this operation has been canceled due to restrictions in effect on this computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by dropandhop, Mar 10, 2007.

  1. dropandhop

    dropandhop Private E-2

    I would love to get your help guys....

    Not sure if this is spyware or a virus or what you would consider this.

    But, I was a dumbo and ran an executable on my win xp prof sp2 machine whose origins I did not know (at around 5:55pm today). When I logged out and back in again with my usual account (not administrator), I was working in a stripped down Windows. Things that were usually setup were no longer: No quicklaunch, no run command, no desktop items, pretty much all the shortcuts to my programs on the start bar were gone, etc. Then when I tried to run anything I get this error: this operation has been canceled due to restrictions in effect on this computer. Please contact your system administrator.

    Going into that same account in safe mode gave the same situation. I then went into safe mode as administrator and I was able to run programs and didn't encounter that error so I created a new user account. I logged back in normally as that new user, but things are still weird. I don't get that error anymore, but windows doesn't remember some settings that I am adjusting (like enabling quicklaunch). So this virus/spyware is definitely still causing trouble (maybe in the registry?). I looked at all system/hidden files and didn't find anything interesting.

    I am hoping that you guys can look at the attached logs and see what you come up with.

    Spybot didn't come up with anything interesting.
    And the online Trend Micro HouseCall didn't find anything either.

    Thanks so much!
    A
     

    Attached Files:

  2. dropandhop

    dropandhop Private E-2

    PS- I forgot to mention that after this happened I noticed 21 new files in my D:\ drive. I have attached those to this msg. Please don't run them as they might cause you problems! But, I thought that they might be reviling.

    Thanks again!
    A
     
    Last edited by a moderator: Mar 11, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sex.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [KernelFaultCheck] -
    O4 - HKLM\..\Run: [svchost] \svchost.exe
    O4 - HKLM\..\Run: [smss] \smss.exe
    O4 - HKLM\..\Run: [NAV] \TaskManager.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Windows\system32\win32dll.exe
    O4 - HKLM\..\Run: [Windows Update] C:\Windows\kdb34894234.exe
    O4 - HKLM\..\Run: [Win Services] C:\Windows\Services32.exe
    O4 - HKLM\..\RunServices: [Services] C:\Windows\Services.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\svchost.exe
    C:\smss.exe
    C:\TaskManager.exe
    C:\Windows\system32\win32dll.exe
    C:\Windows\kdb34894234.exe
    C:\Windows\Services32.exe
    C:\Windows\Services.exe
    C:\Autoexec.exe
    C:\Calculator.exe
    C:\ctfmng.exe
    C:\Me ****ing a 17 Year Old Sexy Bitch VIDEO.exe
    C:\WINDOWS\I HATE THAT BITCH!!!.exe
    C:\WINDOWS\kb913800.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    You may have to manually delete the below since our filters are editing the curse word out of the below:
    C:\Me ****ing a 17 Year Old Sexy Bitch VIDEO.exe

    You know what it should say. Just delete this file.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Please don't attach anymore ZIP files. Your last one was infected with a Trojan and has been deleted.
     
  4. dropandhop

    dropandhop Private E-2

    Thanks sooo much for your quick and thoughtful reply! I really appreciate it.

    I started the process and got to the Pocket Killbox part (with some hangups, which I will report after I go through all of your steps). When I got to the Pocket Killbox part I realized that it seems that you want me to delete some files that I know windows needs to operate. Things like:

    C:\svchost.exe
    C:\smss.exe
    C:\TaskManager.exe
    C:\Windows\system32\win32dll.exe
    C:\Windows\Services32.exe
    C:\Windows\Services.exe
    C:\Autoexec.exe

    I am afraid to use Killbox and delete these files because my thought is that when I reboot and these files don't exsist windows won't be able to boot. What is your thought process behind this? How will windows be able to start up if I delete these files with Killbox?

    Also, I am running through all of your instructions logged in as administrator in safe mode. Is that ok?

    Thanks again for all of your help!
    I just want to make certain I don't lock myself out of booting into windows.

    Take care,
    A
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of those are files that windows needs to operate. They are all trojans. Valid copies of smss.exe, svchost.exe and sevices.exe would be in c:\windows\system32 and no place else. Everything in the above list is not valid.

    You need to follow those instructions while logged into whatever account you posted the logs for.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And after looking back at your logs, the account you posted logs for was as3952
     
  7. dropandhop

    dropandhop Private E-2

    Thanks again for the quick reply and for easing my worries!

    Attached are the new log files. I also want to report back how things went when I followed your steps.

    In HijackThis:

    This line didn't have the url in it, it was blank, but i fixed anyways:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sex.com

    This line did not exsist anymore, so I couldn't fix it:
    O4 - HKLM\..\Run: [svchost] \svchost.exe



    When double clicking on the registry changes you wanted:
    It confirms that you want to add the information into the registry. I said YES. But, it comes back with the following error: Cannot Import C:\HijackThis\fixME.reg: Error accessing the registry. However, I confirmed that I can get into the registry by going run and typing regedit. I am doing all of this while logged in as administrator in safe mode.


    So I am not sure how I can get those changes into the registry, or what is up. I tried merging the entries after I rebooted my machine (still in safe mode as administrator) but it still gave me the same error.


    Pocket Killbox:
    I deleted the temp files for the 3 user accounts that I have now (including administrator)

    When I pasted all the files you wanted me to delete in Pocket Killbox, the following files did not show up in its list:
    C:\svchost.exe
    C:\smss.exe
    C:\TaskManager.exe
    C:\Windows\Services.exe
    C:\Me ****ing a 17 Year Old Sexy Bitch VIDEO

    Should I delte these manually?


    I haven't yet tried to log in normally as my usual user because I did not fully complete everything, as per above, and did not want to cause any more damage. So please further advise what I should try next.

    Thanks so much!
    A
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat! You need to be logged into the account you posted logs for. That was not the Administator account. The account you posted logs for was as3952 and that is the account we are cleaning. The other accounts all need to be cleaned separately. In additon, unless we say to work in safe mode, you should be in normal boot mode.
     
    Last edited: Mar 11, 2007
  9. dropandhop

    dropandhop Private E-2

    I'm sorry about that, I thought I was logged in as admin, and didn't notice your new reply.

    So I stepped through your processes logged in normally as as3952. Please find the log files attached.


    A few things to note:
    - I only fixed the first 4 items you listed for HijakThis. The rest were not listed anymore, so I guess when I ran it as admin it worked!

    - The registry update still wouldn't work. Same error as per below.

    - Killbox couldn't delete any of the remaining files. So I guess it did all that it could do when I was logged in as admin.

    Please advise as to what to try next.

    Thanks yet again,
    A
     

    Attached Files:

  10. dropandhop

    dropandhop Private E-2

    I forgot to mention again......I have all those files sitting in my D:\ drive that were created after I got this problem. They were the files that were attached to my other msg, but was deleted b/c it contained a trojan. The files are the following:
    alg
    AluScheduler
    CachemanXP
    CCAPP
    CCPROXY
    csrss
    dllhost
    lsass
    MotiveBrowser
    msdtc
    NOPDE
    NPROTECT
    Rundll32
    smss
    spoolsv
    svchost
    System
    System Idle Process
    TaskManager
    winlogon
    zlclient

    Any thoughts on these? Should I delete them?

    Thanks!
    A
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to give you a new registry patch below anyway to try. If you cannot get it to add into the registry by double clicking on it, then run the Registry Editor and click File, Import. Then navigate to where you saved the new patch and select it and see if it adds into the registry this way.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You seem to have done a pretty good job a messing up your OS. I'm not sure if we can fix everything. You may have to do a reinstall. Time will tell. Also you seem to be missing many necessary applications. Like an antivirus, firewall, and antispyware. Did you have any of these installed previously?

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [zlclient] \zlclient.exe
    O4 - HKLM\..\Run: [AluScheduler] \AluScheduler.exe
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now goto the following site and do a file scan of the below file on your PC: http://virusscan.jotti.org/

    C:\WINDOWS\explorer.exe

    This is your Windows Explorer shell and I want to make sure it is not infected. Attach the log from the online scans!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You listed a Task Manager processes list not files! System Idle Process is a fake Task Manager item shown to represent your CPU's idle time. And what do you mean they are on your D drive? How did they even get there? Did you install a new/second drive on your system?

    I'm really starting to think you should just format and reinstall. I have no idea what you have done to your system but it goes way beyond malware problems.
     
    Last edited: Mar 12, 2007
  13. dropandhop

    dropandhop Private E-2

    I know that those items appear in the taskmanager. However, I promise you, this virus thing placed all these files on my D:\ drive with those names. I attached it to the other email, but they were removed b/c they contained a virus.

    I will give your new suggestions a try. And I appreciate your patience with this.

    I might just do a re-install anyways to play it safe.

    Thanks again,
    A
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's your decision on how you want to proceed. If you with to continue the cleaning, just work thru the steps in message # 11 and we will go from there.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds