Can't install or run any tools

Discussion in 'Malware Help (A Specialist Will Reply)' started by SillyLittleBoy, Aug 17, 2008.

  1. SillyLittleBoy

    SillyLittleBoy Private E-2

    I've gone through the Malware Removeal READ ME FIRST and followed all the instructions to the letter, until I get to the part where it says to "Clean Windows XP," which involves installing and running each of the programs I've downloaded.

    I couldn't get the "SuperAntiSpyware" to install at all - nothing happens after I double-click and select "RUN." I was able to install "SpyBot Search and Destroy," but when I try to run it, nothing happens.

    I think I am infected with something fairly common. One of the files I've seen mentioned is: C:\WINDOWS\system32\braviax.exe

    It is causing me to get these little red balls with white X's in my task tray and I keep getting these popups saying I have a security problem or my computer has been infected with SpyWare. I have a current McAfee subscription, but both a scan with it and AdAware did find some things, but the problem still exists. Whatever it is has also shut down my McAfee autoscan feature and I cannot get it fixed.

    I have some other strange files in my startup in MSCONFIG that a internet search revealed NOTHING about that, they are:
    C:\WINDOWS\system32\lphcllnj0egav
    C:\Program Files\rhcgknj0egav\rhcgknj0egav.exe
    buritos.exe (no location given but a search revealed two places - C:\WINDOWS and C:\WINDOWS\system32

    I scanned both files with McAfee, but it didn't find anything wrong with it. I suppose it could be a new virus that they are unaware of as of yet.

    ANY HELP getting MY PC cleaned up would be appreciated.

    Thanks,
    John
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try doing the scans in safe mode?

    The items you mentioned need to be removed:
    C:\WINDOWS\system32\braviax.exe
    C:\Program Files\rhcgknj0egav
    C:\WINDOWS\system32\lphcllnj0egav
    C:\WINDOWS\system32\ buritos.exe
    C:\WINDOWS\ buritos.exe

    You can try either doing a search for each in windows explorer or download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot. Please attach that on your next reply.

    Tell me if you can run the scans in safe mode ...I need at least the C:\MGLogs.zip
     
  3. SillyLittleBoy

    SillyLittleBoy Private E-2

    Thanks for all your suggestions and response. I was able to remove many of the malware and trojans that had infected my PC. I used a trial version of "SpyBot - Search and Destroy," which removed many things AND I used AdAware, too.

    This has not gotten my computer back operational and able to use the programs and procedures suggested in the READ ME FIRST - DO THIS FIRST article in this section.

    One of the BIG keys was getting XP Security Center removed, which wasn't easy, since it's not in the Add/Remove programs list and is/was an Icon in the Control Panel. It must have come bundled with the computer as a trial version. What I had was this self-replicating thing that kept installing this XP Virus software as part of the XP Security Center and was giving it many false readings about the number and extent of the viruses and infection on my PC.

    Nice way to nearly force many people to puchase their software, so that you can get your PC operational again, since the XP S.C. was preventing my PC from doing much of anything, due to it's false readings on a complete system infection of deadly proportions.

    ANYWAY... working my way through the other tools suggested in the "DO THIS" posting and getting things ALL cleaned up.

    So far... so good...
    Thanks,
    JP
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Be sure to attach the requested logs so I can see what is left to remove. :)
     
  5. SillyLittleBoy

    SillyLittleBoy Private E-2

    Okay... here are all the logs from the requested programs. I don't think I have any more issues with any viruses, malware, spyware, or trojans, BUT.... I think I do have an issue in my registry.

    The "My Computer" icon disapeared from my desktop and I can't right click on the screen, select "properties" then the "Desktop" tab and then "Customize Desktop" and get the "My Computer" icon to return. That option for selecting items/icons for my desktop for the "My Computer" is grayed out and/or cannot be checked.

    When I find "My Computer" in my explorer tree and I click on "My Computer," none of the drives show in the "folder view," but they do show on the left-hand tree view.

    Any thoughts or suggestions on THAT one?

    Thanks again... here are all my logs...

    JP
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off...there is no point in running MalwareBytes and not having it fix the problems:
    Second...did you run combofix? Where is the log?

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2"
    Java(TM) 6 Update 7

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  7. SillyLittleBoy

    SillyLittleBoy Private E-2

    First off, THANK YOU VERY MUCH for all your time and assistance.

    I did everything you outlined AND I ran ComboFix, too.

    Here are all the logs.

    Thanks,
    JP
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see avenger was being picky....

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Attach the new log from avenger. :)
     
  9. SillyLittleBoy

    SillyLittleBoy Private E-2

    Thanks again for all your help. I think my system is fairly clear of any malicious files, but I DO have ONE issue that is probably related to my previous infections.

    The "My Computer" icon has disappeared from the desktop and it is not in the usual place in Explorer. When I click on "My Computer" in Explorer, I can see the drives in the tree in the left window, but the drives do not show in the main window (folder view).

    ALSO... when I do a "right click" on my desktop and choose "Properties" and then the "Desktop" tab and then "Customize Desktop" I DO NOT have the option of checking the box to "show on desktop" for My Computer. The option is there, but the box is faded and will not allow me to put a checkmark in it. The text for "My Computer" on that option is also faded.

    Here is the new log file as you requested.

    Thanks again!
    JP
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you in classic view? RIght click start / properties / customize / advanced ...are any of the options selected for My Computer?
     
  11. SillyLittleBoy

    SillyLittleBoy Private E-2

    No, I am not in classic view and when I do as you said, right click on start and select properties, customize, and advance, there are no options anywhere for My Computer on any menu anywhere.

    Would this have anything to do with something being altered in my registry?

    Once again... thanks again for all your help. I'm sure my "infection" has been cleared up and this is the only or final issue that I currently have, which is bothersome, but doesn't hinder the basic operation of my PC.

    It has restricted me a couple of times with the use of certain programs, since "My Computer" and thus my drives (including my hard drive) are not available through a programs general "browse" feature and can only be accessed through Windows Explorer OR a desktop shortcut to a folder in one of my Program Files (I can get a "tree" from that folder that will show "My Computer" and thus all my drives).

    If you can offer any further help with this last "issue," I would greatly appreciate it AND thank again for all of your previous help.

    JP
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The malware might have messed with some system files. You could go to start / run / type "sfc /scannow" without quotes and let it run twice ( have you xp cd handy). If that doesn't do it, you should post in the software forum as it may be a registry problem. :)

    If you are not having any other malware problems, it is time to do our final steps:
     
  13. SillyLittleBoy

    SillyLittleBoy Private E-2

    Thanks again Tim for all your help.

    To steal a quote from "Poltergiest"

    "This house is clean!"
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome......safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds