Can't use Cleaning Procedures

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Comp, May 30, 2011.

  1. Comp

    Comp Private E-2

    Hello, MG,

    A few days ago I began getting pop-up boxes from a suspicious, badly
    written website calling itself "XP Total Security", listing 27 viruses
    lodged in personal (named) files (I screenshotted them) and wanting me to
    buy protection software. The giveaway was that it promised a 1-click
    solution to my problems, etc. My Sygate firewall had not been switched
    back on after I disabled it some weeks ago to use some tax-return
    software, hence infection.

    I initially started having problems opening my browsers. I ran an old
    version of CCleaner and had less problems opening them, although browser
    problems have been with me since last year, so I was not unduly anxious.

    Yesterday I started getting continuous Avira alerts about a trojan. I
    continually pressed 'deny access' or 'send to quarantine'. These alerts
    have now ceased but now the problems have really started:

    I can't open any programs except a few Office programs, Adobe and Opera,
    Opera only by clicking on an old Opera Web Page icon on my desktop. The
    trick here is that I'm clicking on actual files, or similar, not on the
    program itself. My main email inbox directory on Opera has also
    disappeared, but that's a detail(!).

    When I try to open programs using Start > Programs - even things like the
    calculator in Accessories - I'm getting the 'Open with...' list of
    programs, and my attempt to open the program fails.
    This even happens with things like Thunderbird and Paintbox, where the
    relevant program is an option in the list of programs.
    It happens with the most recent MGtools.exe, with SUPERAntiMalware (from
    wherever I try to access it), with a new mbam.exe which I renamed into
    mb.exe - and now with Sygate (which I had switched back on, btw).

    I'm blocked from the stuff in Control Panel, e.g. 'Software' for
    adding/deleting. I just get a 'can't open application' message. I.e. the
    symptom is different from the Start > Programme route.

    I've tried running system restore via the command C:\windows\system32\restore\rstrui.exe, unsuccessfully.

    I do have the Recovery Console, btw. I can press F8 when booting and it's
    an option on the screen, if I remember correctly. Is that going to save
    me? I've sent the personal work I've done over the past few days to my
    provider's server, so a reversal to say the 20th May wouldn't bother me.
    Also, from last year's dealings with major geeks, I have a 2-second screen
    with white-writing on when I turn on the computer, but never get a chance
    to read it. I tried to screenshot it today but can't open Paintbox to save
    and view it.
    Because of the Console etc, I haven't repeated the whole Read and Run Me
    First sequence that I did last year with some success. Some of the issues
    I've described above also suggest that I may not be able to.

    Today am not getting the XP Total Security pop-up boxes listing 27 viruses
    and only very occasionally the Trojan alert from Avira.
    I'm on XP Pro.

    Best regards,
    WP
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. Comp

    Comp Private E-2

    Yes, I've since read up a bit on "XP Total Security" (http://www.rvnetwork.com/index.php?showtopic=91470) and discovered that my clicking to close the "buy our AV software" boxes was what infected me.

    Due to the problems stated, I can't run any of the versions of Rkill that I downloaded, so can't begin to follow your step-by-step suggestions. I continually get the "Open with.." list of programs - a brick wall. The Rkill doesn't open ...and now the "Open with" box refuses to close, forcing me to use the Task Manager to close it.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Comp

    Comp Private E-2

    I'll ask a friend to mail me the contents of the exe-fix zip file individually, because when I tried to open the downloaded zip file I ran into the same brick wall that I've run into with all other programs: I choose '[open with] WinZip Executable' and it refuses.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried doing it in safe mode w/networking? Do you have a different computer to download it to and transfer via CD or thumb drive?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download RogueKiller.exe and save it to your desktop.
    • Now quit all running programs.
    • Double click RogueKiller.exe to run it.
    • When prompted, type 1 and hit Enter.
    • A RKreport.txt should appear on your desktop.
    • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
    • Please post the contents of the RKreport.txt in your next Reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds