Cant get rid of malware (i think)

Discussion in 'Malware Help (A Specialist Will Reply)' started by cc117, Nov 4, 2010.

  1. cc117

    cc117 Private E-2

    ok I will start off like most by saying I am completely new to all this.Usually I am able to fix things with a little research and loading some removal tool. Have tried all things such as starting in safe mode and running a scan. Anyway I have a log which I hope you can help me with. I am not technically minded so please spell it out.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 22:21:42, on 04/11/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.17091)
    Boot mode: Normal

    Edit by chaslang: Inline HJT log removed. READ & RUN ME FIRST. Malware Removal Guide sticky not followed.



    Thanks again in advance, any help at all is appreciated :)
     
    Last edited by a moderator: Nov 4, 2010
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. cc117

    cc117 Private E-2

    Ok sorry about that. I did as much of the procedure as i could but could not do the combofix. I will try to attach the logs. Please help I have lost days on this. :). Just let me know if I need to get a professional cos I am failing miserably here. I am having trouble even following your instructions even though they are clear.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the log from running C:\MGTools.exe --> C:\MGLogs.zip.
     
  5. cc117

    cc117 Private E-2

    Hiya I think this is it
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download and put ComboFix directly on your desktop. Do not run it yet.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 2


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. cc117

    cc117 Private E-2

    Hiya did everything that you told me. Thanks so much for all your help. I think all is well I didnt really check as was busy doing this and wanted to get back to you before bed. Anyway I really appreciate you taking the time and energy. cheers :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We have one more little fix to do.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O20 - Winlogon Notify: cryptnet32 - Invalid registry found

    After clicking Fix, exit HJT.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. cc117

    cc117 Private E-2

    Hiya did that, am I fixed yet :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. cc117

    cc117 Private E-2

    Hiya sorry me again. laptop is starting up fine with no error message but i still have a random window opening up with various search pages. Can you help. It closes down when I click it but just wondering if I could get rid. Thanks
     
  12. cc117

    cc117 Private E-2

    ok lads I am so sorry but need your help again. I was making sure everything was ok and ran my free avg and it has picked up a load of viruses (sp?) which it says cannot be moved as they are in a critical location. Also the avg resident shield keeps popping up also. Can you help pleeaasse?:)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you complete all of my final instructions including the toggling of System Restore in step # 9? If not then this is likely why.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Random window?
    What does it say and when do you get it?
    Is it only when on certain websites?
    What browser are you using when it appears?
     
  15. cc117

    cc117 Private E-2

    Ok sorry about this. I did all of the steps that you said. The window that pops up is gameo or something like that. Another thing is I can't do my windows update. It comes up that the internet cant connect.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be exact or instructions cannot be exact and you need to answer the rest of the questions I asked.
     
  17. cc117

    cc117 Private E-2

    ok it seems to happen when I update avg. It is coming up multiple threat detection and then some of the viruses identified are win32/patch.....
    It is getting worse now
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you toggle System Restore? Did you uninstall Combofix? If not, you must make sure you do both of these steps.

    Attach a log from a full scan with AVG.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  20. cc117

    cc117 Private E-2

    yes i did system restore, I think i did it right but not sure. Its even hard to get into the internet explorer. the threats just keep popping up need help quick
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do what I asked in my last two messages. That is, run a full scan with AVG and attach the log. Then run a scan with TDSSkiller and attach the log.

    We may need to have you download and run ComboFix. We will tell you if/when this is needed, but you will have to uninstall AVG before trying to download and run ComboFix since AVG is problematic for some specialty tools including ComboFix. ComboFix will not run properly with AVG installed.
     
  22. cc117

    cc117 Private E-2

    where do i get my avg scan results. Every time I try to attach the file it is invalid
     

    Attached Files:

  23. cc117

    cc117 Private E-2

    Hiya I think this is the avg log. Could be wrong. The multiple threat detection window is popping up constantly now making it very hard even to post
     

    Attached Files:

  24. cc117

    cc117 Private E-2

    help needed really badly here.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your operating system CD?
     
  26. cc117

    cc117 Private E-2

    no I have microsoft works 8. Thats not it is it
     
  27. cc117

    cc117 Private E-2

    Hiya just wondering should I begin again at the malware removal again. would this help
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, we need to replace two system files. So we need the XP CD to do this. We can try having you create a recovery console disc, which you could then boot to. You will need to use another computer to create the disc and then change your boot record file in the bios so that the cd drive is the first boot device.

    Here is the link for creating an xp recovery console disc:
    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    Tell me if you are able to do this.
     
  29. cc117

    cc117 Private E-2

    Hiya I found a toshiba product recovery cd. Is this the one I need
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That may or may not work. Can you use it to boot into the recovery console?
     
  31. cc117

    cc117 Private E-2

    Sorry about this but what do you mean. Will I put it in the computer and go from there. Excuse my ignorance
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, you have to get into the bios before you can run it. That means on startup, you should see a message telling you what to hit to access the bios, possibly F12. Once in the bios, you need to click on the boot order tab and change the first boot device to the cd drive. Make the hard drive the second device. Then put the disc in the computer and reboot. It will ask you if you want to boot from the cd and you will just hit the enter key. Then see what options you have with that disc. It may only give you the choice to put it all back to factory settings, meaning you will loose everything. But we need to know if it will give you the option to get into the recovery console.
     
  33. cc117

    cc117 Private E-2

    Hiya it gives me three options and one is expert recovery mode. what will i do now
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can get into the Recovery console, do this:
    This assumes that D: is your cd drive letter. The last command should reboot your PC. Remove the CD and see if Windows will boot.
     
  35. cc117

    cc117 Private E-2

    I changed boot order. It gives me the 3 options. 2 being expert recovery mode. When I hit 2 it comes up press any key to continue then the prompt is local options or quit. Press local disk partition check are the next options. If I press disk from image comes up. Anyway I don't see a c:/windows prompt. What am I doing wrong
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds as though the Recovery Disc will only allow you to re-image your computer ( though one may allow for a re-image that keeps your files and settings, but I don't know if that is the case). I would suggest you create the Recovery CD that I linked you to before and try booting to that. Then we can try replacing the two system files.
     
  37. cc117

    cc117 Private E-2

    Cheers will try do that tomorrow. Cheers
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are able to create that disc, then run what I posted in message #34. I will be back to check on you tomorrow. ;)
     
  39. cc117

    cc117 Private E-2

    Hiya i am on my brothers laptop trying to load that link to the windows recovery disk and it keeps coming up the feature you are trying to use is on a network source that is unavailable. What do I do now?
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That link should just open a download file. Is your brothers machine also an xp system? Does he have an XP CD of the same version as what you have?
     
  41. cc117

    cc117 Private E-2

    no he has no cd either. I cant seem to download it. the message comes up when it has downloaded
     
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  43. cc117

    cc117 Private E-2

    no thats not working either. It says an installation package for sonic record cannot be found
     
  44. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are going to have to find an xp cd of the same version as what you have installed. Ask around. See if you can borrow one from someone, otherwise you will be stuck with having to re-image your system with the recovery disc. That will wipe out everything and put you back to when you first got the machine.
     
  45. cc117

    cc117 Private E-2

    Thanks I will try to get one :)
     
  46. cc117

    cc117 Private E-2

    Ok I got an xp disc and put it in. I changed the laptop to boot from cd. I picked to go into recovery mode but when i got to the c:/prompt bit I typed in the the copy d.................. and it comes up the parameters are not valid.
     
  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is your CD drive letter D:\ ?
    It should first come up as:
    C:\Windows and you would just type:
    copy D:\i386\explorer.ex_ explorer.exe
    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit
     
  48. cc117

    cc117 Private E-2

    ok it comes up microsoft windows xp recovery console
    the recovery console provides system repair and recovery functionality
    Type exit to quit the recovery console and restart the computer

    1: C:\WINDOWS

    Which windows installation would you like to log onto
    <to cancel, press ENTER>? (I pressed 1)

    Type the administrator password:
    (I just pressed enter as dont know it)

    C:\WINDOWS (I pressed copy D:\i386\explorer.ex_explorer.exe
    it comes up
    The system cannot find the file specified

    So should I just go for the whole thing to be recovered?
     
  49. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If this is the same version of windows as what you have installed and you have your installation key somewhere on the computer ( usually the bottom of a laptop or the back of a desktop ) then you can try doing a repair install. That means you don't hit R the first time, but do the second time.
     
  50. cc117

    cc117 Private E-2

    what do you mean. on the first window?

    To set up windows xp now press enter

    to repair a windows xp installation using recovery console, press R

    to quit setup without installing windows xp, press F3

    Do you mean dont press R here?

    or where it says

    1:C:\WINDOWS

    which windows installation would you like to log onto (to cancel, press ENTER)?


    do i press 1 here?

    sorry I probably sound so hopeless
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds