Probable Malware/Spyware infestation

Discussion in 'Malware Help (A Specialist Will Reply)' started by stejampzy, Jun 5, 2010.

  1. stejampzy

    stejampzy Private E-2

    Greetings. I went to the READ ME FIRST post and followed the instructions to the best of my ability, however every single thing I do on my computer (I'm running Vista) tells me that it's unexecutable and is infected. I actually can't even get into my Control Panel to see what installed itself on my computer, but I'm assuming there must have been something?

    Basically, everything I do -- open Control Panel, open IE, open Firefox, open CCleaner, open uTorrent -- prompts me to scan with and pay for malware/spyware protection through something called antispywareprog.com and it's the only website I can access. No other programs open and I simply get a Windows Security Alert balloon that pops up from the "green shield with a checkmark on it" in my toolbar.

    I'm assuming I'll need to run some scans in safe mode or something? I'm currently accessing the web via my MacBook.

    Can anyone please help? Thank you very kindly.
    -Steve
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. stejampzy

    stejampzy Private E-2

    After trying a few more times, I can now open my Control Panel. There doesn't seem to be anything "extra" in there that I didn't personally download, and from what I can tell I only have one piece of Antivirus software. I generally use CCleaner on a nearly daily basis to clean out excess crap but it won't load now and, again, "Windows" tells me there is spyware afoot.

    To re-clarify, I haven't actually tried to start in Safe Mode. That is, generally speaking, beyond my level of expertise when it comes to computing.

    With this new info, are there any other ideas you can offer from the get-go?

    Thanks again. I really appreciate your time and help.
    -Steve
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may become necessary to try if you cannot run things in normal boot mode.


    It all depends on what you can run. Can you run our cleaning procedure: READ & RUN ME FIRST. Malware Removal Guide
     
  5. stejampzy

    stejampzy Private E-2

    Hello. Thanks for your help.

    Based on the READ & RUN ME FIRST file, here is what I have been able to accomplish/figure out:

    -I only have 1 piece of antivirus software

    Housecleaning
    -I didn't have any of the listed programs to remove
    -I could not update in Java in normal mode because my internet access is being pirated by something.
    -Quarantines and Recycle Bin emptied
    -I have CCleaner, but can't run it.

    Config & Setup
    -I have a 32 bit version of Windows.
    -I have enabled viewing of hidden files, etc.
    -I cannot access msconfig. A red X comes up and says, "Application cannot be executed. The file msconfig is infected. Do you want to activate your antivirus software now?"

    -No Malware and Unwanted Software to remove based on the list in step 5

    -I could not access the disk emulation software in step 6, because I can't get to the website.

    -I could not run thru the Vista cleaning procedures because I can't access the internet properly.

    I haven't tried booting in safe mode as of yet, but am happy to at your direction. My Vista PC is disconnected from the internet presently. About every 3-4 minutes my Windows Security Center pops up and says everything is running OK, but at the same intervals I also get red X balloon's that pop up and tell me my computer is infected.

    Best regards,
    -Steve
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if the reason behind this is the below:

    Proxy Server - Changing Settings


    Can Task Manager be opened?

    If downloading the tools is a problem with this PC, download them on another PC and burn to a CD to use in copying to the infected PC. Yes you could use a flash drive but they can be infected and spread infections elsewhere, so only use a flash drive if you cannot burn to a CD. You will need another PC to do this. Hopefully you have one you can use because I may need to have you create a special boot CD.

    Yes you need to try this now. Some of these infections will even break the ability to get into safe mode. If one form of safe mode does not work ( like safe mode with networking, try each of the 2 other types of safe mode boot ).

    Is this a laptop or a Desktop?

    Do you have your Vista boot DVD?
     
  7. stejampzy

    stejampzy Private E-2

    Hello.
    I was able to do a few things, but not everything, on the Vista cleanup page.

    To answer your question, this is a desktop computer and I don't know where my Vista boot DVD is, though I'm sure it's around here somewhere. :-o

    I was able to run SUPERAntiSpyware in safe mode, and have attached a log for it. It cleaned a few things up and now I am able to access the internet "normally" again on my PC.

    The other four fix-it programs all failed for various reasons.

    MB downloaded to my computer but when I tried to run it told me "The setup files are corrupted. Please obtain a new copy of the program."

    ComboFix downloaded fine, but when I tried to run it said, "Windows Command Processor has stopped working" and the operation was automatically aborted.

    Root Renewal downloaded, but gave me an error that read, "DeviceIOControlError! Error Code = OxO"

    MG Tools would not download completely and kept getting blocked out by my AVG program. I tried shutting it off several times, but was unable to do it successfully.

    I have a feeling I need to restore a few settings from where I was still, but I can't figure out what and where. Any ideas?

    Thank you, chaslang, for your help.
    Best regards,
    -Steve
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes as stated in the cleaning procedure, some antivirus programs are problematic and decide that MGtools is a problem when in fact the antivirus program itself is actually more of a problem. You need to uninstall AVG and then run MGtools, preferable in normal boot mode.

    Not sure what you are referring to. You need to finish verifying your system is clean before doing anything else.
     
  9. stejampzy

    stejampzy Private E-2

    I uninstalled AVG and then attempted to run MGTools. It gave me an error reading "Virtual device driver error message in 16-Bit MS-DOS subsystem". I tried to work around it with support from Microsoft (since the possible errors listed on the Using MGTools page only lists XP and 2000, and I run Vista) but it told me to try downloading a patch for XP, and I was hesitant to do so since I'wasnt sure if you'd suggest something else?

    Additionally, when I tried to run ComboFix it kept telling me that my Norton Antivirus Internet was running. This isn't a program I've downloaded (it's not in Control Panel), so I don't know how to access it or turn it off for the scan.

    Thanks,
    -Steve
     
  10. stejampzy

    stejampzy Private E-2

    Oops, "Norton Internet Security".
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the READ & RUN ME and specifically in the Using MGtools link, you need to disable or uninstall your antivirus program since it is just getting in the way of cleanup. So either shutdown AVG or uninstall it. Then download and run MGtools and attach the log. You many find the below link helpful to disable AVG

    http://www.avg.com/us-en/faq.num-1209
     
  12. stejampzy

    stejampzy Private E-2

    I already did this and received an error message. Can you comment on my Post #9? I uninstalled AVG but still can't get MGTools to work properly.

    Thank you,
    -Steve
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may be working well enough to create a log. Did you bother to check for the MGlogs.zip file? ;)
     
  14. stejampzy

    stejampzy Private E-2

    There was no log created (no MGlogs.zip file). The program wasn't able to run. Any other ideas? :confused
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.
    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black larger fonts are commands. The purple/brown is merely informational.
    dir c:\ > c:\flist.txt <-- there is a space after the dir and after the \
    dir c:\mgtools >> c:\flist.txt <-- there is a space after the dir and after the mgtools
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GRK <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.





    Attach the c:\flist.txt file to your next message.
     
  16. stejampzy

    stejampzy Private E-2

    Hello.

    GRK = no error
    ShowNew = error that read...
    Administrator: Command Prompt - ShowNew
    SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers. VOD. Virtual Device
    Driver format in the registry is invalid. Choose 'Close' to terminate the application.

    flist.txt attached.

    Thanks!
    -Steve
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Contrary to what you previously stated, there is a C:\MGlogs.zip file because I can see it in the log you just attached. Please attach the C:\MGlogs.zip file do this now before doing the below where I will ask for another try at running MGtools.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the below and attach the log from GMER:

    GMER - running with a random name


    Now reboot your PC.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the GMER log
    • C:\MGlogs.zip
     
  18. stejampzy

    stejampzy Private E-2

    MGLogs.zip file attached before trying any of the remaining steps, as you suggested.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions for Using MGtools with Vista explain that you MUST disable UAC and reboot. You did not do this. UAC is still enabled. You cannot properly run MGtools with UAC enabled. We did explain running a registry patch we provided in the MGtools folder to disable UAC for you which is useful when MSconfig cannot be run. You need to follow our instructions properly if you want tools to work.
     
    Last edited: Jun 17, 2010
  20. stejampzy

    stejampzy Private E-2

    On the contrary, chaslang, I did disable UAC and reboot... but when only one of the scans worked (Super Anti-Spyware), I re-enabled UAC in order to -- at least somewhat -- re-secure my computer while I travelled for business and awaited further instruction.

    For arguments sake, I went back to the very beginning yesterday and ran through all of the READ ME FIRST info and the Vista Cleaning Procedures info. Still, the only scanning program that didn't have an error was Super Anti-Spyware. MB, Root Repeal and MGTools had the same error messages as before.

    Additionally, I ran through the registry and GMER steps you suggested in your previous post (before it was edited) and while the registry edit was added successfully, the GMER program froze up my computer 4-5 times either during or after the scan, and I never was able to obtain a log.

    Thanks again for your assistance.
     
  21. stejampzy

    stejampzy Private E-2

    In addition to my post (#20), here is a log from Malwarebytes which I was able to run after re-downloading and not renaming it. Thank you.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You MUST have UAC disabled before trying to run any of our instructions. Thus if you renabled it, you have to disable it again and then reboot. The instructions in the cleaning procedure clearly stated that UAC must remain disabled until we are finished. It will get in the way of many programs we use including ComboFix and MGtools. UAC does not provide any advanced protection from malware.

    Disable it now. Then reboot into safe mode. Then in safe mode, try running the below.

    Make sure ALL protection software is disabled!

    Try running ComboFix.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. stejampzy

    stejampzy Private E-2

    Greetings,

    Thanks for the follow-up.

    I was able to successfully run ComboFix (though it kept telling me that AVG and Norton Internet antispyware and antivirus were running even though I uninstalled AVG a couple of weeks ago and have no idea how to access Norton since it is also not a program on my computer) and have included a log below.

    Then I ran MGTools\GetLogs.bat as Adminstrator like you suggested and attached the log below.

    All of this was done with UAC off and in safe mode. Everything is running pretty smoothly right now.

    Best regards,
    -Steve
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are still some leftovers from these programs on your PC which we will attempt to remove with the below fix.

    Try to run the below in normal boot mode if possible. If not possible, then run it in safe bootmode.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\Nwktst.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Wait for it to finish ( the black command prompt window will close when finished). If it does not run properly, just continue on.

    Now run the C:\MGtools\GRK.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Wait for it to finish. A notepad window will open with a log in it when finished. Just close the notepad Window. ( the black command prompt window will close when finished). If it does not run properly, just continue on.

    Now run the C:\MGtools\SN64.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Wait for it to finish. A notepad window will open with a log in it when finished. Just close the notepad Window. ( the black command prompt window will close when finished). If it does not run properly, just continue on.

    Now run the C:\MGtools\UserInfo.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Wait for it to finish ( the black command prompt window will close when finished). If it does not run properly, just continue on.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  25. stejampzy

    stejampzy Private E-2

    I just want to be sure I'm clear before using the Fix button on HijackThis. You mentioned "select the following lines" but didn't mention any specific lines. When I ran the scan there were 30-40 results. Do I fix all of them, or are there specific ones that I should check the box on and fix? Thanks.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! That was part of a boilerplate that I forgot to edit out. There is nothing to do with HijackThis. The fix begins with ComboFix.
     
  27. stejampzy

    stejampzy Private E-2

    OK. ComboFix and all of the MGTools scans seemed to complete properly.

    I've attached the logs you requested.

    Everything seems to be running smoothly right now.

    Thanks again,
    -Steve
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  29. stejampzy

    stejampzy Private E-2

    Hey chaslang. Just wanted to say thanks again for your kind help. It is very much appreciated. :)
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds