Got the XP Virus (XP Security or whatever..)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pmarc, Jul 8, 2011.

  1. pmarc

    pmarc Private E-2

    SHOOT - FORGOT TO DO THE READ ME STUFF... I'LL COME BACK!


    Actually: the XP AntiVirus virus

    I can boot in safe or regular mode. But cant open up anything. Have HJT, GMER, DSS on desktop. Have log only for HJT and DSS but cant go online.

    How can someone help? Have Malwarebytes and Superantispyware but cant run them. I'm on PC #2 now. PC's on the same WIFI network.
     
  2. pmarc

    pmarc Private E-2

    Re: Got the XP Anti-Virus (XP Security thing..)

    I performed all in READ/RUN ME.. except the virus did not allow opening up any of the 4 anti-malware applications I downloaded [I can get online now] so the only logs I have are for DDS and HJT [done prior to the virus stopping applications opening - it got worse.

    PC is not controlled by configsys, I removed all quarantined items, removed all but [Superantispyware] programs, I have a 32-bit system, downloaded updated Java, checked hidden files, used add/remove to look for malware.

    I also followed steps at http://www.lancelhoff.com/how-to-remove-xp-antivirus-protection/ ...

    ..but error message said: xxxfile was loaded but the dllUNregisterserverwas not found ..the file can not be registered.

    So what can we do next?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Got the XP Anti-Virus (XP Security thing..)

    Welcome to Major Geeks!

    Did you run MGtools as requested? If not please do so and attach the log from it.

    We do not want HJT logs nor logs from DDS unless requested.


    That is a very bad idea since those instructions are wrong and could break your PC. The shlwapi.dll and wininet.dll files are required system files.
     
  4. pmarc

    pmarc Private E-2

    mg log in a word doc

    Thanx, pls see attachd.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the C:\MGlogs.zip file not a log of what you saw in the command prompt window. See what it said at the end of those messages.
     
  6. pmarc

    pmarc Private E-2

    I've got the MG command prompt window open, it finished.

    What do you do to save the MGlogs.zip

    If it saves automatically, I could not find it anywhere on the machine. Haven't exited this one yet.
     
  7. pmarc

    pmarc Private E-2

    got it

    see attch'd
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    After you attach the above two logs, immediately continue on with the below.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. pmarc

    pmarc Private E-2

    4 logs attch'd

    PC works pretty good. Upon re-booting after Avenger, the PC cycled thru 2 boots on its own before stopping on a full boot.

    Superantispyware ran farther than it did prior to your tutorial and looked as tho it would finish. I did not quarantine - I just cancelled and ended. I can open word, excel, pdf's and get online. I don't get the viral pop-ups.

    BTW - a cool thing included in Superantispyware... if you check it out, there's a file called Bootsafe.exe. Open that and it gives 4 alternate safemodes to click and auto re-boot. Found this cool since hitting F8 never worked during this virus attack.
     

    Attached Files:

  10. pmarc

    pmarc Private E-2

    small quirk

    When I search online the browser gets substantially delayed and gets hijacked. I have to work hard to get to where I'm goin. Maybe select "cached" in the search results. Whereas I go direct to the site if I click a bookmark.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: small quirk

    TDSSKiller attempted to fix a problem with C:\WINDOWS\system32\DRIVERS\ipsec.sys

    Let's see if it was really able to fix it. Please rerun TDSSKiller now and attach a new log.

    Also another two bad files showed up that we will have to fix:
    Code:
    "C:\WINDOWS\system32\drivers\"
    bolhey.sys    Jul  9 2011       61440  "bolhey.sys"
    vhcpdokm.sys  Jul  9 2011       61440  "vhcpdokm.sys"
    Do you have your Windows XP boot CD?

    Also you are not get HijackThis to run which is automatically included in MGtools. Did you see the popup from TrendMicro to accept the license?

    Run C:\MGtools\analyse.exe by double clicking on it. When the license agreement pops up, you need to click the Accept button twice in some cases ( yes twice ) to accept or it just sits there. However your logs do show that it believes HijackThis is installed so you may not even get the license agreement window. Tell me if HijackThis opens. If you still have an infection, it could be blocking this.
     
    Last edited: Jul 9, 2011
  12. pmarc

    pmarc Private E-2

    attachmt

    re: Do you have your Windows XP boot CD?

    ans: I have a cd called MS XP home edition with the [hologram?] graphics on front. I'm sure it's the original. I don't know if they call it a "boot" CD. However, I found a CD I burned years ago. The jacket says "Anit-virus re-boot disc" -- my handwriting.

    re: Also you are not get HijackThis to run which is automatically included in MGtools. Did you see the popup from TrendMicro to accept the license?

    ans: i did not see any of this - tried it again. Nothing. I have always had HJT on my machine. 5 min ago I could not open it. Says can not access the path, etc... I may not have permissions to access them.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: attachmt

    It should be and we may need to use this to boot to the Recovery Console to run fixmbr because you may have an MBR infection. The TDSSKiller log shows that now a different file seems to be a problem so this is likely due to the MBR infection. Boot the XP Home CD may result in it complaining that it does not match your Windows XP Pro installation. See if you can boot it anyway and get into the Recovery Console. See the second section in the below link where it says "How to use the Recovery Console"

    http://support.microsoft.com/kb/307654

    If you can get to the command prompt of the Recovery Console, type fixmbr and hit enter. After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.

    If you were able to run fixmbr, rerun TDSSKiller and attach a new log.
     
  14. pmarc

    pmarc Private E-2

    no console

    The PC ignored the CD-rom drive and just booted on the C:/
     
  15. pmarc

    pmarc Private E-2

    again..

    Found a xp pro cd but it is for a diff machine [a re-installation cd]. Mine ignored it and just booted on the c:/
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: no console

    You have to change the boot order in the BIOS to boot the CD before the hard disk.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: no console

    If you are not sure how to do this, the below link should help. It gives examples for a few different BIOS manufacturers.

    http://www.hiren.info/pages/bios-boot-cdrom
     
  18. pmarc

    pmarc Private E-2

    drives

    Still ignores the CD-rom. I saved in the bios the first boot disc = CD. Went in afterwards and saw this setting was changed and saved. But same result.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: drives

    Then it is not saving. You need to get this to work in order to fix this. You have no choice. You will not even be able to do a reinstall if it becomes necessary because you will need to boot from the CD to reinstall. You need to figure out why chaning the boot order is not working.

    The other alternative would be you need to use another PC to repair your hard disks MBR.


    Edit: One more thing to verify is to make sure that the CD you are trying to boot from is actually a bootable CD.
     
  20. pmarc

    pmarc Private E-2

    boot

    I read some stuff then tried doing diff but no boot on infected pc.

    I will try the discs on another pc tomorrow, thanx.

    [How 'bout that women's soccer team... noticed you came back right after that game today].
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: boot

    Okay let me know what happens.


    Yes this was great but I was not watching it. I was watching baseball after playing my own game. ;)
     
  22. pmarc

    pmarc Private E-2

    unbootable discs

    Well they're not bootable. My pc #2 is on a wired home network, however.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: unbootable discs

    Then you will need to make one. ;)

    See what was posted in message # 12 of the below thread and see if you can get this CD to run.

    whistler/black internet@mbr again!
     
  24. pmarc

    pmarc Private E-2

    floppies, coming up..

    Will take a few days.. on the internet.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. Let me know what happens.
     
  26. pmarc

    pmarc Private E-2

    disketts

    Device mgr says my floppy disc works, drivers ok. Cntrl/System properties shows the device. But when I open it with a disc inside there's no clicking sound and drive a: hangs.. then messg says insert disc.

    Any ideas? I'm ready to install the MS 6-disckett set with XP recovery file.
     
  27. pmarc

    pmarc Private E-2

    Fact is my machine is not opening ANYTHING on the cd-rom, either. Known data. So I'll bring the machine to a store and see if they can access the drives.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the drive does not work properly even when in normal Windows mode then perhaps you have a physical problem with drive or cables. When is the last time you used the drive for anything? Maybe it would also be a good idea to double check the BIOS to make sure the drive is still enabled. Setting the boot order is one thing. Having the CD/DVD drive enabled is another.
     
  29. pmarc

    pmarc Private E-2

    bios

    Looked everywhere there.. no sign of what to do / where to look to check if drives work.

    looked in adv bios + cmos + most other areas

    FWIW:
    boot up floppy seek disabled
    swap floppy drive disabled
    1st boot = cd-rom
    2nd ... HDD-O
    for cd-rom: optomized defaults not loaded; fail safe defaults not loaded
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can post in the Hardware Forum to see if they have ideas about your problems with your CD/DVD drive or you can remove your hard disk and put it into another PC to perform the fix of your MBR.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds