporal

    Thank you so much Kestrel i really appreciate all you done for me, now a hard question, where do i go? Hardware (i probably need RAM), or Software, if you have any opinion on that please let me know and thanks a million!!
     
    Last edited by a moderator: Feb 8, 2010
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome, Chala.
    Software
    Hardware

    Go for the hardware forum to discuss RAM upgrades.
     
  14. Chala

    Chala Corporal

    Thank you again Kestrel :)
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, safe surfing :)
     
  16. Chala

    Chala Corporal

    Sorry Kestrel one last thing please? Can you take a look at these RootRepeal logs. It gives me a BSOD in normal mode, so i had to run it in safe mode, thanks!
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nothing untowards in those logs.

    Why are you running RootRepeal again?
     
  18. Chala

    Chala Corporal

    Well, I never got to run it in the first place, I think I mentioned in an earlier post that I got a BSOD in normal mode. Someone helping me now asked me to try and run it (they believe their might be a rootkit) but I told them my previous help was thorough. So I tried in safe, was just wondering what those entries were, that's all, I will be deleting it. Thanks
     
  19. Chala

    Chala Corporal


    I apologize this has been a long enduring process for me, I see I did run it, and post a log. My apologies sir!
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem. And I am a lady not a sir:)
     
  21. Chala

    Chala Corporal

    Thats why you were so kind, :) my apologies again ma'am!
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have good days and bad days :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds