Problems after the 'Run and Read Me' Logs 1

Discussion in 'Malware Help (A Specialist Will Reply)' started by MrNood, Apr 16, 2011.

  1. MrNood

    MrNood Private E-2

    Hi
    I have had a week's struggle to get back to a useable computer and thought I was close.

    I have carried out a Windows XP 'Repair' from the Dell reinstallation disk.

    I am now able to boot normally and have run the tools in the recommended options.

    I am now getting many 'Malware found' messages from my Avira ANtivirus guard, and have redirection windows popping up from IE (I reverted to IE8 from the IE6 which appeared after my repair).

    I don't think the Avira warnings are real - and it seems to block access to IE, Firefox and others.

    I attach the logs from my first run (was unable to run combofix)

    Would TRULY appreciate any help in regaining the use and confidence in my PC

    Thanks in advance
    MrNood
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\Program Files\olhorbja\woybcbsn.exe

    After clicking Fix, exit HJT.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 22

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Program Files\olhorbja\woybcbsn.exe
    C:\Documents and Settings\AdminTest\Start Menu\Programs\Startup\woybcbsn.exe
    C:\Documents and Settings\Geoff\Start Menu\Programs\Startup\woybcbsn.exe
    C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Startup\woybcbsn.exe
    C:\Program Files\olhorbja
    C:\Documents and Settings\AdminTest\Local Settings\Application Data\gytnfvrh.log
    C:\Documents and Settings\AdminTest\Local Settings\Application Data\kiatwoxb.log
    C:\Documents and Settings\AdminTest\Local Settings\Application Data\mbqqjrng.log
    C:\Documents and Settings\AdminTest\Local Settings\Application Data\qpjgobne.log
    C:\Documents and Settings\AdminTest\Local Settings\Application Data\xsysdabm.log
    C:\Documents and Settings\All Users\Application Data\l8h6k22165o6e645bt4xcs1558h
    C:\Documents and Settings\All Users\Application Data\qxsxf67l435so7e67w35t648
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. MrNood

    MrNood Private E-2

    Hi - and thanks a million for taking the time to help.

    I was unable to run any .exe when logged in normally, so have carried out the instructions insafe mode as administrator.

    I was unable to uninstall the java (fatal error message) and I was unable to re-install the new JRE.

    I attempted to run getlogs in normal login bet it gave a load of 'access denied' messages.

    The attached logs are as requested.

    I'll try running in normal login now, and keep youi informed - I think I am still unable to run various apps.

    Thanks again

    Mr Nood
     

    Attached Files:

  4. MrNood

    MrNood Private E-2

    OK - I've tried my normal boot up, but without network connection (I'm using another PC for these communications)

    I still have a warning from AVIRA about Ramnit.C

    I can run some apps like Windows Explorer, Paint, Notepad, WMP, VLC, Outlook

    However, I cannot launch either IE8 or Firefox - there is no message - the app simply fails to run after a short 'timer' cursor.

    I also cannot run other installed apps like Paint Shop Pro, Picture Motion Browser (My Sony picture management software), Google Sketchup.
    These seem to be apps which I installed myself. They give an error message - "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item'

    Bear in mind that I have done a windows repair - do I need to reinstall these software packages?

    Also - some of these seem to have been mentioned in the earlier Avira messages. Is it possible that Avira has quarantined some relevant files for these apps?.

    Certainly seem to have made some progress - Thanks. I have not tried to connec the network, since these problems still indicate some problems.

    Hope the previous logs are appropriate, and hope you can guide me back to a useable PC. (It is just SOOO frustrating that this amount of distress and effort is caused maliciously, and with no benefit to the originator ( I Hope!))

    Thanks again

    Mr Nood
     
  5. MrNood

    MrNood Private E-2

    Last bit of info for now...

    I booted into safe mode with networking.

    I can run all the apps, and have IE and Firefox connection to the web.

    Back in normal bootup, with network connection - tried 2 separate user logins (both with admin rights) but neither will run the IE or other apps as described.

    Thanks
    Mr Nood
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not going to help us fix the account that I gave you the fix for. Your logs were from

    USERPROFILE=C:\Documents and Settings\AdminTest

    This is the account you need to log into to run the fixes and get new logs. Try again.
     
  7. MrNood

    MrNood Private E-2

    Sorry bout that. As I said I cannot run some files when in normal mode so I thought that safe mode might be better than nothing.

    I have now attempted to carry out the sequence in the 'AdminTest' user with the following results:

    1:
    mgtools\analyse.exe -will not run under this user. I get the following message:
    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item'

    If I right click it and try to run as I have tried to use the 'Administrator' account but it denies me access.
    Result - I have not run analyse.exe.

    2:
    Uninstall the below old versions of software:
    Java(TM) 6 Update 22

    Using 'Add and remove programs' from Control Panel. This process results in a 'Fatal Error' message during then uninstall. The program is NOT uninstalled.

    3:
    OTM
    I can now run this from the desktop in this user account. I attach the log from this run.

    4:
    Install latest JRE:
    The Java Setup process fails with the following message:
    Installation failed. The wizard was interrupted before Java 6 Update 24 could be completely installed.

    5:
    Run Getlogs.bat

    If I run this from the given user then it generates a whole series of 'Access Denied' lines.
    On completion the Dos box shuts down, but the no MGlogs.zip file is created!
    I attach 2 screencaps taken whilst it was running.

    Sooo - I'm afraid that not much of what you asked is completed in this user.

    Just for info - the problem appears to be present in at least 2 user profiles (AdminTest and Geoff). The only users I actually need to keep are "Geoff" and "Joanne".

    Thanks again for your time

    Mr Nood
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it was. Please attach it.


    Okay then let's simplify things a little. Delete the AdminTest user account and then see how much of the READ & RUN ME FIRST you can complete after logging into the Geoff user account.
     
  9. MrNood

    MrNood Private E-2

    Hi

    I have searched c:\ for *.zip

    The only mglogs.zip is from Saturday - and is the one I posted earlier, acquired from safe mode.

    I will carry out the 'Read and Run me first' sequence from my login as best I can.

    Thanks for your time. It'll be 24 hours or so til I get to the next step since work gets in the way!

    Cheers
    Mr Nood
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay just attach the new logs after you finish.
     
  11. MrNood

    MrNood Private E-2

    new logs part 1

    Hi

    I have run all the scans from 'Read and Run Me..'

    I attach the first logs here
     

    Attached Files:

  12. MrNood

    MrNood Private E-2

    new logs part 2

    Here are the second set of logs

    It's v late and i have not yet tested the system, in particular no network connection was made during the scans.

    Appreciate your analysis of the logs, and hope we're near to a solution!

    Thanks for all your input

    Mr Nood
     

    Attached Files:

  13. MrNood

    MrNood Private E-2

    Some further info - after a reboot after the scans.

    I am unable to run the programs as described before, and cannot run IE or Firefox.

    My Avira antiVir is still beeping madly and claims to have found many viruses or unwanted programs.

    Shutting down for tonight. Thanks again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: new logs part 2

    Actually it depends on how we look at it. It may be a solution but it will not be the one you wanted. Your logs are showing that you have a Ramnit infection and most of the time this infection will require a total clean reinstall to fix because of what it can do to your PC. This is why SUPERAntipspyware was removing legit file names and why ComboFix just did too. I will post a typical message we normally use for this kind of infection at the end of this reply but first, let me ask you to run the below:

    Using ESET's Online Scanner

    Then attach the log from ESET. Then reboot and run it again and then attach the second log. This may give us enough info to decide whether a reinstall will be required.


    Here is the standard reply/warnings for Ramnit infections:

     
  15. MrNood

    MrNood Private E-2

    hi Thanks for the analysis. As you say - not quite the solution I'd hoped for.

    I have a few questions if you will:

    1: Online scan. I cannot run IE or Frefox under my current user. I think I may be able to in safe mode. Is there any benefit in running the proposed ESET online scan in this mode?

    2: Re-install. Is it OK to re-install on the existing HDD?

    3: Data: My disk is still readable, and infact I made a complete copy of C: onto another HDD when I first had a crash (using Bootable CD).
    I am an amateur photgrapher, and have a large number of pics (jpg, tif, bmp, and psp (paisntshop pro) files. Is there a way of safely accessing them, either to back up from the existing corrupt disk, or to recopy them from the second drive after I re-install.?
    Other useful files to recover would include .doc and .pst files

    Note the second HDD has been powered OFF during the most part of the tests you have proposed this week, but the copy to it was made After the first appearance of the infection.

    If you've any other advice about a clean re-install I'd appreciate it (never done it before). Will I need to install hardware drivers for on board devices? graphics, sound, DVD r/w, etc?

    Cheers
    Mr Nood
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can try safe mode and you can also try using another user account. This would still find many things even though there is a chance it may not find some infected files directly related to your user account.

    Yes but you really should format before installing just to be safe. However you may have a factory partition from which you can restore your PC to the state it was when it came out of the box.

    This is one reason we want to run the online scan....to see if any of them show up as infected. Ramnit can infect many files but most frequently it seems to be all .EXE and .HTML files. So don't backup or reuse any .EXE or .HTML files at all. The others you mentioned may be okay. If you already backed them up, why do you need to back them up again?

    You should scan this drive with the online scanner before using anything from it. You can wait until after the reinstall ( or reimage from factory partition ) before scanning it.

    Yes you would may need to locate some drivers since not all of them always come as part of Windows, but this is why you also should see if you can use the factory recovery partition I was mentioning. It would have everything your PC came with.
     
  17. MrNood

    MrNood Private E-2

    Hi

    I seem to be thwarted in running the Eset scan.
    None of the normal accounts have IE or firefox access.
    If I start in safe mode then I can connect, and I can access sites such as Google. However, if I connect to eset.com I get redirected (licosearch) to MSN or facebook (neither of which I subscribe to)
    Other mainstream sites such as BBC also are not accessible.

    Are there other options before I clean re-install?

    The reason I asked about another backup is cos the copy I have is from a 'known infected' disk. I wondered if there was a safer way of making a copy before I overwrite.

    Can you tell me how to check if there is a re-install partition? (Otherwise I have the re-install OS disk, and drivers supplied with the PC)

    Thanks for the advice.

    Mr Nood
     
  18. MrNood

    MrNood Private E-2

    Hi

    I've found the Dell Repair option (Ctrl F11) and it looks set to re-install.

    Just holding off doing it, if you can help with the other questions:

    1:Is there any other option ? (Whilst I don't have a huge number of installed programs it's always gonna be a pain to get back to where I am after a couple of years useage)

    2: Is there a safer way to archive the old disk, (knowing that it is infected) rather than the direct 'copy' I made onto a separate HDD?

    Thanks

    Mr Nood
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds