Help!!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rwbil, Feb 26, 2012.

  1. rwbil

    rwbil Private E-2

    My computer is messed up. I have a Dell running Vista 32 Bit machine. At first commercials were playing even though I did not even have iexplorer up. And on top of that my web browser is being hijacked. And then the computer would crash doing memory dumps. I tried running the spyware software suggested here but things got worst. Currently I can only boot into safe mode. If I try and boot normal startup, the computer just reboots automatically.

    I opened up Msconfig and changed it to Selective startup. I thought I would attempt to isolate what start up program or process was causing it not to boot. But when I try to reboot in Selective Startup it just automatically reboots and when I open Msconfig in Safe Mode, I notice it automatically changed from Selective startup back to Normal Startup. I am not sure why it is not booting in Selective Startup.

    When looking at the process running, I notice I have several iexplorer, even though I did not open up internet explorer and several Svchost running. One of the malware tools says Svchost was infected, but then failed to repair it. There are several iexplorer and Svchost processes running even in Safe Mode.

    I also tried to delete my IE8 and Install IE9, but for some reason I could not get IE8 to delete.

    I have run all the following programs:

    SuperAntiSpyware
    Sbybot
    CC Cleaner - Both files and registry cleaners
    Glary Utilities
    CombatFix
    Malwarebytes

    This site states to run them in Normal Mode, but my computer will not boot in normal mode.

    My computer is a Dell and it has a backup in the D: Drive. I have thought about taking SVCHost and other files from the D: Drive and overwriting what is currently in the C:windows/System32 Directory. But the dates and sizes are different, so not sure good idea or bad idea.


    Just in case it might be a memory problem, I ran a memory tester and it said the memory was fine.

    I am not sure how to best proceed from here, except to reinstall windows. Any suggestion appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. rwbil

    rwbil Private E-2

    I went through the steps as outlined. I still have the same problems. I can not boot in normal mode and if I try to use selective startup, it automatically switches back to normal startup. I have attached my logs. I had some issues as shown below:

    1) Could not Install latest and greatest Jave in Safe Mode, though deleted all other Java Versions

    2) Combofix kept saying AVG was installed even though I ran AVG Remover, rebooted and do not see AVG Anywhere.

    3) MGtools would not run. I got the following error messages.

    a) C:\windows\system32\config\system 1\Appdata\local\temp\. A temporary file needed for intialization could not be created or could not be written to.

    The directory path exist and the disk is only 2/3 full.

    I should add Combofix, did run and found 3 infected files including SVCHOST. It then automatically rebooted. But the problems continued
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.

    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  5. rwbil

    rwbil Private E-2

    My Cmd Window says: Adminstrator: c:\Windows\System32\Cmd.exe - getrunkey

    A windows popup says:
    Adminstrator: c:\Windows\System32\Cmd.exe - getrunkey
    c:Windows\system32\config\System 1\AppData\Local\Temp\. A temporary file needed for intialaztion could not be created or could not be written to. Make sure that the directory path exists, and disk space is avaiable. Choose Close to terminate the application.

    I then hit Close

    I get the exact same message again. Again I hit Close

    The Windows popup goes away, but in the CMD window It states:

    c:\Windows\System32\config\systemprofile''' is not recognized as an internal external command, operable program or batch file. grep:( standard input): Not enough space.

    And the program stops there.

    Looking at my C: drive there is 77GB of free space
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you change the directory ( cd ) to MGTools?
     
  7. rwbil

    rwbil Private E-2

    Yes.

    Attached is a jpg of the cmd window.
     

    Attached Files:

  8. rwbil

    rwbil Private E-2

    Here is the attachment showing the Windows Pop Up Message.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  10. rwbil

    rwbil Private E-2

    I do not seem to be having any luck running these programs. I download OTL, right clicked and ran as administrator. I got an open file -Security warning saying the publisher could not be verified. I hit run anyway then I got an error message. See attachment

    Robert
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  12. rwbil

    rwbil Private E-2

    I am not having much success. I have a Dell 32bit machine running Window Vista. I hit F8 and then selected Repair Your Computer. I did not get a keyboard or operating system choice. It asked for my user name and pw. When I entered my user name and pw, it came back and stated Domain could not be found or contacted and just ended their.

    I found a Dell resource Disk and was able to boot from that into Dos, but the program would not run from Dos. I know my computer has a D: Drive partition created by Dell. I am not sure if I have an Operating System CD to boot from. I will try and look for it. The resource disk had a memory test, so I ran it and that passed and it has a system test which I also started, but it has not completed yet.

    If I cannot locate an Operating System CD, is there another option and what does it mean that the Domain could not be found.

    Robert
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this computer part of a network?

    Use windows explorer to find and delete:>
    C:\Users\user\AppData\Roaming\flint4ytw.exe
    C:\Windows\System32\acovcnt.exe

    Let me know if you find your disc.
     
  14. rwbil

    rwbil Private E-2

    Not a client server network, just a simple home network whereby the computers access the internet via a router.

    I could not find either of those files on my computer.

    Still cannot locate an operating system disk. I am not sure they sent me one. Dell does have that D: Drive Recovery Partition. I think it is like a Ghost Image to set everything back to when it was new.

    Is there somewhere I can download the files required to make a bootable Vista 32 bit CD.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sadly, no. But you can contact Dell and they will send you an install disc for a nominal charge.
     
  16. rwbil

    rwbil Private E-2

    Finally got a Vista Bootable CD and was able to run FRST. Attached is the FRST.Txt File.

    Roberrt
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go into your bios and change the boot order to CD/DVD as first boot device, then:

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER.

    Can you now boot to normal mode?
     
  18. rwbil

    rwbil Private E-2

    I ran bootrec.exe and re-started in Normal Mode. It did react differently. Normally when I boot in Normal Mode after I select the user and type in my PW it displays the Welcome screen for 2 seconds and then automatically reboots before the desktop appears. This time after running bootrec.exe /fixMBR the desktop actual came up for about 2 seconds before the system automatically rebooted. I rebooted again in normal mode again and then it did like it previously did and automatically rebooted after the welcome screen.

    I was not sure if it was some fluke that the desktop came up or not, so I did the whole process again and again when rebooted in normal mode the Desktop appeared for a second and then rebooted.

    Not sure why but that is what it did. Also not sure if it is important or not, but when I boot up in safe mode or even in normal mode when the desktop appeared for a second or two, the System Properties Menu comes up each time.

    BTW, was that FRST.txt file helpful?

    I am also running a Chkdsk /f


    Thanks in advance,
    Robert
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you can't run any of the tools and you can't boot to normal mode, there isn't much we can do. I suggest that you boot to safe mode and back up all your personal data and files and then do a clean install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds