All kinds of problems ...

Discussion in 'Malware Help (A Specialist Will Reply)' started by horizone, Jun 25, 2010.

  1. horizone

    horizone Private E-2

    Problems started at least a month ago with Firefox issues. Switched to Chrome. Earlier this month plagued by the fake anti-virus popups but fixed these with AntiMalwareBytes. Then a few days ago links from searches began re-directing. Ran AntiMalwareBytes some more. Then Chrome quit working altogether.

    Specifics:

    1) While executing all the items in the cleaning procedures, Explorer repeatedly encountered an error and shut down.

    2) I believe the file PersonalAV.job is on the computer somewhere - SuperAntiSpyware spent a very long time scanning it.

    3) The directory HelpAssistant is present under Documents and Settings.

    4) FireFox would not start, so I uninstalled it, but have not reinstalled it yet. Chrome and IE are working now (after following the cleaning procedures).

    5) I encountered two errors while running MGtools - I will quote them in the next post.
     

    Attached Files:

  2. horizone

    horizone Private E-2

    Oops ... I think I posted two threads instead of adding to this one. Sorry.

    Since I ran Anti-MalwareBytes several times this month since my problems started, I zipped all the logs together.

    I encountered two errors while running MGtools that were not in the list of possibilities.

    With the first one, I simply didn't click anything until MGtools finished. I researched it a little bit and found that I can run 'cmd' but I cannot run 'command.com'.

    With the second, I tried to click 'Yes' but because of my broken browsers, it stalled, so I killed the browser window and clicked 'No' (or whatever the choice was) and let MGtools finish.

    Here is the text of the two pop-up errors:

    =====================================

    16 bit MS-DOS Subsystem

    C:\WINDOWS\system32\cmd.exe
    NTVDM has encountered a System Error
    NTVDM has encountered a System Error c0h Choose 'Close' to terminate the application.

    ======================================

    HijackThis

    Please help us improve HijackThis by reporting this error

    Click 'Yes' to submit

    Error Details:

    An unexpected error has occurred at procedure: modRegistry_IniGetString(sFile=system.ini,sSection=boot,sValue=Shell)
    Error #5 - Invalid procedure call or argument

    Windows version: Windows NT 5.01.2600
    MSIE version: 8.0.6001.18702
    HijackThis version: 2.0.4

    Thanks so much in advance!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
    Close out all other open programs and windows.
    Double click the file to run it and follow any prompts.
    If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
    Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

    helpasst -mbrt

    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.


    *In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.

    mbr -f

    Now, please do the Start>Run>mbr -f command a second time.
    Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
    Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

    helpasst -mbrt

    Make sure you leave a space between helpasst and -mbrt !
    When it completes, a log will open.
    Please post the contents of that log.

    No matter what happens with the above, attach the above logs and then immediately continue with the below in normal boot mode!

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    File::
    C:\WINDOWS\Temp\$$$dq3e    
    C:\WINDOWS\Temp\$67we.$
    c:\documents and settings\darrell\Local Settings\Application Data\bdnylicju
    Folder::
    C:\Documents and Settings\HelpAssistant
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. horizone

    horizone Private E-2

    Here is the log file from helpasst.

    In case it matters, the first time I ran it it hung - task manager showed xcopy as the only process using the CPU. I shut down Avast and restarted the helpasst. This time it complained about not having a profile, but it ran and did detect an mbr infection.

    I'm moving on the the next step as instructed.
     

    Attached Files:

  5. horizone

    horizone Private E-2

    Here are the other two log files. ComboFix forced a reboot and hung while trying to generate logs ... I stopped Avast again and that allowed it to finish.

    Things are much better. I reinstalled Firefox and it is working now. Speed of everything is much improved. So far explorer has not crashed since reboot.

    I still have a HelpAssistant directory tree in "Documents and Settings".

    Thanks!!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you manually delete:
    C:\Documents and Settings\HelpAssistant ?
     
  7. horizone

    horizone Private E-2

    Yes, but it wasn't easy. Hundreds of thousands of files.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Are you still having any malware issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  9. horizone

    horizone Private E-2

    I cannot run mgclean.bat. I have tried double clicking it, Start-Run, and also starting it from both cmd and command windows. I get the following error message in all cases: "The system cannot find the file specified."

    Not sure if it's relevant, but in one of my earlier posts, I had noted a problem with command.com involving NTVDM. command.com does launch a command window now.

    Otherwise, the malware seems to be gone.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can just manually remove the MGTools.exe, the MGTools folder as well as the MGLogs.zip.

    Good to know things are running well. You are most welcome. :)
     
  11. horizone

    horizone Private E-2

    Uh-Oh. Explorer just crashed again, so something is still a little wrong.

    BTW, MGtools disappeared all on it's own ... very weird. I've already cleaned up most of the stuff, but let me know if more logs would help.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Explorer crashing probably has nothing to do with malware. I suggest you post in the software forums as your system was clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds