Computer not responding

Discussion in 'Malware Help (A Specialist Will Reply)' started by bluelou, Apr 21, 2011.

  1. bluelou

    bluelou Private E-2

    Hey everyone,

    I posted the other day in the welcome center and was asked to post here.
    My comp got a browser redirect virus that also disabled spybot. It wouldn't let me go to spybots website either.
    I then downloaded and ran adaware and it found trojans etc.. removed them and then I ran a full scan with norton antivirus. Somewhere during the scan my comp locked up. Now when I boot up I get the active desktop recovery screen and nothing will run.
    Occaisionally I can get a program to open but then it locks up. It seems to be different everytime I bootup. Any suggestions what to do?

    Thanks in advance.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try running the below in safe mode if you are unable to in normal mode.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Then continue with this.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. bluelou

    bluelou Private E-2

    I will try. I guess I can download to the comp I am using to respond to you with put on flash drive then onto trouble comp if it will let me. You see the major problem is the problem comp doesn't let me do anything.
     
  4. bluelou

    bluelou Private E-2

    Just to help clarify I am running XP pro. The comp is locked up! On bootup it hangs at the desktop. I cannot run any programs, get online, download anything, open my computer.....
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try...and let me know.

    Also you did not tell me what happens if you try running tools in safe mode.
     
  6. bluelou

    bluelou Private E-2

    The comp will not boot to safe mode.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well will it let you?
     
  8. bluelou

    bluelou Private E-2

    No. If it lets me open my computer it locks up there. It saw the flash drive once but when I click on it it locks up.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you really cannot run anything to provide us information that we need to perform a proper diagnosis, your option would be to use another PC to try create one or more of the below CDs to boot from that allow you to run scans and perform many other tasks without Windows even being loaded. Sometimes this can help to get you started when all else fails. They can even help in cases where a previous scan may have removed something that resulted in your PC being unbootable.
     
  10. bluelou

    bluelou Private E-2

    Ok, I was able to get the system to respond by launching CCleaner as soon as the desktop appeared.
    I am back up but still have a redirect virus in IE and Firefox.
    I downloaded and ran the TDSSKiller and am attaching the file.

    I will go through the read me first post and follow those steps next.
     

    Attached Files:

  11. bluelou

    bluelou Private E-2

    I went through the redirect fix steps in the read me first post. Here is Goored.txt log.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. ;) I need to see logs from the following next:

    • SUPERantispyware
    • Malware Bytes
    • RootRepeal (if not on 64 bit)
    • Combofix
    • MGTools
     
  13. bluelou

    bluelou Private E-2

    Ok here are the files. Comp seems to be fine now. Thanks alot!
    Mg tools wouldn't run because it said CA antivirus is installed. I tried several time to uninstall it but I get a window saying I don't have the proper permissions to uninstall.Try logging on as admin. I am ADMIN!!!
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Java(TM) 6 Update 24 <--- Uninstall outdated Java.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - - (no file)
    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
    O2 - BHO: FCTBPos00Pos - {B1BE275B-78BF-4A33-81AB-380699CFF329} - (no file)
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
    O15 - Trusted Zone: *.line6.net
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -

    After clicking Fix exit HJT.


    Download and run OTM.


    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1BE275B-78BF-4A33-81AB-380699CFF329}]
    
    :files
    C:\WINDOWS\system32\drivers\kmxcfg.u2k4
    C:\WINDOWS\system32\drivers\kmxcfg.u2k5
    C:\WINDOWS\system32\drivers\kmxcfg.u2k6
    C:\WINDOWS\system32\drivers\kmxcfg.u2k7
    C:\WINDOWS\system32\drivers\kmxcfg.u2k0
    C:\WINDOWS\system32\drivers\kmxcfg.u2k1
    C:\WINDOWS\system32\drivers\kmxcfg.u2k2
    C:\WINDOWS\system32\drivers\kmxcfg.u2k3
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Now run Ccleaner.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running now? If you are still having problems then Combofix should be run as you seemed to have skipped that step.
     
  15. bluelou

    bluelou Private E-2

    When running OTM as Administrator, I apparently don't have a password setup for admin or I don't remember it.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just double click to run it.
     
  17. bluelou

    bluelou Private E-2

    otm file
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget this part! :)

     
  19. bluelou

    bluelou Private E-2

    It was combofix that would not run because it says I have CA antivirus installed. My comp will not let me uninstall it. It says I don't have permission.

    All seems well though. There is no more redirect and I seem to be running normally.
     

    Attached Files:

  20. bluelou

    bluelou Private E-2

    What should I do with all these programs I've downloaded? TDSSKiller, OTM..etc.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can just right click and delete them. A few files I tried to remove that I shouldn't have have reappeared anyway relating to CA. So not to worry. The logs look good. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds