Continued Issues After 'Read Me & Run Me 1st'

Discussion in 'Malware Help (A Specialist Will Reply)' started by no_luck, Jul 6, 2009.

  1. no_luck

    no_luck Private E-2

    After getting my laptop back from a soon to be (if my machine doesn't get better) former friend, I found it infected with 'System Secure 2009 ver4.52.' Nothing worked in Normal Mode. From Safe Mode I ran my usual suite of software (Avast, CCleaner, Ad-Aware, and Spybot S&D) and got rid of the annoying fake anti-virus program and wallpaper. Then the machine began suffering intermittent blue screens of death (BSOD); sometimes they would appear in the middle of Normal Mode booting and sometimes they would not. It was at this time I began the complete 'Read Me & Run Me First' instructions in Safe Mode since booting in Normal Mode was virtually impossible. Following are the results of that process upon full completion:
    -found but could not remove (no remove button visible) 'My Way Search Assistant' using the 'Add remove Programs' app
    -successfully removed 'Viewpoint Media Player' and 'Logitech Desktop Messenger'
    -could not remove 'Java 2 Runtime Environment SE V 1.4.2_03' nor install the newer version; still there
    -could not load 'SUPERAntispyware' in Safe Mode; during installation the app went into a loop never reaching a successful final installation stage
    -successfully installed and ran 'Malwarebytes Anti-Malware,' 'combofix.exe,' 'RootRepeal,' and 'MGtools;' logs for these appa are attached
    -the machine is a bit slow and I am dread rebooting it for fear a BSOD will appear afterwards (I am using the sick machine to write this message)

    I'll wait patiently for your reply. BTW, kudos to chaslang for writing the code for MGtools; its a neat piece of code and probably very difficult to write.

    Thanks in advance.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, no luck!

    I'm have taken on your thread and will review your logs. Please be patient while I go through them and work up a fix.

    Thanks!
    dr.m
     
  3. no_luck

    no_luck Private E-2

    Thanks for the reply, no hurry here. I'm on vacation for a few days and have parked the laptop. Will monitor the thread every six to eight hours or so.

    Thanks again,
    no_luck
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many times, problems like this are not due to malware. You need to write down the exact word for word error messages and post them. It may be something that needs to be debugged in the Software Forum.

    See if you can use the below to uninstall them:

    Your Uninstaller! 2008

    If that does not work, try using this: Windows Installer CleanUp Utility

    This is most likely due to your PC specs which show a relatively slow PC with half the amount of memory we recommend and your hard disk space is getting low. The below is what your logs show for these:
    Code:
    Processor x86 Family 6 Model 13 Stepping 8 GenuineIntel ~1296 Mhz
    Total Physical Memory 512.00 MB 
    Available Physical Memory 208.39 MB
    Item Value 
    Drive C: 
    Description Local Fixed Disk 
    Compressed No 
    File System NTFS 
    Size 33.63 GB (36,108,976,128 bytes) 
    Free Space 6.22 GB (6,683,586,560 bytes) 
    
    But I will give you a few things to do which will help a little especially since you are running some unnecessary startups.

    Thanks!;)

    You have multiple antivirus programs installed (Avast and Norton) which will definitely slow your PC down. You should have remove one of these while running the READ & RUN ME. I recommend that you uninstall Norton Security Center now. And then since Norton products rarely uninstall properly, please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Also since you are running Ad-Aware's Ad-watch, you really should not be running Windows Defender. Also you have an outdated version of Spybot still installed. Thus, uninstall the below:
    Spybot - Search & Destroy 1.5.2.20
    Windows Defender Signatures
    Windows Defender


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. no_luck

    no_luck Private E-2

    Ok, will do. Thanks again.
     
  6. no_luck

    no_luck Private E-2

    Again, many thanks for the help. You are not only helping save a laptop but also a friendship. OK, now to business:

    - I have not been able to replicate the BSOD since completing the 'Read Me 1st' process. I recall it saying something about a 'driver irq not less or equal' something or other and Windows had to restart. Unfortunately I did not pay close attention to the driver information at the bottom of the screen. Is there a log file somewhere I can retrieve this information? I hate to leave this knot untied.

    - removed 'My Way Search Assistant' using Uninstaller 2008 w/o a problem

    - you're absolutely right, this is and old machine that I take when I'm away from home; it is a no frills machine in case it is destroyed while I'm out there

    - I uninstalled Norton stuff soon after purchase back in '05 and installed Avast in its stead; obviously the uninstall was not complete and I still had that monitoring utility hanging around; now gone using the Norton Removal Tool, SWEET!

    - uninstalled Spybot S&D 1.5.2.20 & Windows Defender, did not see a separate entry in the Add/Remove app for Windows Defender Signatures (I assume they were removed along with the main app, correct?)

    - ran MGtools and created new zip file; ran HJT and removed the R0, R1, O2, and O2 lines

    - ran Combofix with the script; the machine rebooted in the middle of the process and all the security software began to come up while the Combofix window saying the log was being written was still open; I closed all security apps while the Combofix window was still open; Combofix finished running without event and produced a log. Combofix had me install Windows Recovery Console.

    - uninstalled the old Java environment and installed the latest per your posting recommendation; tried it using the MS Add/Remove app and it worked, did not need to use Uninstaller 2008

    - ran cleaner and GetLogs.bat

    The machine feels a faster; I haven't noticed strange browser behavior. The Ad-Aware Ad-watch Live icon disappeared (used to be there) from the system tray but a check in the process list shows it running, weird. I have a few apps (GN Accelerator, Logitech Cam, and Skype) in startup. I remember reading somewhere in the 'Read Me 1st' process there is an app out there to herd these guys if there is not option to remove them for startup in the app itself. I think you also wrote something about using HJT to achieve the same. At any rate fells okay, I'll wait for your comments on the logs. One more thing, I keep seeing processes like lsass.exe, csrss.exe, smss.exe running. Looking around I read conflicting info. Mine reside in the i386 and system32 sub-folders off of root, I think this is ok and nothing to worry about, what do you think?

    Thanks again,

    no_luck
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Step 1 of the READ & RUN ME gave you this: Dealing with Startup Process

    Normal.


    You have a little more to do.

    First you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. no_luck

    no_luck Private E-2

    Only one out of the three had a check-box for disabling the start-up; I will deal with the other two via Spybot or HJT processes after I get smart on how to do it.

    Ran the script and logs; they are attached. The only thing I have notice, other than increased speed, is that on occasion menus opened using the right mouse click of items in the toolbar (bottom of screen) do not always go away when you click elsewhere on the screen. They stay opened until a choice in teh opened menu is made.

    So far it feels and looks great.

    I guess I'll add a third item to my list of things to never loan; my laptop (the other two are my car and my wife).

    thanks again and have a good weekend,

    no_luck
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. no_luck

    no_luck Private E-2

    All cleaned up and running smoothly. I've learned a lot while doing this too.

    Thanks for all the help, you are invaluable to wannabe geeks like myself.

    no_luck
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds