Help with removing malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by jlachey, Aug 12, 2012.

  1. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, Chas, I'm on the case! :)

    Yes, please try and start it because even if you do not need the firewall you do the ICS. Does it start up ok? If not - any errors? Also what happens when you try to start this service? Network Connections
     
  2. jlachey

    jlachey Private First Class

    I clicked ok, and it gave me the message that it could not start the service.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And the Network Connections?
     
  4. jlachey

    jlachey Private First Class

    It is already started, with a manual startup type.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not in previous logs.

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  6. jlachey

    jlachey Private First Class

    Am I not looking in the right place for this information? I looked under services/network connections, and that is the information that is given.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes now this log shows it is okay; however I see MANY other services that are not in expected states.

    I cannot believe this is all due to the malware you had as it is not typical of this malware to cause this many changes. Had you in the past many any kinds of tweaks to your system services in some attempt to improve performance as commonly ( and quite mistakenly ) posted on many websites?

    Please shutdown ALL protection software and then run the below again. I know you ran it before but I want to do it again. Pay close attention to which options I have selected.


    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for your input Chas, much appreciated. You're in good hands jlachey ;)
     
  9. jlachey

    jlachey Private First Class

    Thank you for your help, Kestrel13! Chaslang, I ran Windows Repair and it disappeared I believe during step 7. Did something go wrong or should I restart my computer and attach the log?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you first disable ALL protection software ( this includes the junk from AOL, Avast, ZoneAlarm )?

    Also once you select all the options, shutdown your browser before clicking Start.

    Please try again.
     
  11. jlachey

    jlachey Private First Class

    I think it worked this time.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now the Network Connections service shows that it is no longer running again. As are many other services. As stated earlier, I do not think all of this is due to malware damage. There are way to many things in the wrong state to have been from malware that you had. This is not at all typical. Also it seems you don't have any restore points we could attempt to use to fix this. Let's try the below using ComboFix but we will first need to download a new copy to your Desktop. Also we will need to do this in a few stages since there are so many broken services.

    Download this combofix.exe and save to your Desktop. Do not run it yet. Just save it.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. jlachey

    jlachey Private First Class

    This is an older computer, so could it be from something I did a while ago? I stopped using it a few years ago because it had a lot of problems and I didn't think I would be able to get it to work. I only started using it again less than a year ago, and I thought it was close to being back to normal. I did have a lot of trouble with installing Service Pack 3- I don't know if any changes to my computer at that time could have caused some problems. As for system restore, I only noticed it wasn't working after I got rid of the malware and tried to flush my restore points. I was able to turn it off, but I could not turn it back on after I restarted my computer. I'm guessing that is why I don't have any restore points.

    I am hoping ComboFix worked. It seems like it did, but I was concerned since Zone Alarm was re-enabled after ComboFix restarted my computer.

    For the second step, I did receive a success message for the addition to the registry.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good. That fixed 13 services. Let's try to fix a few more with another registry patch.
    Yes it was not running. Now it is.


    Copy the bold text below to notepad. Save it as fixme2.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I did not realise so much was broken! Nice one Chas. :major
     
  16. jlachey

    jlachey Private First Class

    The addition to the registry was successful. When you tell me to let you know how things are working, what should I check? I don't want to click on something I shouldn't, and ruin any progress we are making.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now most of what we fixed is broken again. I think it is time you bite the bullet and reinstall. There is just too much messed up to be able to repair. Your other choice may be to use Macrium to restore an old backup.
     
  18. jlachey

    jlachey Private First Class

    Hmm, ok. Well, thank you for all of your help! :)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. One other thing of note if you reinstall. Do not have two active Windows partitions like you have now. You have somethings trying to load from drive F and some from drive C. There should be only one "ACTIVE" Windows partition.
     
    Last edited: Sep 2, 2012
  20. jlachey

    jlachey Private First Class

    Ok. I was new to all of that when I installed the second drive- hopefully I have a better understanding of things now.
     
  21. jlachey

    jlachey Private First Class

    Actually, I don't think I completely understand what you are saying. I have two hard drives. I cloned the original drive onto the newer one because I was running out of space on the first one. The newer one has data onit that is not on the original drive. Could that be why some things try to load from the C drive and others try to load from the F drive? How do I make only one partition active?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From your logs there were examples of what I'm referring too. For example in RogueKiller it showed the two hard disks and both of them have Active Windows boot partitions.
    Code:
    +++++ [COLOR=darkred][B]PhysicalDrive0: WDC WD2500JB-57REA0[/B][/COLOR] +++++
    --- User ---
    [MBR] c7d283efd6f72a116f5c4a6e68b934a6
    [BSP] 124cd039919cf1c728422027a3563770 : Windows XP MBR Code
    Partition table:
    0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 31 Mo
    1 - [COLOR=darkred][B][ACTIVE][/B][/COLOR] NTFS (0x07) [VISIBLE] Offset (sectors): 64260 | Size: 238441 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!
    +++++ [COLOR=darkred][B]PhysicalDrive1: MAXTOR 6L040J2[/B][/COLOR] +++++
    --- User ---
    [MBR] 3457ac3ae5cfdb2a5d269d6c6080e1bc
    [BSP] f49cae14d8b91b005dff84b1f6d8852f : Windows XP MBR Code
    Partition table:
    0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 31 Mo
    1 - [B][COLOR=darkred][ACTIVE][/COLOR][/B] NTFS (0x07) [VISIBLE] Offset (sectors): 64260 | Size: 38138 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!
    Only one disk should have an active boot partition. You should have turned the other into a slave drive just to hold data. You have things setup where you are booting Windows from drive F and then having some things like C:\Program Files reference while this in itself is not necessarily an issue, the two active boot partitions is. I'm not sure of everything you did but you may even have Windows itself confused on where your registry is and perhaps this is even part of the reason that your services are all messed up. I cannot be sure but I do know all of this is not due to malware. And since each time we get things fixed, and then they break again on the next reboot, it points towards some internal issues with Windows. For stability sake, it would be better to reinstall; however you could try temporarily disconnect the smaller ( and I assume older ) drive and then see if your PC will bootup Windows properly.

    I'm not even sure if removing the Active setting on one of the drives will cure the problems you have.

    Do you have a full backup from Macrium? Possibly you could use it?
     
  23. jlachey

    jlachey Private First Class

    I did some tweaking and I think I managed to make the F drive (the newer drive) into a slave drive. The C drive has always been set to master, but I wasn't sure about the F drive since it isn't labelled very well. The computer now seems to be starting up with the older drive, but it is very slow. System Restore works- at least in safe mode. I might try disconnecting the C drive next to see if I can get the system to boot up with the newer drive. I don't have a full backup, but I do have my important data stored on other devices. So I'm not really worried about losing anything.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well while you only have one drive connected ( either the C or the currently F drive ), run MGtools and attach the new log so we can see what the status is in that mode with all your services.
     
  25. jlachey

    jlachey Private First Class

    I am still trying to get one drive to work by itself- I keep getting error messages along the lines of 'primary Hard disk drive 0 (or 1) not found. I did manage to configure it where one disk is listed as 'active' and the other is listed as 'system'. I think they were previously both listed as 'system'. The problem now is that the computer will now only start up properly in safe mode (I'm using the network option) and I cannot update any programs (Avast, Malwarebytes, etc.). I will keep trying to get just one drive working alone, or do you think I should try something else?
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is likely the effect of having Windows installed on both and both being active. This is why we were having problems previously in getting services fixed. Perhaps you would be better off reinstalling.
     
  27. jlachey

    jlachey Private First Class

    Yeah, I'm thinking that will be my best option. Thank you so much for your help- thank you, Kestrel13! as well! I really appreciate the time and effort you both put into helping me.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    On behalf of us both, you are *most* welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds