Virus/Trojan That stops Regedit+TM+access to some files

Discussion in 'Malware Help (A Specialist Will Reply)' started by Turok, May 25, 2010.

  1. Turok

    Turok Private E-2

    Help me my REGEDIT and TM are still locked i was unlocking it with a program during one of the scans so it worked.. pLease help me im still infected!

    these are the logs i have

    # SASlog.txt log from SuperAntiSpyware.
    # Malwarebytes Anti-Malware log
    # ComboFix.txt (normally C:\ComboFix.txt)
    # RRlog.txt (from RootRepeal)
    # MGlogs.zip
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    NetSvc::
    xryjdspwp
    
    File::
    C:\Program Files\Smart Virus Remover\Smart Virus Remover.exe
    
    Folder::
    c:\program files\Smart Virus Remover
    c:\program files\Messenger Plus! Live
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please run this: GMER - running with a random name and attach the log from GMER.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  3. Turok

    Turok Private E-2

    getlog.bat doesn;t do anything since my REGEDIT is still locked from usage regardless of anything..after clicking "registry editing has been disabled by your administrator" 10 times it starts to say some temp file not found blablabla


    EDIT MGLOG SCAN WORKED
     

    Attached Files:

    Last edited: May 25, 2010
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only reference is in your HJT log. Let's do it again. Make sure no AS or AV program is running to bloke the fix.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now tell me how confident you feel about going into your registry?

    Attach the new HJT log.
     
  5. Turok

    Turok Private E-2

    it gets redisabled the second i click fix lol.. and the getlog.bat doesn;t work still

    the thread line O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    reappears 5 seconds later again when i do a SCAN from HJT.. so nothing is happening
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run Defogger as requested in step 6 of the READ & RUN ME to disable your disk emulation software. You need to keep this disable until your problems are resolved.


    Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v
    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Turok

    Turok Private E-2

    I cant seem to find the download link of TDSSKiller anywhere i checked on 3 different trusted sites tried it on another pc and on both IE and FIrefox download link is dead..
     
  8. Turok

    Turok Private E-2

    i downloaded TDSS from a link given through bleeping computers the file was named TDSSKiller_2.0.0 RC3.exe so i renamed to the one that the /run has and it enteredd a box then typed

    All the results where 0/0

    it then tells me press any key to continue after i press a key it then exits the dos prompt and doesn;t even create a log file..
     
  9. Turok

    Turok Private E-2

    My Registry is still disabled even after the scans etc.. and my Task Manager also my ill put in the TDSSKiller logs just for more information and i have the other ones u requested also. Note i disabled the System Restore since it was advised to me on your Help Thread

    NOTE on TDSKiller: I never reached to the DELETE PART since all was 0/0
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try it again.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\Admin\Local Settings\temp\4.TMP
    
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"= 0 (0x0)
    "DisableRegistryTools"= 0 (0x0)
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  11. Turok

    Turok Private E-2

    There are some errors happening with combofix i can only run it once per time then i have to delete it then redownload it to use it since an error comes the 2nd time i try to use the same COMBOFIX with dragging a file on it. 2nd combofix keeps installing windows restore console, it tells me it must install this in order to proceed and if it doesn;t it wont proceed so it downloads it from microsoft then the starts to something then it tells me something about a boot drive or something like this not being found then it asks if i want to scan for maleware i press ok then it starts then resets my PC and makes a log. My registry is still being locked and my taskmanager i keep using RKILL to help it and when i used to MGlogs tool scan it kept pressing "YOU DONT HAVE ACCESS TO REGISTRY " i Rkilled then i pressed "OK" on the error message like 20 times in order for the scan to go through.. The HIJACK this did nothing to the LOCKs and the COMBO fix did nothing to the LOCKS.. and for some reason everytime I reset PC my firewall is DISABLED, if i put DISABLE all system restore for both drives they both get re-enabled, and everytime i press show hidden files it still goes to Hidden. and i even used other things to bypass the hidden thing and it doesn't work
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try something a little different. First go into your user accounts and change one of them so that it has Administrative privileges. Then log into that account and go to start / run / type:
    regedit and tell me if your registry opens.
     
  13. Turok

    Turok Private E-2

    I have full admin access and there is no guest account i even checked in computer management and Users even when i press switch users the only thing i see is ADMIN. And i am computer administrator i have no guest accounts created.
     
  14. Turok

    Turok Private E-2

    i even did Start>>Run>>gpedit.msc>>System>>Prevent Access to Registry Editing Tools (set this to DISABLED) and it is on Disabled and it still doesn;t work rofl :S I also

    In computer management Services --> REMOTE REGISTRY: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. I also stopped this and i cant even regedit+TM...
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have multiple users on this account, but only the one account that has admin. privileges:
    Code:
    Users on this computer:
    Is Admin? | Username
    ------------------
       Yes    | Admin
       Yes    | Administrator
              | Guest
              | heave
              | heave1
              | HelpAssistant (Disabled)
              | postgres
              | postgres1
              | postgres2
              | postgress
              | SUPPORT_388945a0 (Disabled)
    What I suggested was to change one of the above to have admin. privileges and see if you are still blocked.
     
  16. Turok

    Turok Private E-2

    I tried that it still doesn;t work i edited Heave and made it admin privileges as i was logging off ADMIN to enter heave i got an error about netch.exe as i entered Heave i ran regedit.exe and it still displays same message.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bummer.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now double click C:\MGtools\Regfix.bat

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip
     
  18. Turok

    Turok Private E-2

    it made an error so i didn;t press execute

    error:invalid registry syntax in command:
    "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system | DisableRegistryTools"
    Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program.
    Skipping line. (Registry value deletion mode)
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Crap...sorry, I forgot.

    Use windows explorer to find:
    C:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\regedit.exe
    Right click the regedit.exe and then copy and paste it directly on your C:\ drive ...so you have C:\regedit.exe

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    Driver::
    abp470n5
    
    File::
    c:\windows\system32\drivers\omhgun.sys
    
    FCopy::
    C:\regedit.exe | C:\WINDOWS\system32\dllcache\regedit.exe
    
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=-
    "DisableTaskMgr"=- 
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  20. Turok

    Turok Private E-2

    i did what you said .. and unfortunately TM+REGEDIT still Disabled. I noticed an error after ComboFix was downloading Microsoft Restore Services since it wouldn;t start without it .. lol this is the 6th time it Installs this thing :S... anyways after it downloaded it this error appeared

    "Boot partition cannot me enumerated Correctly"

    it then asked me if i would like to scan for malware i clicked yes and proceeded with the Task.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do this:
    ?
     
  22. Turok

    Turok Private E-2

    no but... even now when i try pressing (regfix.bat) it does nothing it gets a cmd screen and then vanishes it appears for like 0.3 seconds with nothing on it.. the mglog scan still says registry is disabled blablabla
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am going out on a limb with this one, so please create this disc and boot to it when ready:
    Kaspersky Rescue Disk.

    Tell me if it finds anything.
     
  24. Turok

    Turok Private E-2

    im downloading the kaspersky cd atm but i just noticed that when i put regfix.bat into a CMDPROMPT it says file: "fixchode.reg" doesn;t exist and the file is there :S i also click on the script to enable regedit and press fixchode quickly and it says the same thing. i also tried clicking the script fast then the fixchode.reg and press yes to put the file in the folder then proceeded it still did the same :S.

    Anyways i just wanted to ask is my PC infected since i scanned it with SAS and it found only 2 results the TM lock +REGEDIT Lock, is it safe to type my username+password in my online gaming accounts such as diablo2 and other games is it safe to type username passwords anywhere im scared of a key log or something of that sort this virus could use?
     
  25. Turok

    Turok Private E-2

    one more question is it possible i have Sality virus ??
     
  26. Turok

    Turok Private E-2

    Btw i deleted all my anti virus+firewall software at the beginning of this thread since they where infected.. should i install new ones like AVAST and firewalls like Sunbelt, and Comodo is it safe for me to download these and use them or should i wait till the PC is cleaned b4 downloading that
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do what I requested in my last message and download and run the version of TDSSKiller exactly as I requested. Running and old/outdated copy is not going to help you. Please follow my instructions and download it from the link I have you in my message. Links are in blue
     
  28. Turok

    Turok Private E-2

    Link is broken maybe give me an alternate one? I clicked the blue link 10 times all that comes is cannot find server.. i tried it on my other pc it says the same thing.
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The link works just fine. Either try again or use another PC to download it.
     
  30. Turok

    Turok Private E-2

    it is the virus that is disabling me from entering that link can u maybe upload the file i must download here please ?:O
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  32. Turok

    Turok Private E-2

    Ok I did what you told me but let me warn you. During the TDDS it said 0 of 0 I didn't get to type DELETE it said press any key to continue then it went out.. and for the MGT scan i kept having to click the script that enables access to regedit like 30 times in order for the scan to do its job.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay. Using the current version was important just to be sure you do not have the TDSS infection.

    Do you still have your Disk Emulation software (Daemon Tools) disable as requested? Your last logs seem to indicate that you download it but did not run it or renabled it.

    Please run this: Resetting Registry and File Permissions


    Now run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

    After clicking Fix, exit HJT.

    Now please run the 32 bit version of AVG's removal tool to cleanup additional items from AVG: http://www.avg.com/us-en/download-tools

    Now let's clean up some things including some more left overs from AVG being broken and also some files that you have been saving where they do not belong.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    NOTE: You appear to be missing your c:\boot.ini file which is likely why you are seeing that message saying Boot partition cannot be enumerated Correctly

    You will need to fix this in the Software Forum if necessary but the Resolution section in the below link tells you how to do this with your boot CD.

    http://support.microsoft.com/kb/330184
     
    Last edited: May 27, 2010
  34. Turok

    Turok Private E-2

    i Did everything you told me but the problem is in that REGISTRY repair windows thingy. I did it and then reg edit was enabled. But then when i Ran Combo fix a windows explorer error appeared i didn;t touch it and let combo fix finish.. but it didn;t i guess since my pc just froze and all i could see was my wallpaper but nothing else.. no TASKBAR no ICONS no nothing.. I waited 3 minutes and nothing happend so I resetted my PC manually and guess what happend next.. REGEDIT is LOcked again... so i tried doing the registry windows thingy again and now it stops and doesn't finish.. I dont understand I had the Windows Recovery Disabled from properties/Mycomputer disabling C+D. but after the reset they get enabled and so i keep disabling them. anyways ill give u the logs.

    But i am happy with the support I am getting it is unbelievable :O. I thank you guys with all my heart!

    NOTE:ComboFix didn;t make a log since it errored
     

    Attached Files:

  35. Turok

    Turok Private E-2

    i redid the combo fix and my REGEDIT+TM still locked
     

    Attached Files:

  36. Turok

    Turok Private E-2

    i quick scanned with MBAM just to make sure all it found was this
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the READ & RUN ME, please refrain from doing anything but what we ask you to do. We never asked you to disable system restore. Also you are running and doing other things not requested. You must only do what we ask and nothing else. No repeated runs. No other scans. No other surfing...etc.

    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  38. Turok

    Turok Private E-2

    ok i did what u asked of me Regedit+TM still locked and windows firewall is getting changed to off. Btw i have no current software Anti Virus+Firewall since im scared the virus will infect the Exe files some way and i get re infected.
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the below file keeps getting recreated:

    c:\windows\system32\drivers\omhgun.sys

    Also the below driver keeps being found and deleted by ComboFix

    ABP470N5

    It looks like you have a Sality infection. And I just noticed you mentioned this earlier in the thread. Did you have a scanner saying anything about this infection? You may have many system files infected. Even one of the keys I just had you delete with ComboFix ( [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ) is from Sality.

    Please run the below removal tool from Kaspersky

    http://support.kaspersky.com/faq/?qid=208279889

    After running the above, repeat my previous instructions again and attach new logs from ComboFix and MGtools.
     
  40. Turok

    Turok Private E-2

    i cant enter the link remember :O can u upload the removal here
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be able to get to the link to follow the instructions there. It is not legal for us to post them here. Try using another browser or another PC so that you can follow the instructions.
     
  42. Turok

    Turok Private E-2

    I downloaded the remover from

    http://www.avg.com/tr-tr/virus-removal.tpl-crp.ndi-67769

    http://free.avg.com/ww-en/win32-sality

    I uploaded the removers log located in the Zip
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not the removal tool that I asked you to run and based on your logs I'm guessing you still have a problem?
     
  44. Turok

    Turok Private E-2

    yes my TM+Regedit are still locked. Dont worry if anything gets fixed i'd be screaming and jumping :p and basically capsing like crazy
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes a few infected files probably caused the whole infection to come back which means something addition is hiding or there are still many many infected system files.

    Please run : GMER - running with a random name just like you did earlier and attach a new log. Make sure that you have not reenabled your disk emulation sotware otherwise the log will be of no use to me. If I still see Daemon Tools running in this log, I will be asking you to uninstall it and then we will be forcefully removing any leftovers to get it out of our way.

    Also see if you can use another browser and run the Kaspersky removal tool for Sailty. The AVG tool was useless as it found nothing.
     
  46. Turok

    Turok Private E-2

    I pressed the scan and did the procedures the scan was only 6 lines or so anyways i couldn;t find another version of the Sality remover i looked everywhere
     

    Attached Files:

    • LOG.log
      File size:
      584 bytes
      Views:
      2
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to find another version. I asked you to try running the Kaspersky one again from the link I supplied and I asked you to try using a different browser to access it. For example, if you have been using Internet Explorer, try using FireFox. Or if you had been using FireFox, try Internet Explorer.

    There are several different websites that provide tools for attempting to remove Sality, but I want you to run the one from Kaspersky.


    Also do the below.

    Download the Registry Search Tool from here: http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    • Unzip to your Desktop and double click on regsrch.vbs
      (if you have script protection, please allow this to run)
    • In the dialog that opens enter the following:
    omhgun
    • Press 'OK'
    • The search will run for a while then alert you when it is finished.
    • Press 'OK' and copy the contents of the WordPad window and post in this thread.
    If you still were not able to run the Kaspersky Tool, please try running the below Online Scan from BitDefender and attach the log from it here:

    http://www.bitdefender.com/scanner/online/free.html
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot! Some of your system files appears may have been replaced by a bad copies. I want to search for a replacement copies just in case. But did you update your Nvidia drivers in April this year? It could just be that the updated versions have much larger file sizes now.


    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1


    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
    Code:
    :filefind
    nv4_mini.sys
    nv4_disp.dll

    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
    Last edited: May 29, 2010
  49. Turok

    Turok Private E-2

    Ya i downloaded new drivers like a month ago or 1.5 months ago
     

    Attached Files:

  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that would explain why the Nvidia files have changed.

    You need complete what I requested in msg # 47
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds