Windows XP Laptop Malware/Virus Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by cpfms, May 10, 2010.

  1. cpfms

    cpfms Private E-2

    I am working on my sister-in-laws Toshiba Laptop w/ Windows XP, SP2. She broght it to me a few days ago and the computer would prev not fully boot into XP. There were a lot of errors loading progs. I did use a AVG rescue cd and kaspersky rescue cd prior to finding your guide and was able to at least boot into XP fully, but i was still unable to do anything in a normal boot. I also cannot connect to the internet on the laptop, but it is right here next to my desktop for any dloading i have to do.

    When loading XP in normal boot the computer runs very slow and gives an error about the Virtual mem being low and needing to configure more virtual mem. The processor is not actually doing anything and i am unable to open task manager, control panel, or my computer. Basically it just sits there doing nothing. I have to hold the power down to turn the computer off. I have done a clean boot and finished the steps in the read me first guide. My logs are below. I was unable to dload the mgtools though due to a broken link in the guide and i was unable to find it anywhere else on the web.

    Logs to follow.
     
  2. cpfms

    cpfms Private E-2

    Logs #1
     

    Attached Files:

  3. cpfms

    cpfms Private E-2

    Log #2
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    More likely to be non-malware issues, but we need the final log to be sure.

    The link is just fine. Please try again and the only place to get the proper download is from Major Geeks! We need the MGlogs.zip file to continue.
     
  5. cpfms

    cpfms Private E-2

    Sorry it took so log. Had to go to work. Here is the last log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try to do the below in normal boot mode. If you cannot run the fix in normal boot mode, then use safe boot mode.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: FrostWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Policies\Explorer\Run: [XRxCO5XIMu] C:\Documents and Settings\All Users\Application Data\lepihafu\xspcnive.exe

    After clicking Fix, exit HJT.

    Uninstall the below software:
    Ask Toolbar <-- should have been uninstalled in step 5 of the READ ME
    Java(TM) 6 Update 4

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it:
    Code:
    KILLALL::
     
    RenV::
    c:\program files\Adobe\Reader 8.0\Reader\Reader_sl .exe
    c:\program files\AIM\aim .exe
    c:\program files\AIM\AIM95_c1\aim .exe
    c:\program files\America Online 9.0\AOL .EXE
    c:\program files\Common Files\AOL\1131163763\EE\AOLHostManager .exe
    c:\program files\Common Files\AOL\1131163763\EE\AOLSoftware .exe
    c:\program files\Common Files\AOL\ACS\AOLDial .exe
    c:\program files\iTunes\iTunesHelper .exe
    c:\program files\Java\jre1.6.0_04\bin\jusched .exe
    c:\program files\ltmoh\Ltmoh .exe
    c:\program files\Messenger\msmsgs .exe
    c:\program files\Real\RealPlayer\RealPlay .exe
    c:\program files\Synaptics\SynTP\SynTPEnh .exe
    c:\program files\Synaptics\SynTP\SynTPLpr .exe
    c:\program files\TOSHIBA\TOSCDSPD\toscdspd .exe
    c:\program files\TOSHIBA\TOSHIBA Applet\thotkey .exe
    c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView .exe
    c:\program files\TOSHIBA\Touch and Launch\PadExe .exe
    c:\program files\TOSHIBA\Tvs\TvsTray .exe
    c:\windows\system32\DLA\DLACTRLW .EXE
    
    File::
    C:\Documents and Settings\All Users\Application Data\lepihafu\xspcnive.exe
    c:\windows\system32\vtsqn.exe 
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\lepihafu
     
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{BA52B914-B692-46c4-B683-905236F6F655}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
    "XRxCO5XIMu"=
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "MsSecurity1.209.4"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now if you could not do the above part of the fix in Normal Boot Mode, make sure that you try again now to continue with the below in normal boot mode.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. cpfms

    cpfms Private E-2

    I am unable to install java in safe mode and normal boot is still giving me a virtual mem low error and i cannot do anything from a normal boot. Here is the combofix log for the time being. I will try to install java from a clean boot tonight after work.

    Thanks for the help
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please provide exact word for word messages. This may not be a malware issue. You could try the below. Not sure it will help.

    Right-click My Computer and choose Properties. Click the Advanced tab. Click the Settings button in the Performance panel. Click the Advanced tab in the Performance dialog. Click the Change button in the Virtual memory panel. Whew! This setting is buried quite thoroughly! Look for the System managed size option, select it if it isn't already selected, and then click OK, OK, OK.



    Not sure what you did with the Rescue disks but it looks like you may be missing a variety of drivers required for your hardware. For one thing, it looks like no network devices are being found which is why you cannot connect to the internet. You will likely need to reinstatt this: REALTEK Gigabit and Fast Ethernet NIC Driver

    Who knows what other required drivers for the laptop have been removed or corrupted. It may more reliable to reinstall.

    Please provide the new log from MGtools even if it must be in safe boot mode but try normal boot mode.
     
    Last edited: May 13, 2010
  9. cpfms

    cpfms Private E-2

    'Your system is low on virtual memory. Windows is increasing the size of your virtual memory paging file. During this process, memory requests for some applications may be denied."

    I changed the virtual mem back to the system managed setting and that seems to be helping a little. I am running a chkdsk now.

    Here is a mgtool log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean, but you should uninstall the below junk from AOL that noone wants, needs, or uses:

    Viewpoint Media Player

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. cpfms

    cpfms Private E-2

    Thanks again for all of your help. After following all of your steps I am still having issues with booting into normal mode. It takes a lot longer to boot up now and I cannot run task manager, internet explorer, or open the control panel. I also cannot enable windows firewall. Any suggestions?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Chaslang will be away for a few days, but from what I am reviewing, I believe he would suggest you post in the software forum for further assistance. He did mention that you appear to be missing drivers and possibly other needed system files. Two suggestions:

    1) go to start / run / type:
    sfc /scannow --> have your windows disc handy.
    2) try a repair installation.
     
  13. cpfms

    cpfms Private E-2

    I am unable to run sfc /scannow from the computer. It gives me an error about a RPc server not available.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software forum. Again, you may need to do a repair install. You can get some other opinions about your issues in that forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds